Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=scoops.com.au
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 22, 2026
Valid Until
August 20, 2026 61 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
17:EA:28:68:95:4B:22:45:DB:A5:75:5D:4A:0F:8B:99:E8:0E:26:F8:BA:A6:C7:50:09:A1:D6:85:BC:C5:C4:A7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
annuitybtc.com *.annuitybtc.com *.access.annuitybtc.com *.app.annuitybtc.com *.apps.annuitybtc.com *.desktop.annuitybtc.com *.gateway.annuitybtc.com *.gp.annuitybtc.com *.ra.annuitybtc.com *.rd.annuitybtc.com *.rdp.annuitybtc.com *.rds.annuitybtc.com *.rdweb.annuitybtc.com *.remote.annuitybtc.com *.remoto.annuitybtc.com *.secure.annuitybtc.com *.sitemap.annuitybtc.com *.sitemaps.annuitybtc.com *.sslvpn.annuitybtc.com *.ts.annuitybtc.com *.vdi.annuitybtc.com *.vpn.annuitybtc.com *.vpn1.annuitybtc.com *.vpn2.annuitybtc.com *.webvpn.annuitybtc.com *.wildcard.annuitybtc.com

Other domains in certificate

bewell-connect.de *.bewell-connect.de
diksa.website *.diksa.website *.hayr.diksa.website *.mask.diksa.website *.maxigrov.diksa.website *.official.diksa.website *.oficial.diksa.website *.random.diksa.website *.restorer.diksa.website
disasterloanassistance.com *.disasterloanassistance.com *.git.disasterloanassistance.com
divertivoto.com *.divertivoto.com
mandmswim.co.uk *.mandmswim.co.uk
*.dev.meridianpark.co.uk meridianpark.co.uk *.meridianpark.co.uk *.staging-steppyweb.meridianpark.co.uk *.taxi.meridianpark.co.uk *.www.meridianpark.co.uk
onlinekerstkado.nl *.onlinekerstkado.nl
outofthecoldhalifax.org *.outofthecoldhalifax.org
realhotnews24.store *.realhotnews24.store *.www.realhotnews24.store
*.2.satcon.dev *.71c9f87e-e7fd-41b6-a43c-8f1239d340c2.satcon.dev *.api.satcon.dev *.d07f682d-9931-4886-86dc-a23426687977.satcon.dev *.dev.satcon.dev *.gepwxmedia.satcon.dev *.manager.satcon.dev *.media.satcon.dev *.members.satcon.dev *.new.satcon.dev satcon.dev *.satcon.dev *.www02.satcon.dev *.y3de3s.satcon.dev
scoops.com.au *.scoops.com.au
theniche.co *.theniche.co
*.mail.thepropertyshopross.co.uk thepropertyshopross.co.uk *.thepropertyshopross.co.uk
*.7yej22.udianzi.vip *.api.udianzi.vip *.login.udianzi.vip udianzi.vip *.udianzi.vip *.vip.udianzi.vip
valleywellnesscenter-eg.com *.valleywellnesscenter-eg.com
*.random.worldbeverageduluth.com worldbeverageduluth.com *.worldbeverageduluth.com