Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=zippyweb.cfd
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 05, 2026
Valid Until
May 06, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3E:6E:D9:9A:84:AF:A3:1C:3D:8F:3A:8B:B7:AA:1C:DD:44:94:67:2E:9A:3D:D6:7B:20:78:61:A5:A6:B6:22:50
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
24sieben.com
*.24sieben.com
amgpipelinemax.com
*.amgpipelinemax.com
*.dev.amgpipelinemax.com
*.emneicloud.amgpipelinemax.com
*.hostmaster.amgpipelinemax.com
*.hs2.amgpipelinemax.com
*.img.amgpipelinemax.com
*.rds.amgpipelinemax.com
amz-th.org
*.amz-th.org
*.ww16.amz-th.org
*.ww25.amz-th.org
assa.net
*.assa.net
*.hotspot.assa.net
*.vpn1.assa.net
*.web.assa.net
*.asyevilo.chuanputea.com
*.backup.chuanputea.com
*.bot.chuanputea.com
chuanputea.com
*.chuanputea.com
*.demo.chuanputea.com
*.hostmaster.chuanputea.com
*.qa.chuanputea.com
*.redash.chuanputea.com
*.staging.chuanputea.com
*.uwrwovpn.chuanputea.com
*.vpn.chuanputea.com
*.web.chuanputea.com
*.webmail.chuanputea.com
*.beta.crown-management.com
crown-management.com
*.crown-management.com
*.download.crown-management.com
*.mail.crown-management.com
*.monitor.crown-management.com
*.news.crown-management.com
*.repos.crown-management.com
mobifone.org
*.mobifone.org
*.sitemap.mobifone.org
*.dashboard.orex.gold
*.hostmaster.orex.gold
orex.gold
*.orex.gold
*.srakqhostmaster.orex.gold
*.staging.orex.gold
*.v2.orex.gold
*.web.orex.gold
*.earlyaccess.spokcareconnect.com
*.innovation.spokcareconnect.com
spokcareconnect.com
*.spokcareconnect.com
*.staging.spokcareconnect.com
*.wildcard.spokcareconnect.com
*.app.storni.it
*.dev.storni.it
storni.it
*.storni.it
*.protrade.swiftfxtrade247.net
swiftfxtrade247.net
*.swiftfxtrade247.net
*.app.talc.com.au
*.commerce.talc.com.au
*.cpanel.talc.com.au
*.ext.talc.com.au
*.random.talc.com.au
*.servercn.talc.com.au
*.stagecheck.talc.com.au
talc.com.au
*.talc.com.au
*.ww38.talc.com.au
*.www.talc.com.au
*.mailer.twiiter.co
twiiter.co
*.twiiter.co
*.sitemap.wrightcounty.com
wrightcounty.com
*.wrightcounty.com
*.stg.yourbitcoinprivacy.com
yourbitcoinprivacy.com
*.yourbitcoinprivacy.com
*.so-huu-cach-trong-tieng-han.zippyweb.cfd
zippyweb.cfd
*.zippyweb.cfd
Other domains in certificate