Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=18lulu.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 13, 2026
Valid Until
May 14, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C7:E8:12:E6:2E:32:8B:75:6E:85:6C:2F:66:72:91:2E:82:65:07:2E:A6:D2:2C:3F:A4:0F:4D:8E:D0:CF:42:D8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
278183.com
*.278183.com
175da.com
*.175da.com
18bdsm.com
*.18bdsm.com
18lulu.com
*.18lulu.com
2030india.com
*.2030india.com
206826.cn
*.206826.cn
30207.vip
*.30207.vip
333bbb333kkk.com
*.333bbb333kkk.com
35559kk.com
*.35559kk.com
4745truti-yscz.xyz
*.4745truti-yscz.xyz
51madou.com
*.51madou.com
57045.net
*.57045.net
59888kk.com
*.59888kk.com
5hkjxzx.cc
*.5hkjxzx.cc
63336kk.com
*.63336kk.com
68883kk.com
*.68883kk.com
69douyin.com
*.69douyin.com
72111kk.com
*.72111kk.com
777bbb888kkk.com
*.777bbb888kkk.com
7oq7tbhy.top
*.7oq7tbhy.top
83339kk.com
*.83339kk.com
91pornapp.com
*.91pornapp.com
93338kk.com
*.93338kk.com
97632.in
*.97632.in
993.biz
*.993.biz
a056clx.top
*.a056clx.top
accessebs.com
*.accessebs.com
amoncasino.org
*.amoncasino.org
avguzman.com
*.avguzman.com
debett.app
*.debett.app
fuliji520.com
*.fuliji520.com
gamespage.club
*.gamespage.club
gialailottery.com
*.gialailottery.com
hris-payroll-management304531.icu
*.hris-payroll-management304531.icu
javman.com
*.javman.com
pggod1688.club
*.pggod1688.club
qnpcwqhangwqvpunmame.com
*.qnpcwqhangwqvpunmame.com
repellendus.com
*.repellendus.com
taskan.org
*.taskan.org
ticketwish.club
*.ticketwish.club
ultramarineblueindia.com
*.ultramarineblueindia.com
usscreen.club
*.usscreen.club
web-pentest-177259843.click
*.web-pentest-177259843.click
xnxxoo.com
*.xnxxoo.com
xvideos520.com
*.xvideos520.com
Other domains in certificate