Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=nationgeographic.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 12, 2026
Valid Until
July 11, 2026
36 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
47:5F:7C:26:39:BF:ED:95:74:6B:92:11:6E:D9:AE:18:07:66:D6:07:AD:B3:51:BD:03:67:D7:CB:46:6C:09:CC
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
72 domains
stary.io
*.stary.io
*.analitik.stary.io
*.analysis.stary.io
*.config.stary.io
*.dashboards.stary.io
*.dwh-replication.stary.io
*.edge.stary.io
*.hostmaster.stary.io
*.id.stary.io
*.insights.stary.io
*.my.stary.io
*.pop3.stary.io
*.session.stary.io
*.static.stary.io
*.sup.stary.io
*.tools.stary.io
*.www.stary.io
activepr.cc
*.activepr.cc
*.c35g5aod5d.activepr.cc
*.ww38.activepr.cc
*.api.ballerinan.online
*.autodiscover.ballerinan.online
ballerinan.online
*.ballerinan.online
*.cpanel.ballerinan.online
*.cpcalendars.ballerinan.online
*.cpcontacts.ballerinan.online
*.mail.ballerinan.online
*.vihkpu5fnzz5y57b.ballerinan.online
*.webdisk.ballerinan.online
*.webmail.ballerinan.online
diversreefkarachi.co
*.diversreefkarachi.co
firstclassnurses.biz
*.firstclassnurses.biz
futemax2.live
*.futemax2.live
*.m.futemax2.live
insurancehunter.biz
*.insurancehunter.biz
jimuin.com
*.jimuin.com
*.adventure.nationgeographic.com
*.education.nationgeographic.com
*.enviorment.nationgeographic.com
*.enviornment.nationgeographic.com
*.kid.nationgeographic.com
*.kids.nationgeographic.com
nationgeographic.com
*.nationgeographic.com
*.news.nationgeographic.com
*.ngm.nationgeographic.com
*.plasma.nationgeographic.com
*.science.nationgeographic.com
*.travel.nationgeographic.com
*.video.nationgeographic.com
*.w.nationgeographic.com
*.xn--yourshot-hm3d.nationgeographic.com
newstoday82.store
*.newstoday82.store
*.ww38.newstoday82.store
peipeicoinsol.vip
*.peipeicoinsol.vip
*.rustore.peipeicoinsol.vip
*.www.peipeicoinsol.vip
vn123win.org
*.vn123win.org
*.www.vn123win.org
xxxz.work
*.xxxz.work
Other domains in certificate