HTTPS, SSL & Security Report for jonnybarnes.uk

This report summarizes how well jonnybarnes.uk is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.

Partially secureScore70/100Last checked: 8 Aug 2026 at 13:00 UTC
HTTPS

Enabled

HTTP → HTTPS

N/A

TLS

B · 1.2, 1.3

Security headers

4/6

Detailed checks

HTTPS availability

The site is reachable over HTTPS.

Why it matters: HTTPS encrypts traffic and protects user data.

HTTP to HTTPS redirect

HTTP port 80 is not responding, so there is no HTTP listener to redirect. Modern browsers upgrade to HTTPS automatically.

Note: Port 80 may be firewalled or intentionally closed. Opening it with a 301 to HTTPS ensures visitors who type http:// are redirected rather than getting a connection error.

TLS & CertificateB

ValidYes
IssuerC=US, O=Let's Encrypt, CN=YE2
Expires2026-08-11
Days until expiry3 days

Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.

To improve your grade

  • Port 80 is closed, so visitors typing http:// get a connection error instead of an automatic redirect. Open port 80 with a 301 to HTTPS to recover the redirect points.
  • Reach 80+ points for B+ (currently 70).

Monitor this domain

We'll check SSL grade, HTTPS, redirects, and security headers automatically. Email only when something changes.

Start monitoring — freeOne-click account with Google, GitHub, or email. No password.

Free: 1 domain, weekly. Plans from €7/mo — daily checks, up to 50 domains, history & white-label PDF.

Grade breakdown2 things to improve for a higher grade →
70/100 pts
HTTPS Connection
+25/25
HTTP to HTTPS Redirect
+0/20
Valid SSL Certificate
+20/20
Certificate Not Expiring Soon
+0/10
Short Redirect Chain
+5/5
HSTS Enabled
+5/5
Security Headers
+5/5
Modern TLS (no 1.0/1.1)
+10/10

To improve your grade

  • Port 80 is closed, so visitors typing http:// get a connection error instead of an automatic redirect. Open port 80 with a 301 to HTTPS to recover the redirect points.
  • Reach 80+ points for B+ (currently 70).

Security headers4/6

  • HSTS
  • CSP
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy — sent, but weakSent as "no-referrer-when-downgrade", which sends the full URL — path and query — to other sites. Browsers already default to strict-origin-when-cross-origin when no header is set — use that or no-referrer.
  • Permissions-Policy

Score: 4 of 6 headers effective. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required. We count a header only when its value actually provides the protection, so a header sent with a weak value counts as “sent, but weak” rather than present. Scanners that count a header as present regardless of its value will report a higher number here.

HSTS (HTTP Strict Transport Security)Preload ready

  • EnabledYes
  • Max-Age730 days
  • PreloadYes
Submit or verify on hstspreload.org

Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.

We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.

HTTP/3 (QUIC)

Advertised + confirmed

Alt-Svc: h3=":443"; ma=86400

Active QUIC negotiation succeeded (curl --http3).

DNS Security

CAAConfigured

Allowed issuers: letsencrypt.org

DNSSEC
Validated
HTTPS Record
Not set

No HTTPS record. Browsers discover protocols via connection — an HTTPS record speeds this up. Learn more →

Redirect chain

When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.

  1. 1.http://jonnybarnes.uk

Recommendations for jonnybarnes.uk

Based on this scan, here are the 2 next steps that would most improve security and SEO for jonnybarnes.uk.

  1. Certificate expires in 3 days

    High impact

    Renew the certificate for jonnybarnes.uk before it expires to avoid downtime. If you use Let's Encrypt or another ACME CA, check that auto-renewal is actually running — expired-but-automated certs are one of the most common outages.

  2. Add 2 missing security headers

    Recommended

    jonnybarnes.uk sends 4 of 6 recommended security headers — missing: X-Frame-Options, Referrer-Policy. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.

Show this badge on your site

Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:

SSL grade badge for jonnybarnes.uk← live preview, updates automatically
<a href="https://httpsornot.com/report/jonnybarnes.uk?utm_source=badge" target="_blank" rel="noopener">
  <img src="https://httpsornot.com/badge/jonnybarnes.uk.svg" alt="SSL grade for jonnybarnes.uk — checked by HTTPS Checker" height="20" loading="lazy" />
</a>

Domain owner? If you want this report removed or made private, contact us.