76/100 SECURITY SCORE

Certificate Information

Subject
CN=estop1.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 07, 2026
Valid Until
August 05, 2026 65 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:49:75:90:DD:AF:E1:8E:07:29:7C:E9:B8:6C:FF:53:2D:71:0E:60:88:BA:92:63:46:7B:6F:C0:F9:D7:BF:C6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
paperpal.io *.paperpal.io *.analytics.paperpal.io *.app.paperpal.io *.beta.paperpal.io *.help.paperpal.io *.kpi.paperpal.io *.set.paperpal.io *.ww38.paperpal.io

Other domains in certificate

abislab.io *.abislab.io
alertmail.net *.alertmail.net
*.api.borismoiseev.pro borismoiseev.pro *.borismoiseev.pro
*.analytics.buyingaweddingring.com *.bi.buyingaweddingring.com buyingaweddingring.com *.buyingaweddingring.com *.insight.buyingaweddingring.com *.production.buyingaweddingring.com *.staging.buyingaweddingring.com *.users.buyingaweddingring.com *.ww1.buyingaweddingring.com
*.backend.cedono.com cedono.com *.cedono.com *.demo.cedono.com *.forecast.cedono.com *.metrics.cedono.com
cleaningservicesadelaide.com.au *.cleaningservicesadelaide.com.au *.cpcontacts.cleaningservicesadelaide.com.au *.mail.cleaningservicesadelaide.com.au
ea0695.bet *.ea0695.bet
estop1.com *.estop1.com *.ww38.estop1.com
euromide.info *.euromide.info
*.bi.finishingtouchupholstery.com *.demo.finishingtouchupholstery.com *.dev.finishingtouchupholstery.com *.dev2.finishingtouchupholstery.com finishingtouchupholstery.com *.finishingtouchupholstery.com *.flowiseai.finishingtouchupholstery.com *.mx.finishingtouchupholstery.com *.ww17.finishingtouchupholstery.com *.ww25.finishingtouchupholstery.com
gani.live *.gani.live
*.bgptools-wildcard-confirmed.general-catalog.net *.client.general-catalog.net *.gate.general-catalog.net general-catalog.net *.general-catalog.net *.hostmaster.general-catalog.net *.m.general-catalog.net *.mail.general-catalog.net *.mta-sts.general-catalog.net *.ns1.general-catalog.net *.ns2.general-catalog.net *.portal.general-catalog.net *.random.general-catalog.net *.sitemaps.general-catalog.net *.sso.general-catalog.net *.static.general-catalog.net *.wildcard.general-catalog.net *.ws.general-catalog.net *.wss.general-catalog.net *.ww1.general-catalog.net *.ww12.general-catalog.net *.ww7.general-catalog.net *.ww99.general-catalog.net *.www.general-catalog.net
hochiminhtv.com *.hochiminhtv.com
*.cpcontacts.howtokillatree.com howtokillatree.com *.howtokillatree.com
starfield.au *.starfield.au
umhealth.live *.umhealth.live
urso.studio *.urso.studio