Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=gumilang.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:FB:E5:73:84:FB:32:36:D1:50:3B:BB:60:72:8B:8F:01:F2:D2:08:FE:93:1F:F2:70:74:3C:E7:04:F7:D0:43
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
okochi.com
*.okochi.com
*.vpn1.okochi.com
*.ww1.okochi.com
05030.net
*.05030.net
06093.loan
*.06093.loan
125228.loan
*.125228.loan
130026.gdn
*.130026.gdn
308972.cc
*.308972.cc
3s9t4w.shop
*.3s9t4w.shop
40598y.co
*.40598y.co
411341.co
*.411341.co
53926.mobi
*.53926.mobi
55580.boston
*.55580.boston
59418.loan
*.59418.loan
608415.vip
*.608415.vip
72731.locker
*.72731.locker
*.5q45p.7daysale.com
7daysale.com
*.7daysale.com
*.assets.7daysale.com
*.bnohodzf.7daysale.com
*.bzwzm5t.7daysale.com
*.d6ej9oaq.7daysale.com
*.intelligence.7daysale.com
*.q0zh9x.7daysale.com
7lwbq9.shop
*.7lwbq9.shop
961523.top
*.961523.top
99754.mobi
*.99754.mobi
am272.cc
*.am272.cc
apnamajdoor.mom
*.apnamajdoor.mom
bcnkvs.top
*.bcnkvs.top
brightseek.xyz
*.brightseek.xyz
ceemy.gdn
*.ceemy.gdn
christensen-benefits.us
*.christensen-benefits.us
dentalimplants068392.icu
*.dentalimplants068392.icu
fireprooffencing.com
*.fireprooffencing.com
gumilang.com
*.gumilang.com
*.rdweb.gumilang.com
hvduc.gdn
*.hvduc.gdn
icbeckaro.cc
*.icbeckaro.cc
lakehometours.com
*.lakehometours.com
meemy.gdn
*.meemy.gdn
nobetcinoter.org
*.nobetcinoter.org
passportchain.com
*.passportchain.com
pgoom.cc
*.pgoom.cc
pgoqv.cc
*.pgoqv.cc
pipelike.com
*.pipelike.com
reasonbased.com
*.reasonbased.com
tvfrnhxgmphqrl.cc
*.tvfrnhxgmphqrl.cc
yw3y798g.top
*.yw3y798g.top
Other domains in certificate