Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=lacafes.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 03, 2026
Valid Until
September 01, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
29:7A:73:87:DE:34:26:A5:8D:8E:69:C6:31:1E:91:17:AB:C4:A3:37:0D:98:6E:62:08:EA:E0:7B:BA:2F:CA:26
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
lacafes.com *.lacafes.com *.backup.lacafes.com *.blog.lacafes.com *.hostmaster.lacafes.com *.iqrxusecure.lacafes.com *.neipeblog.lacafes.com *.shop.lacafes.com *.vpn.lacafes.com *.wiki.lacafes.com *.www.lacafes.com

Other domains in certificate

234167.com *.234167.com *.m.234167.com
3692781.com *.3692781.com *.beta.3692781.com *.blueprint.3692781.com *.painel.3692781.com *.test.3692781.com
audkble.com *.audkble.com *.blg.audkble.com *.shop.audkble.com *.site.audkble.com
*.32.brking.bet brking.bet *.brking.bet
fashionweekverse.com *.fashionweekverse.com *.ftp.fashionweekverse.com *.m.fashionweekverse.com *.old.fashionweekverse.com *.random.fashionweekverse.com *.www.fashionweekverse.com
*.abundanceusa.launchzoo.com *.alexasangels.launchzoo.com *.choosejoeysantos.launchzoo.com *.conelec.launchzoo.com *.fiduciaryspecialist.launchzoo.com *.golfshopdesign.launchzoo.com *.izzibanrestaurant.launchzoo.com *.jaredsellscfl.launchzoo.com *.jlstoneconstruction.launchzoo.com launchzoo.com *.launchzoo.com *.modernperio.launchzoo.com *.nicelydoneeventsusa.launchzoo.com *.prs-jobs.launchzoo.com *.revlift.launchzoo.com *.southtampadj.launchzoo.com *.starkicf.launchzoo.com *.starkicf2.launchzoo.com *.sterlingimportsinc.launchzoo.com *.thirstypirates.launchzoo.com *.tuttocaffe.launchzoo.com *.umadvs.launchzoo.com *.whatsnextormond.launchzoo.com
lgclothing.com *.lgclothing.com
mydevryu.net *.mydevryu.net
newyorkand.co *.newyorkand.co *.notexistsww1.newyorkand.co *.remote.newyorkand.co *.wildcard.newyorkand.co *.ww1.newyorkand.co *.ww11.newyorkand.co *.ww38.newyorkand.co *.www.newyorkand.co
*.gp.oye-oye.com oye-oye.com *.oye-oye.com
*.random.sasy.live sasy.live *.sasy.live
*.app.zijieyunti.site *.dy.zijieyunti.site *.mail.zijieyunti.site zijieyunti.site *.zijieyunti.site *.zj.zijieyunti.site *.zj10.zijieyunti.site *.zj2.zijieyunti.site *.zj3.zijieyunti.site *.zj5.zijieyunti.site *.zj7.zijieyunti.site *.zj8.zijieyunti.site *.zj9.zijieyunti.site