76/100 SECURITY SCORE

Certificate Information

Subject
CN=rl-labs.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 07, 2026
Valid Until
May 08, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:16:4E:64:2F:B0:15:9C:65:E3:D2:52:E3:B5:48:D7:8D:FB:12:2E:5F:29:58:15:34:F5:35:AD:00:2B:74:D4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
journigan.com *.journigan.com *.api.journigan.com *.beta.journigan.com *.demo.journigan.com *.dev.journigan.com *.mail.journigan.com *.store.journigan.com *.test.journigan.com *.vpn.journigan.com *.wiki.journigan.com

Other domains in certificate

branddesign.it *.branddesign.it *.superset.branddesign.it
colaboratory.com *.colaboratory.com *.ethereumwolf.colaboratory.com *.research.colaboratory.com *.ww1.colaboratory.com
*.38.full-price.com *.fr.full-price.com full-price.com *.full-price.com *.vps.full-price.com
*.assets.geckle.com geckle.com *.geckle.com *.s3.geckle.com *.static.geckle.com *.wiki.geckle.com *.ww25.geckle.com
iletisim-is.org *.iletisim-is.org *.test2.iletisim-is.org
libren.org *.libren.org *.ww1.libren.org
*.img.littletikeso.com littletikeso.com *.littletikeso.com
*.imap.mobileonvue.com mobileonvue.com *.mobileonvue.com *.panel.mobileonvue.com
myapartmentsucks.com *.myapartmentsucks.com *.random.myapartmentsucks.com
*.antseiko.nelz.com *.little-might.nelz.com nelz.com *.nelz.com *.wiki.nelz.com *.ztgapdohaevl.nelz.com
*.dha.nua.nu nua.nu *.nua.nu *.su.nua.nu *.sun.nua.nu
*.1.phu.nu *.cho.phu.nu *.hoi.phu.nu *.hop.phu.nu phu.nu *.phu.nu *.thap.phu.nu *.trang.phu.nu
*.kjbm.rl-labs.com rl-labs.com *.rl-labs.com *.transviet.rl-labs.com *.webexch19.rl-labs.com *.ww38.rl-labs.com
salomonshoesonline.us *.salomonshoesonline.us *.uwnvmwebmail.salomonshoesonline.us *.webmail.salomonshoesonline.us
*.api.spieletage.com *.dev.spieletage.com *.mail.spieletage.com spieletage.com *.spieletage.com *.test.spieletage.com *.vpn.spieletage.com
*.poc.touchstone.it touchstone.it *.touchstone.it
*.cdn2.xmovies.pro *.sitemaps.xmovies.pro xmovies.pro *.xmovies.pro