76/100 SECURITY SCORE

Certificate Information

Subject
CN=housemortgages.au
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D4:F0:36:15:B1:98:3F:3D:08:F1:F9:14:D2:DA:69:3B:32:0D:D5:C7:B2:58:F9:1D:27:F9:E8:96:BE:97:42:5F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
creativamente.com *.creativamente.com *.api.creativamente.com *.ass.creativamente.com *.crm.creativamente.com *.dev.creativamente.com *.rustore.creativamente.com *.sitemap.creativamente.com *.sitemaps.creativamente.com *.ww1.creativamente.com *.ww11.creativamente.com *.ww25.creativamente.com

Other domains in certificate

*.backup.bemelman.com bemelman.com *.bemelman.com *.beta.bemelman.com *.blog.bemelman.com *.crm.bemelman.com *.forum.bemelman.com *.hostmaster.bemelman.com *.random.bemelman.com *.ww1.bemelman.com *.ww11.bemelman.com *.ww16.bemelman.com *.ww17.bemelman.com *.ww25.bemelman.com *.ww38.bemelman.com
horticulturalists.au *.horticulturalists.au
housemortgages.au *.housemortgages.au
*.blog.lavetra.com *.crm.lavetra.com *.demo.lavetra.com *.ebay.lavetra.com *.forum.lavetra.com *.hostmaster.lavetra.com lavetra.com *.lavetra.com *.webmail.lavetra.com *.ww.lavetra.com *.ww1.lavetra.com *.ww16.lavetra.com *.ww17.lavetra.com *.ww38.lavetra.com
microbrewer.au *.microbrewer.au
*.hostmaster.nijenhuis.com *.m.nijenhuis.com nijenhuis.com *.nijenhuis.com *.store.nijenhuis.com *.wiki.nijenhuis.com *.ww1.nijenhuis.com *.ww16.nijenhuis.com
pairstrading.au *.pairstrading.au
*.admin.piazzaitalia.us *.api.piazzaitalia.us *.assets.piazzaitalia.us *.cpanel.piazzaitalia.us *.dc-9c13e0dcff2e.piazzaitalia.us *.demo.piazzaitalia.us *.dev.piazzaitalia.us *.docs.piazzaitalia.us *.external.piazzaitalia.us *.ftp.piazzaitalia.us *.hostmaster.piazzaitalia.us *.m.piazzaitalia.us *.mail105.piazzaitalia.us piazzaitalia.us *.piazzaitalia.us *.public.piazzaitalia.us *.random.piazzaitalia.us *.rds.piazzaitalia.us *.remote.piazzaitalia.us *.sanantonioadmin.piazzaitalia.us *.share.piazzaitalia.us *.vpn.piazzaitalia.us *.webdisk.piazzaitalia.us *.webmail.piazzaitalia.us *.whm.piazzaitalia.us *.wildcard.piazzaitalia.us *.ww1.piazzaitalia.us *.www.piazzaitalia.us
thestreamest.co *.thestreamest.co
willye.com *.willye.com