76/100 SECURITY SCORE

Certificate Information

Subject
CN=thebrightbeacon.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 21, 2026
Valid Until
August 19, 2026 75 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
69:12:C4:5D:7D:A2:3F:3A:D3:DF:2D:81:10:5A:9A:23:AD:51:D6:F9:CD:44:80:B1:DB:92:B2:2F:6C:E0:71:AB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bigbullship.com *.bigbullship.com *.admin.bigbullship.com *.app.bigbullship.com *.assets.bigbullship.com *.demo.bigbullship.com *.dev.bigbullship.com *.test.bigbullship.com

Other domains in certificate

aqtherapy.com *.aqtherapy.com *.jbfxm0.aqtherapy.com
*.42.beautifulhomespaces.org beautifulhomespaces.org *.beautifulhomespaces.org *.dl0qvl.beautifulhomespaces.org
*.billing.cazinovulcan-stars.xyz cazinovulcan-stars.xyz *.cazinovulcan-stars.xyz *.members.cazinovulcan-stars.xyz *.pay.cazinovulcan-stars.xyz *.store.cazinovulcan-stars.xyz
christianlouboutinsaleflagshipstore.com *.christianlouboutinsaleflagshipstore.com *.petsfamous.christianlouboutinsaleflagshipstore.com
creativedrivesandpatiosltd.co.uk *.creativedrivesandpatiosltd.co.uk
*.api.diamantes.site *.autodiscover.diamantes.site diamantes.site *.diamantes.site *.ww25.diamantes.site *.ww38.diamantes.site
immersivenode.com *.immersivenode.com *.www.immersivenode.com
*.apb0v4.jagnes.com *.cpanel.jagnes.com jagnes.com *.jagnes.com *.m.jagnes.com
*.aidslifecycle.myride.org *.gbzquns2.myride.org *.hostmaster.myride.org myride.org *.myride.org
*.analyze.secretdreams.it *.dashboard.secretdreams.it *.dashboards.secretdreams.it *.data.secretdreams.it *.m.secretdreams.it *.mx.secretdreams.it secretdreams.it *.secretdreams.it
*.kiflvcopfjr.thebrightbeacon.com *.ocytukarnd.thebrightbeacon.com *.rabuceraveqk.thebrightbeacon.com thebrightbeacon.com *.thebrightbeacon.com *.ww38.thebrightbeacon.com
*.hostmaster.topfinanza.it topfinanza.it *.topfinanza.it *.www.topfinanza.it
*.a.topflightrealty.info *.admin.topflightrealty.info *.app.topflightrealty.info *.assets.topflightrealty.info *.cloudflare-resolve-to.topflightrealty.info *.demo.topflightrealty.info *.exchange.topflightrealty.info *.jukbxadmin.topflightrealty.info *.m.topflightrealty.info *.m9fh7d.topflightrealty.info *.members.topflightrealty.info *.outlook.topflightrealty.info *.risdgdemo.topflightrealty.info topflightrealty.info *.topflightrealty.info *.www.topflightrealty.info *.zgoyojukbxadmin.topflightrealty.info
*.api.yogacourse.in *.www.yogacourse.in yogacourse.in *.yogacourse.in
*.main.z7170cpd64pz9ei7b365.xyz *.ww38.z7170cpd64pz9ei7b365.xyz z7170cpd64pz9ei7b365.xyz *.z7170cpd64pz9ei7b365.xyz
zbahisler.com *.zbahisler.com