76/100 SECURITY SCORE

Certificate Information

Subject
CN=nbook.app
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 04, 2026
Valid Until
September 02, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
22:75:1B:8D:83:77:27:0F:A9:A5:C6:34:1A:F8:02:94:1E:40:C0:93:DA:F2:A7:68:A2:FD:2C:A3:63:F7:53:AE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
xn--btr.com *.xn--btr.com *.4e406d8d-7f4c-45cf-ac50-7c84b2243091.xn--btr.com *.admin.xn--btr.com *.analytics-demo.xn--btr.com *.api.xn--btr.com *.app.xn--btr.com *.backend.xn--btr.com *.bbs.xn--btr.com *.blog.xn--btr.com *.demo.xn--btr.com *.dev.xn--btr.com *.m.xn--btr.com *.root.xn--btr.com *.sap.xn--btr.com *.staging.xn--btr.com *.txad.xn--btr.com *.vpcs.xn--btr.com *.vpn.xn--btr.com *.www.xn--btr.com

Other domains in certificate

*.app.myaibetgroup.com *.come6883df.myaibetgroup.com *.fcwtgl.myaibetgroup.com *.mail.myaibetgroup.com *.mailer.myaibetgroup.com *.members.myaibetgroup.com myaibetgroup.com *.myaibetgroup.com *.ovpnqv2.myaibetgroup.com *.qa.myaibetgroup.com *.secure.myaibetgroup.com *.stg.myaibetgroup.com *.test.myaibetgroup.com *.web.myaibetgroup.com
*.access.nbook.app *.admin.nbook.app *.api.nbook.app *.app.nbook.app *.apps.nbook.app *.assets.nbook.app *.backup.nbook.app *.blog.nbook.app *.bxcqfvpn.nbook.app *.c2923a30-2b6a-430c-ae67-d64fbff389ad.nbook.app *.cddf9a8d-203a-4bc6-bec2-895fd041c6f7.nbook.app *.connect.nbook.app *.demo.nbook.app *.desktop.nbook.app *.dev.nbook.app *.ekiswrdp.nbook.app *.gateway.nbook.app *.gp.nbook.app *.m.nbook.app nbook.app *.nbook.app *.oqiwtgp.nbook.app *.rd.nbook.app *.rdp.nbook.app *.rdweb.nbook.app *.remoteapp.nbook.app *.remoto.nbook.app *.rustore.nbook.app *.sdlwtekiswrdp.nbook.app *.secure.nbook.app *.ssl.nbook.app *.sslvpn.nbook.app *.staging.nbook.app *.test.nbook.app *.vdi.nbook.app *.vpn.nbook.app *.vpn2.nbook.app *.webvpn.nbook.app
*.api.orgevia.com *.app.orgevia.com *.assets.orgevia.com *.demo.orgevia.com *.dev.orgevia.com *.mwbvoassets.orgevia.com *.new.orgevia.com orgevia.com *.orgevia.com *.staging.orgevia.com *.test.orgevia.com
*.app.tevasandalsoutlet.com tevasandalsoutlet.com *.tevasandalsoutlet.com
*.app.xn--vermgenscontrolling-t6b.info xn--vermgenscontrolling-t6b.info *.xn--vermgenscontrolling-t6b.info