76/100 SECURITY SCORE

Certificate Information

Subject
CN=lindacoffeeconnection.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 21, 2026
Valid Until
May 22, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:1B:46:B0:98:44:16:2F:5E:B2:8B:6C:3D:A2:23:83:CB:44:C0:A1:36:0C:94:9E:CC:C6:20:63:23:AE:73:BA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
advancedmemoryformula.us *.advancedmemoryformula.us *.ww38.advancedmemoryformula.us

Other domains in certificate

alfornoitaliankitchen.co.uk *.alfornoitaliankitchen.co.uk *.cpcontacts.alfornoitaliankitchen.co.uk
*.api.bunyips.com bunyips.com *.bunyips.com *.dev.bunyips.com *.mail.bunyips.com *.rustore.bunyips.com *.sitemaps.bunyips.com *.test.bunyips.com *.ww1.bunyips.com *.ww17.bunyips.com *.ww38.bunyips.com
*.1.ghln.be *.35.ghln.be *.accounts.ghln.be *.admin.ghln.be *.api.ghln.be *.blog.ghln.be *.bts.ghln.be *.demo.ghln.be *.emv1.ghln.be *.forum.ghln.be ghln.be *.ghln.be *.goudenf1.ghln.be *.intranet.ghln.be *.jenkins.ghln.be *.m.ghln.be *.old.ghln.be *.pipeline-preprod.ghln.be *.remote.ghln.be *.s1.ghln.be *.ssp.ghln.be *.store.ghln.be *.temp.ghln.be *.test.ghln.be *.uat.ghln.be *.users.ghln.be *.vn.ghln.be *.webmail.ghln.be *.ww1.ghln.be *.ww2.ghln.be *.ytdbcpanel.ghln.be
lindacoffeeconnection.com *.lindacoffeeconnection.com *.radio.lindacoffeeconnection.com
my-bigtoe.com *.my-bigtoe.com *.ww12.my-bigtoe.com
*.admin.samair.com *.alex.samair.com *.articles.samair.com *.books.samair.com *.client.samair.com *.comune.samair.com *.de.samair.com *.games.samair.com *.gold.samair.com *.m.samair.com *.map.samair.com *.mx.samair.com *.net.samair.com *.openvpn.samair.com *.radio.samair.com samair.com *.samair.com *.secure.samair.com *.stage.samair.com *.status.samair.com *.test.samair.com *.trashmail.samair.com *.umpqestatus.samair.com *.ww16.samair.com *.ww17.samair.com
slslknet.org *.slslknet.org *.ww7.slslknet.org
stereo-noise.com *.stereo-noise.com
*.a.thefrappening.so thefrappening.so *.thefrappening.so
*.givemen.toyotq.com toyotq.com *.toyotq.com