76/100 SECURITY SCORE

Certificate Information

Subject
CN=22720.gdn
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 02, 2026
Valid Until
July 31, 2026 61 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:BB:DD:79:57:03:7B:06:34:0B:A4:7F:30:41:F4:A1:87:3A:50:38:17:B3:59:9D:43:FF:84:AC:26:8E:75:07
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
brandingagentur.com *.brandingagentur.com

Other domains in certificate

20513.lgbt *.20513.lgbt
22720.gdn *.22720.gdn
365q.net *.365q.net
37683.gdn *.37683.gdn
3z57hbqq.cn *.3z57hbqq.cn
568279.top *.568279.top
639825.top *.639825.top
astdgreaterbroward.org *.astdgreaterbroward.org
avastaresorts.com *.avastaresorts.com
careerinspireplan.xyz *.careerinspireplan.xyz
carpetcleaningglendale.com *.carpetcleaningglendale.com
cash-avalanches.com *.cash-avalanches.com
ecovennsolutions.com *.ecovennsolutions.com
expectgod.org *.expectgod.org
fissionengineering.com *.fissionengineering.com
fitsport.xyz *.fitsport.xyz
iesmuga.com *.iesmuga.com
innflightrestaurants.com *.innflightrestaurants.com
investindia.in *.investindia.in
jk356.vip *.jk356.vip
kangaroocare.org *.kangaroocare.org
kerryway.net *.kerryway.net
leon-zerkalo-azryv.xyz *.leon-zerkalo-azryv.xyz
leon-zerkalo-fdrwz.xyz *.leon-zerkalo-fdrwz.xyz
leonbets-casino-7nixu.xyz *.leonbets-casino-7nixu.xyz
lerros.energy *.lerros.energy
lokicasino-at.com *.lokicasino-at.com
losloosers.com *.losloosers.com
mataibekov.com *.mataibekov.com
myreadyjourney.com *.myreadyjourney.com
narmstoday-digital.com *.narmstoday-digital.com
openvogsy.com *.openvogsy.com
orchardknobmiddle.com *.orchardknobmiddle.com
u86g.cyou *.u86g.cyou
usavisash.com *.usavisash.com
vcjgxek.shop *.vcjgxek.shop
virginiabeachlistings.com *.virginiabeachlistings.com
wadhwani.in *.wadhwani.in
weddingserenity.beauty *.weddingserenity.beauty
ydyse5.com *.ydyse5.com
yvqwad.com *.yvqwad.com
z75y.cyou *.z75y.cyou
z7kd4356.cn *.z7kd4356.cn
zenithleadership.com *.zenithleadership.com