Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=y63.me
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 22, 2026
Valid Until
August 20, 2026
63 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
43:83:C2:7E:CD:FF:A3:39:FD:F0:BE:34:50:77:C4:55:D5:BD:D9:80:BC:E3:C6:7C:F9:C4:60:13:1C:5A:4A:27
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ah-it.com
*.ah-it.com
0523c8be736a24f9ce72.club
*.0523c8be736a24f9ce72.club
3sgisfgfkd.cc
*.3sgisfgfkd.cc
41029.one
*.41029.one
70659.tel
*.70659.tel
89400.blog
*.89400.blog
af157cd3d6fafb30.com
*.af157cd3d6fafb30.com
ajwcmr.auction
*.ajwcmr.auction
amaniwomensempowerment.org
*.amaniwomensempowerment.org
amanterus.lol
*.amanterus.lol
aonelube.com
*.aonelube.com
athmenu.com
*.athmenu.com
audy88fr.cfd
*.audy88fr.cfd
audy88fr.cyou
*.audy88fr.cyou
audy88fr.pics
*.audy88fr.pics
audy88fr.sbs
*.audy88fr.sbs
autoslot88go.cyou
*.autoslot88go.cyou
avlpsicologia.com
*.avlpsicologia.com
chinabug.net
*.chinabug.net
ddccndcnjdcd-dcbdcdcdb.sbs
*.ddccndcnjdcd-dcbdcdcdb.sbs
defghi.auction
*.defghi.auction
f78r.shop
*.f78r.shop
gadgetdokan.xyz
*.gadgetdokan.xyz
gczdy.gdn
*.gczdy.gdn
geometrydashapk.io
*.geometrydashapk.io
geosagespatial.com
*.geosagespatial.com
hpimodelcar.com
*.hpimodelcar.com
iamkevinmccarthy.com
*.iamkevinmccarthy.com
morisha.com
*.morisha.com
navrastv.com
*.navrastv.com
nervela.com
*.nervela.com
nesapedia.com
*.nesapedia.com
pcaindia.com
*.pcaindia.com
pcupjd.co
*.pcupjd.co
professionalweddingwave.beauty
*.professionalweddingwave.beauty
recruitment-bet365.com
*.recruitment-bet365.com
rich.network
*.rich.network
rosmatoursandtravel.com
*.rosmatoursandtravel.com
safedogsears.com
*.safedogsears.com
topmaxsuppliers.com
*.topmaxsuppliers.com
xkzob.win
*.xkzob.win
y2etkl.cyou
*.y2etkl.cyou
y63.me
*.y63.me
zippyassignment.com
*.zippyassignment.com
zoqart.com
*.zoqart.com
Other domains in certificate