76/100 SECURITY SCORE

Certificate Information

Subject
CN=draq.tech
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 09, 2026
Valid Until
May 10, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
65:94:8A:CB:FA:2C:39:84:E1:C6:A4:F0:F9:FA:88:AA:83:5E:54:E9:7B:58:C9:BE:1C:E7:67:85:DA:D3:FC:70
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

83 domains
mdraclick6.com *.mdraclick6.com *.admin.mdraclick6.com *.tracking.mdraclick6.com *.www.mdraclick6.com

Other domains in certificate

allgovtjobbd.com *.allgovtjobbd.com
burnvitta.site *.burnvitta.site
castle247locksmiths.co.uk *.castle247locksmiths.co.uk
draq.tech *.draq.tech
flashslotsbet.com *.flashslotsbet.com *.socket.flashslotsbet.com
gtbonline.vip *.gtbonline.vip *.ww25.gtbonline.vip
intresmart.tech *.intresmart.tech
ixleads.online *.ixleads.online
javyp.com *.javyp.com *.sitemap.javyp.com
*.552.kkm.me *.hostmaster.kkm.me kkm.me *.kkm.me *.ww25.kkm.me *.www.kkm.me
leonovaschool.site *.leonovaschool.site
marco-berti.com *.marco-berti.com
moviecottage26.sbs *.moviecottage26.sbs
newsinsightify.com *.newsinsightify.com
*.mlnotasexclusivas.notiexclusivaspr7.com *.notasdeldiaoficial.notiexclusivaspr7.com *.noticiasdeldiapr7.notiexclusivaspr7.com notiexclusivaspr7.com *.notiexclusivaspr7.com *.twelvemuycurioso.notiexclusivaspr7.com
*.app.omushugugu.com omushugugu.com *.omushugugu.com *.shop.omushugugu.com *.shop1.omushugugu.com *.shop3.omushugugu.com *.vanvaa.omushugugu.com
pennxiang.space *.pennxiang.space
pintereststyles.com *.pintereststyles.com *.ww25.pintereststyles.com
pixelextended.tech *.pixelextended.tech
rudd.id.au *.rudd.id.au *.webmail.rudd.id.au
security1qstbank.com *.security1qstbank.com *.ww25.security1qstbank.com
*.link.shobarjobs.com *.qna.shobarjobs.com shobarjobs.com *.shobarjobs.com
thamesriver.co *.thamesriver.co
*.shop.trysnips.com trysnips.com *.trysnips.com
tunezpoint.com *.tunezpoint.com
*.firmwarefox.viralallnews.com *.liveftpserver.viralallnews.com *.usa.viralallnews.com viralallnews.com *.viralallnews.com *.wicketbd.viralallnews.com