Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=26325.pizza
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 01, 2026
Valid Until
May 02, 2026
76 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
31:00:21:1B:79:AD:21:5C:BF:82:B9:88:5E:F6:AF:BA:82:59:AE:00:70:8B:6D:67:5D:84:5D:F7:A7:A6:6C:E1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
66923.locker
*.66923.locker
26325.pizza
*.26325.pizza
328567.one
*.328567.one
46664.top
*.46664.top
4800cc.cfd
*.4800cc.cfd
537380.cc
*.537380.cc
67190.loan
*.67190.loan
75388.academy
*.75388.academy
75803.academy
*.75803.academy
768510.vip
*.768510.vip
78513.top
*.78513.top
8-o.co
*.8-o.co
960ylxx301.top
*.960ylxx301.top
962dmy301.top
*.962dmy301.top
96582.locker
*.96582.locker
actionhero-marketing.com
*.actionhero-marketing.com
amp.gs
*.amp.gs
averse.com.au
*.averse.com.au
bed-bug-551194100.click
*.bed-bug-551194100.click
bennessweettreats.com
*.bennessweettreats.com
bigdipper.com.au
*.bigdipper.com.au
bkleon-8lai.xyz
*.bkleon-8lai.xyz
bkleon-e46y.xyz
*.bkleon-e46y.xyz
bkleon-k2eq.xyz
*.bkleon-k2eq.xyz
ccasl.com
*.ccasl.com
cfdxs.net
*.cfdxs.net
flashdash.best
*.flashdash.best
googflowx.com
*.googflowx.com
hatisuci.org
*.hatisuci.org
heart-disease-clinical-trials765886.icu
*.heart-disease-clinical-trials765886.icu
heathersbeauty.com
*.heathersbeauty.com
huiwedding.com
*.huiwedding.com
inkagakuen.org
*.inkagakuen.org
kavareview.com
*.kavareview.com
luckyterbesar.top
*.luckyterbesar.top
mamitawork.com
*.mamitawork.com
microsoftfarbe2.xyz
*.microsoftfarbe2.xyz
olibay1.sbs
*.olibay1.sbs
play-valor-territory.xyz
*.play-valor-territory.xyz
prediksirtpwings138.sbs
*.prediksirtpwings138.sbs
simpleaffiliatebusiness.com
*.simpleaffiliatebusiness.com
staffordshirecancerandeol.com
*.staffordshirecancerandeol.com
superbreakingbarrierz.com
*.superbreakingbarrierz.com
tulu3.io
*.tulu3.io
xnewhampshire.com
*.xnewhampshire.com
Other domains in certificate