76/100 SECURITY SCORE

Certificate Information

Subject
CN=tinkerbox.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 24, 2026
Valid Until
August 22, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9D:47:DF:1F:B0:73:51:7A:FA:EE:8E:37:CC:CD:87:6C:22:EC:DD:CB:77:09:13:CC:DA:C2:F8:F2:E3:C5:6B:FD
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
bustun.com *.bustun.com

Other domains in certificate

115533jj.cc *.115533jj.cc
117755jj.cc *.117755jj.cc
18263301xl01.top *.18263301xl01.top
2t87768.com *.2t87768.com
410370.lol *.410370.lol
42204.blog *.42204.blog
42583.my *.42583.my
503367.lol *.503367.lol
504397.lol *.504397.lol
516173.lol *.516173.lol
66734.town *.66734.town
715003.lol *.715003.lol
719006.my *.719006.my
8wy64p.cc *.8wy64p.cc
932wy.top *.932wy.top
*.annelise-co.annelise.co annelise.co *.annelise.co *.annelisew-training.annelise.co *.annelisewoitulewicz.annelise.co *.awcoaching-co.annelise.co
atrnos.me *.atrnos.me *.ayush773.atrnos.me *.bettasmp.atrnos.me *.felixistdumm.atrnos.me *.hellosmpxwni.atrnos.me *.kashimo9.atrnos.me *.random.atrnos.me *.saq6.atrnos.me *.tjbe.atrnos.me *.vcgkihellosmpxwni.atrnos.me *.ww38.atrnos.me
ayy37.com *.ayy37.com
b4il39.cyou *.b4il39.cyou
backupwatcher.com *.backupwatcher.com
bonaventure.pro *.bonaventure.pro *.ww38.bonaventure.pro
egg-don-es-ww-e3243.sbs *.egg-don-es-ww-e3243.sbs
freshwa.com *.freshwa.com
haspur.com *.haspur.com
nociter.top *.nociter.top
onlinecasinosthatpayrealmoney.top *.onlinecasinosthatpayrealmoney.top
pg0002.my *.pg0002.my
reliablegreenculture.xyz *.reliablegreenculture.xyz
tinkerbox.co *.tinkerbox.co *.www.tinkerbox.co
wdlay.vip *.wdlay.vip
webuyhouseshonoluluhi.online *.webuyhouseshonoluluhi.online
xn--wusp30j.org *.xn--wusp30j.org
yortan.com *.yortan.com
zamowienie-56m21xqv2dgf0znb46ryp1.onl *.zamowienie-56m21xqv2dgf0znb46ryp1.onl
zesza.cc *.zesza.cc