77/100 SECURITY SCORE

Certificate Information

Subject
CN=dothabit.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 05, 2025
Valid Until
March 05, 2026 65 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
77:9F:AF:95:95:49:C7:F0:56:1D:5B:F6:2C:D5:BD:2B:A6:41:84:95:C5:78:66:72:5E:C9:0B:47:A7:61:77:FF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
admin.myboardprep.com

Other domains in certificate

backoffice.express.agora.pe
aibrary.co
alejandrodvportfolio.com
www.ambuj.tech
www.ampproject.org
wishlist.anthonyierace.be
aperox.com
mint.art-coiner.com
hwrabot.arvat.tech
www.ask-music.com
askhermes.io
www.barackdafarialima.com
basic-programmer.com
bellicosesecurity.lk
borala.cloud
breejeshrathod.com
xn--18aos-qta.canariasahora.es
www.chapterly.in
tsbu.co.id
app2.citycar.co.il
accds.co.in www.accds.co.in
www.codegraphy.in
vote.codeshovel.com
codingwithcornel.ch
decodingbyte.com
dothabit.com
www.dugoly.com
elzaswmc.com
espacioresidencial.com www.espacioresidencial.com
events4you.in
auth.examry.com
flyo.link
footz.football
galoiss.com
grafikaeclipse.com www.grafikaeclipse.com
gvm.pt
sanity.houseofmath.com
admin.ideashots.ai
app-invest.influxfin.com
wire-beta.io-fund.com
www.iservicio.mx
itboomi.com
ka32.in
kulan.business
link.luna.ac
margauxmasson.com
api.nena.mary.africa
measurementhub.dev
mi11er.net
www.miraserv.com.br
team.mulhouse.fr
xn--ls8h.multiverse.ai
auth.myfestivalplan.com
www.nazifautama.com
www.ojstudio.com.br
onlyagents365.net
www.onskydigital.com
paalgyula.com
pikyard.in
dev.piscada.online
politicas.prestaservi.net
rappid.link
www.rasika.info
rsbg.ch
track.rxoconnectmain.rxo.com
transfers.sastaticket.pk
www.sci-dict.org
shop5.slotendrecht.nl shop8.slotendrecht.nl
xn--0ci.sparkstmc.org
www.tafadzwamhizha.com
www.talentosit.app
get.trade.re
ia-ml.univ-amu.fr
landscape.vipro.online
pets-forum.vlatko.mk
admin-dev1.vnlp.ai agent-test.rtm.vnlp.ai callio.vnlp.ai labelbox-prod.vnlp.ai livechat.callio.vnlp.ai v9tech.vnlp.ai va-ocb.vnlp.ai
vukoo.app
wcbfit.com.br
blog.samsul.web.id
www.xn--95h.gg
xn--ansamen-t2a.at
www.xn--e6h.gg
xn--gtu78gk2rdv6a.1.xn--5gqr11h.net
www.xn--skrtsj-rua.com
www.xn--skrtsj-rua.no
xn--y8jyd0a4c.jp
yashwinibeautyparlour.in
yowai.band
auth.yumzi.app