HTTPS, SSL & Security Report for www.mup.gov.rs

This report summarizes how well www.mup.gov.rs is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.

Partially secureScore80/100Last checked: 9 May 2026 at 02:58 UTC
HTTPS

Enabled

HTTP → HTTPS

Yes

TLS

B+ · 1.2

Security headers

1/6

Detailed checks

HTTPS availability

The site is reachable over HTTPS.

Why it matters: HTTPS encrypts traffic and protects user data.

HTTP to HTTPS redirect

Requests to HTTP are redirected to HTTPS.

TLS & CertificateB+

ValidYes
IssuerC=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV R36
Expires2026-12-20
Days until expiry225 days

Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.

To improve your grade

  • Improve: HSTS Enabled (+5 pts).
  • Improve: Security Headers (+5 pts).
  • Improve: Modern TLS (no 1.0/1.1) (+10 pts).
  • Reach 85+ points for A- (currently 80).

Get a weekly security report for this domain

We'll check SSL grade, HTTPS, redirects, and security headers weekly. Email only when something changes.

for www.mup.gov.rs
Grade breakdown4 things to improve for a higher grade →
80/100 pts
HTTPS Connection
+25/25
HTTP to HTTPS Redirect
+20/20
Valid SSL Certificate
+20/20
Certificate Not Expiring Soon
+10/10
Short Redirect Chain
+5/5
HSTS Enabled
+0/5
Security Headers
+0/5

Requires 4 of 6 headers and Content-Security-Policy (CSP).

Modern TLS (no 1.0/1.1)
+0/10

To improve your grade

  • Improve: HSTS Enabled (+5 pts).
  • Improve: Security Headers (+5 pts).
  • Improve: Modern TLS (no 1.0/1.1) (+10 pts).
  • Reach 85+ points for A- (currently 80).

Security headers1/6

  • HSTS
  • CSP
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

Score: 1 of 6 headers present. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.

HSTS (HTTP Strict Transport Security)Disabled

  • EnabledNo
  • On HSTS preload listNo
Submit or verify on hstspreload.org

Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.

We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.

HTTP/2

Not negotiated

TLS did not negotiate HTTP/2. Visitors may still use HTTP/1.1 over HTTPS.

HTTP/3 (QUIC)

Not advertised

The server does not advertise HTTP/3 (QUIC) via the Alt-Svc header.

DNS Security

CAA: Not set · DNSSEC: Not signedExpand
CAANot set
DNSSEC
Not signed

No CAA records. Any CA can issue certificates. Consider adding CAA to restrict issuance.

Mixed content

None detected

No HTTP resources were detected on the HTTPS page.

Redirect chain1826ms total

When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.

  1. 1.http://www.mup.gov.rs544ms
  2. 2.https://www.mup.gov.rs/558ms
  3. 3.https://www.mup.gov.rs/wps/portal/sr/724ms

Recommendations for www.mup.gov.rs

Based on this scan, here are the 5 next steps that would most improve security and SEO for www.mup.gov.rs.

  1. Enable HSTS (Strict-Transport-Security)

    Recommended

    www.mup.gov.rs does not send the Strict-Transport-Security header. Without it, returning visitors can still be downgraded to HTTP by an attacker on the network. One header makes browsers always use HTTPS.

  2. Add 5 missing security headers

    Recommended

    www.mup.gov.rs sends 1 of 6 recommended security headers — missing: HSTS, CSP, X-Content-Type-Options…. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.

  3. Enable TLS 1.3

    Recommended

    www.mup.gov.rs does not offer TLS 1.3. It is faster (one less round-trip per handshake) and removes legacy cipher suites. Most modern servers and CDNs enable it with a single config line.

  4. Enable HTTP/2

    Nice to have

    www.mup.gov.rs serves traffic over HTTP/1.1. HTTP/2 multiplexes requests over one connection, which noticeably speeds up pages with many assets. It requires HTTPS, which you already have the foundation for.

  5. Add a CAA DNS record

    Nice to have

    www.mup.gov.rs has no CAA record, so any certificate authority can issue certificates for it. A CAA record limits issuance to the CAs you actually use — a cheap defense against mis-issuance.

Show this badge on your site

Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:

SSL grade badge for www.mup.gov.rs← live preview, updates automatically
<a href="https://httpsornot.com/report/www.mup.gov.rs?utm_source=badge" target="_blank" rel="noopener">
  <img src="https://httpsornot.com/badge/www.mup.gov.rs.svg" alt="SSL grade for www.mup.gov.rs — checked by HTTPS Checker" height="20" loading="lazy" />
</a>

Domain owner? If you want this report removed or made private, contact us.