Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=yyshop.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0F:85:B1:94:2A:39:78:D3:21:C2:8A:D1:17:59:C5:EC:0D:44:69:F2:88:45:5B:55:BB:73:7D:48:5A:26:90:77
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
adtrk.com
*.adtrk.com
*.crm.adtrk.com
*.m.adtrk.com
171775.cc
*.171775.cc
bmeti.biz
*.bmeti.biz
*.login.bmeti.biz
*.m.bmeti.biz
*.525v4.bom888.top
*.5jsd7.bom888.top
*.6s98n.bom888.top
*.6y8gt.bom888.top
*.89wkp.bom888.top
*.95lw2.bom888.top
*.96c54.bom888.top
bom888.top
*.bom888.top
*.ebwif.bom888.top
*.gjdvb.bom888.top
*.he00g.bom888.top
*.i51qg.bom888.top
*.jyikv.bom888.top
*.ks0v9.bom888.top
*.kwid9.bom888.top
*.nemln.bom888.top
*.nktjv.bom888.top
*.orrwv.bom888.top
*.osc36.bom888.top
*.rczhl.bom888.top
*.rkuvx.bom888.top
*.sbd1u.bom888.top
*.uugt9.bom888.top
*.v3ywp.bom888.top
*.v6j6e.bom888.top
*.www.bom888.top
*.x7pal.bom888.top
*.y04uw.bom888.top
*.z44ag.bom888.top
catching.in
*.catching.in
*.m.catching.in
chicosychicas.com
*.chicosychicas.com
dive-international.net
*.dive-international.net
*.southafrica.dive-international.net
*.www.dive-international.net
*.creekside.epic.cm
epic.cm
*.epic.cm
*.share.epic.cm
*.training.epic.cm
*.ucs.epic.cm
*.userweb.epic.cm
*.vps.epic.cm
*.vps2.epic.cm
*.wildcard.epic.cm
*.ww38.epic.cm
*.32.kkim.life
kkim.life
*.kkim.life
room17.games
*.room17.games
*.store.room17.games
*.client.samsmall.org
*.office.samsmall.org
*.portal.samsmall.org
*.remoteaccess.samsmall.org
samsmall.org
*.samsmall.org
*.sslvpn.samsmall.org
*.vpn.samsmall.org
*.vpn2.samsmall.org
*.web.samsmall.org
*.random.veza.live
veza.live
*.veza.live
xrevi.com
*.xrevi.com
*.zenli.xrevi.com
*.pae29.yyshop.com
*.portal.yyshop.com
*.school.yyshop.com
*.webconnect.yyshop.com
*.wildcard.yyshop.com
yyshop.com
*.yyshop.com
Other domains in certificate