Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=calmstrategygroup.xyz
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 03, 2026
Valid Until
September 01, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0B:B4:2F:79:5C:B9:E1:69:D7:2D:00:5C:F4:63:99:24:81:5B:0F:78:F6:D9:12:E4:11:99:49:C3:E3:10:81:47
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
evenal.com
*.evenal.com
0010.my
*.0010.my
2035555ba.xyz
*.2035555ba.xyz
28vidas.click
*.28vidas.click
40905.co
*.40905.co
41313.my
*.41313.my
440952.xyz
*.440952.xyz
48179.top
*.48179.top
5d47jw.xyz
*.5d47jw.xyz
5rirte.cyou
*.5rirte.cyou
84p2.com
*.84p2.com
9mvw.xyz
*.9mvw.xyz
a396yhc.top
*.a396yhc.top
austinbrooklyn.shop
*.austinbrooklyn.shop
axelliantchannel.com
*.axelliantchannel.com
bangkokvpn.cc
*.bangkokvpn.cc
blubboard.xyz
*.blubboard.xyz
calmstrategygroup.xyz
*.calmstrategygroup.xyz
claimedai.com
*.claimedai.com
communitypledge.com
*.communitypledge.com
crypto-view.com
*.crypto-view.com
cutenakedgirls.xyz
*.cutenakedgirls.xyz
dacitic.com
*.dacitic.com
daflash.buzz
*.daflash.buzz
dontech.us
*.dontech.us
fajipq.cc
*.fajipq.cc
firstwhistlesport.com
*.firstwhistlesport.com
fulfillment.click
*.fulfillment.click
furniturehub.today
*.furniturehub.today
furystrategy233.shop
*.furystrategy233.shop
getschillerlegal.digital
*.getschillerlegal.digital
gij9i.xyz
*.gij9i.xyz
hh70168.cc
*.hh70168.cc
hottestemail.com
*.hottestemail.com
hyc50666.cc
*.hyc50666.cc
jk3996685.xyz
*.jk3996685.xyz
jwlsn.xyz
*.jwlsn.xyz
kornlongallwin.com
*.kornlongallwin.com
lishnutech.com
*.lishnutech.com
mirrobotics.com
*.mirrobotics.com
noneofuss.com
*.noneofuss.com
od-94428.xyz
*.od-94428.xyz
ouths.xyz
*.ouths.xyz
polling.today
*.polling.today
promosyonnzaman.shop
*.promosyonnzaman.shop
Other domains in certificate