HTTPS, SSL & Security Report for aclhm6.fr

This report summarizes how well aclhm6.fr is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.

SecureScore100/100Last checked: 1 Jun 2026 at 13:39 UTC
HTTPS

Enabled

HTTP → HTTPS

Yes

TLS

A+ · 1.2, 1.3

Security headers

6/6

Detailed checks

HTTPS availability

The site is reachable over HTTPS.

Why it matters: HTTPS encrypts traffic and protects user data.

HTTP to HTTPS redirect

Requests to HTTP are redirected to HTTPS.

TLS & CertificateA+

ValidYes
IssuerC=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
Expires2026-11-16
Days until expiry168 days

Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.

No improvements needed — your configuration meets all requirements for A+.

Get a weekly security report for this domain

We'll check SSL grade, HTTPS, redirects, and security headers weekly. Email only when something changes.

for aclhm6.fr
Grade breakdownNo improvements needed
100/100 pts
HTTPS Connection
+25/25
HTTP to HTTPS Redirect
+20/20
Valid SSL Certificate
+20/20
Certificate Not Expiring Soon
+10/10
Short Redirect Chain
+5/5
HSTS Enabled
+5/5
Security Headers
+5/5
Modern TLS (no 1.0/1.1)
+10/10

No improvements needed — your configuration meets all requirements for A+.

Security headers6/6

  • HSTS
  • CSP
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

Score: 6 of 6 headers present. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.

Cache-Control includes no-store on the HTML response. Browsers will not cache the document; ETag and conditional requests (304) are effectively disabled. Often intentional for authenticated pages; for public pages consider private with max-age or removing no-store if you want HTTP caching.

HSTS (HTTP Strict Transport Security)Enabled

  • EnabledYes
  • Max-Age365 days
  • PreloadNo
  • On HSTS preload listNo
Submit or verify on hstspreload.org

Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.

We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.

HTTP/3 (QUIC)

Not advertised

The server does not advertise HTTP/3 (QUIC) via the Alt-Svc header.

DNS Security

CAA: Configured · DNSSEC: Not signedExpand
CAAConfigured

Allowed issuers: sectigo.com

DNSSEC
Not signed

Redirect chain0ms total

When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.

  1. 1.http://aclhm6.fr

Recommendations for aclhm6.fr

Based on this scan, here are the 2 next steps that would most improve security and SEO for aclhm6.fr.

  1. Consider HSTS preload

    Nice to have

    HSTS is enabled for aclhm6.fr but the domain is not on the browser preload list, so the very first visit can still go over HTTP. Preloading closes that gap — but read the requirements first, removal is slow.

  2. Consider HTTP/3

    Nice to have

    aclhm6.fr supports HTTP/2 but does not advertise HTTP/3 (QUIC). HTTP/3 improves performance on lossy mobile networks. If you are behind Cloudflare or a modern CDN it is usually a toggle.

Show this badge on your site

Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:

SSL grade badge for aclhm6.fr← live preview, updates automatically
<a href="https://httpsornot.com/report/aclhm6.fr?utm_source=badge" target="_blank" rel="noopener">
  <img src="https://httpsornot.com/badge/aclhm6.fr.svg" alt="SSL grade for aclhm6.fr — checked by HTTPS Checker" height="20" loading="lazy" />
</a>

Domain owner? If you want this report removed or made private, contact us.