Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=brandforward.info
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026
60 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:F0:5A:62:D5:78:7E:C6:C9:A7:8A:1F:C6:2B:F7:B1:D4:F7:D1:1C:FB:04:D5:64:F8:CA:AB:26:D4:20:94:9B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
hmqixin.com
*.hmqixin.com
*.staging.hmqixin.com
boostvertexpro.top
*.boostvertexpro.top
brandforward.info
*.brandforward.info
brauntalent.com
*.brauntalent.com
c43m.shop
*.c43m.shop
dvlqhk.bid
*.dvlqhk.bid
dvnhu.top
*.dvnhu.top
ekirch.com
*.ekirch.com
elfarabi-pharmaceuticals.com
*.elfarabi-pharmaceuticals.com
englishcreamgoldenretrieverhaven.com
*.englishcreamgoldenretrieverhaven.com
evdrive.co
*.evdrive.co
f2dtd505te.top
*.f2dtd505te.top
f64298670.com
*.f64298670.com
food-packing-jobs-2r0j0f3t0f8.sbs
*.food-packing-jobs-2r0j0f3t0f8.sbs
food-packing-jobs-9l2h8n5j1u8.sbs
*.food-packing-jobs-9l2h8n5j1u8.sbs
funderfuel.com
*.funderfuel.com
gipsi.life
*.gipsi.life
otdagrogroupltd.com
*.otdagrogroupltd.com
primemetalixtradingltd.com
*.primemetalixtradingltd.com
pywpzb.bid
*.pywpzb.bid
rjfkd.love
*.rjfkd.love
robotscourt.com
*.robotscourt.com
ruitsing.com
*.ruitsing.com
sales-track.info
*.sales-track.info
san2ivista.sbs
*.san2ivista.sbs
security-companies-swe-pablo.click
*.security-companies-swe-pablo.click
seniorapartment.click
*.seniorapartment.click
shcnwfm522.vip
*.shcnwfm522.vip
shinedetailpro.com
*.shinedetailpro.com
shinijia.com
*.shinijia.com
shjueqiwl.com
*.shjueqiwl.com
shopbookhub.com
*.shopbookhub.com
sibsonline.info
*.sibsonline.info
soaknrelax.com
*.soaknrelax.com
soludoss.com
*.soludoss.com
ssxo.cc
*.ssxo.cc
stornodiamondfinance.org
*.stornodiamondfinance.org
swatch-02.sbs
*.swatch-02.sbs
swissxpoint.com
*.swissxpoint.com
techpathhub.com
*.techpathhub.com
teehd-tix-rusdhewyketl1iy.my
*.teehd-tix-rusdhewyketl1iy.my
tenghuama.com
*.tenghuama.com
texas-food-manager.com
*.texas-food-manager.com
theweekndworld.us
*.theweekndworld.us
Other domains in certificate