Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=yyshop.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026 70 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0F:85:B1:94:2A:39:78:D3:21:C2:8A:D1:17:59:C5:EC:0D:44:69:F2:88:45:5B:55:BB:73:7D:48:5A:26:90:77
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
adtrk.com *.adtrk.com *.crm.adtrk.com *.m.adtrk.com

Other domains in certificate

171775.cc *.171775.cc
bmeti.biz *.bmeti.biz *.login.bmeti.biz *.m.bmeti.biz
*.525v4.bom888.top *.5jsd7.bom888.top *.6s98n.bom888.top *.6y8gt.bom888.top *.89wkp.bom888.top *.95lw2.bom888.top *.96c54.bom888.top bom888.top *.bom888.top *.ebwif.bom888.top *.gjdvb.bom888.top *.he00g.bom888.top *.i51qg.bom888.top *.jyikv.bom888.top *.ks0v9.bom888.top *.kwid9.bom888.top *.nemln.bom888.top *.nktjv.bom888.top *.orrwv.bom888.top *.osc36.bom888.top *.rczhl.bom888.top *.rkuvx.bom888.top *.sbd1u.bom888.top *.uugt9.bom888.top *.v3ywp.bom888.top *.v6j6e.bom888.top *.www.bom888.top *.x7pal.bom888.top *.y04uw.bom888.top *.z44ag.bom888.top
catching.in *.catching.in *.m.catching.in
chicosychicas.com *.chicosychicas.com
dive-international.net *.dive-international.net *.southafrica.dive-international.net *.www.dive-international.net
*.creekside.epic.cm epic.cm *.epic.cm *.share.epic.cm *.training.epic.cm *.ucs.epic.cm *.userweb.epic.cm *.vps.epic.cm *.vps2.epic.cm *.wildcard.epic.cm *.ww38.epic.cm
*.32.kkim.life kkim.life *.kkim.life
room17.games *.room17.games *.store.room17.games
*.client.samsmall.org *.office.samsmall.org *.portal.samsmall.org *.remoteaccess.samsmall.org samsmall.org *.samsmall.org *.sslvpn.samsmall.org *.vpn.samsmall.org *.vpn2.samsmall.org *.web.samsmall.org
*.random.veza.live veza.live *.veza.live
xrevi.com *.xrevi.com *.zenli.xrevi.com
*.pae29.yyshop.com *.portal.yyshop.com *.school.yyshop.com *.webconnect.yyshop.com *.wildcard.yyshop.com yyshop.com *.yyshop.com