- Issuer
- Cloudflare TLS Issuing ECC CA 3
- Max TLS
- TLS1.2
- Cipher
- ECDHE-ECDSA-CHACHA20-POLY1305
- Expires
- 10/27/2026( 40 дн.)
- HSTS
- Disabled
- OCSP Stapling
- Disabled
example.com currently holds an SSL grade of A (93/100) from CertH TLS health monitoring. The site supports TLS1.2, does not enable HSTS, and its certificate is issued by Cloudflare TLS Issuing ECC CA 3 — certificate validity is unknown. CertH records daily TLS handshake probes into an auditable certificate health trend.
Full certificate & config details
- Common Name
- example.com
- Key
- ec 256bit
- Sig Hash
- SHA-256
- SAN
- example.com · *.example.com
- Fingerprint
- 6153a96fd1a6ab7f4d438fc34932484299d0729d9140b3a126bb2f9c07b02200
Тренд оценки
Недавняя история
| Время | Оценка | Балл | Издатель |
|---|---|---|---|
| 9/18/2026, 3:23:48 AM | A | 93 | Cloudflare TLS Issuing ECC CA 3 |
| 9/18/2026, 3:23:27 AM | A | 93 | Cloudflare TLS Issuing ECC CA 3 |
| 9/10/2026, 9:57:59 AM | A | 93 | Cloudflare TLS Issuing ECC CA 3 |
| 9/9/2026, 8:04:01 PM | A | 93 | Cloudflare TLS Issuing ECC CA 3 |
| 9/9/2026, 4:13:38 PM | B | 80 | Cloudflare TLS Issuing ECC CA 3 |
Score change insights · Last 90 days
Net change ↑ +106-
↑
9/18/2026 +93 C → AConfig scoring adjustment
-
↑
9/9/2026 +13 B → AConfig scoring adjustment
FAQ
Why did my SSL score drop?
Common causes include an expiring certificate, legacy TLS protocols enabled, weak cipher suites negotiated, HSTS removed or server handshake failures. The "Score change insights" section below lists the specific reason for each move.
How often is the score updated?
Watched domains are scanned daily; leaderboard domains get weekly full snapshots. Publicly queried domains append history snapshots under throttling, building an auditable score history.
Does certificate rotation affect the score?
Usually not — normal rotation keeps the score unchanged, unless the new certificate changes key strength, issuing CA or signature algorithm. The insights section flags such events.
How can I improve my SSL score?
Enable TLS 1.3, disable TLS 1.0/1.1, use strong cipher suites (AES-GCM / ChaCha20), deploy HSTS correctly, and keep the certificate valid with sufficient key strength (RSA >= 2048 or ECC >= 256).