This report summarizes how well drumko.app is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.
Enabled
Yes
A · 1.2, 1.3
1/6
The site is reachable over HTTPS.
Why it matters: HTTPS encrypts traffic and protects user data.
Requests to HTTP are redirected to HTTPS.
| Valid | Yes |
| Issuer | C=US, O=Let's Encrypt, CN=R13 |
| Expires | 2026-08-17 |
| Days until expiry | 79 days |
Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.
To improve your grade
Get a weekly security report for this domain
We'll check SSL grade, HTTPS, redirects, and security headers weekly. Email only when something changes.
Requires 4 of 6 headers and Content-Security-Policy (CSP).
To improve your grade
Score: 1 of 6 headers present. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.
Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.
We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.
Negotiated (ALPN h2)
ALPN: h2
Not advertised
The server does not advertise HTTP/3 (QUIC) via the Alt-Svc header.
Allowed issuers: pki.goog, letsencrypt.org, sectigo.com
None detected
No HTTP resources were detected on the HTTPS page.
When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.
Based on this scan, here are the 2 next steps that would most improve security and SEO for drumko.app.
drumko.app sends 1 of 6 recommended security headers — missing: CSP, X-Frame-Options, X-Content-Type-Options…. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.
drumko.app supports HTTP/2 but does not advertise HTTP/3 (QUIC). HTTP/3 improves performance on lossy mobile networks. If you are behind Cloudflare or a modern CDN it is usually a toggle.
Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:
<a href="https://httpsornot.com/report/drumko.app?utm_source=badge" target="_blank" rel="noopener"> <img src="https://httpsornot.com/badge/drumko.app.svg" alt="SSL grade for drumko.app — checked by HTTPS Checker" height="20" loading="lazy" /> </a>
Domain owner? If you want this report removed or made private, contact us.