Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=bathreflections.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 15, 2026
Valid Until
July 14, 2026
72 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A1:F9:74:D1:BE:55:6C:72:72:00:5D:11:3A:00:DC:6C:75:89:82:AB:3F:4E:AC:26:64:97:3F:21:8A:94:86:62
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
reconcustom.info
*.reconcustom.info
allergyfreeplanet.com
*.allergyfreeplanet.com
basedollar.com
*.basedollar.com
bathreflections.com
*.bathreflections.com
baths.asia
*.baths.asia
battorney.com
*.battorney.com
bayrize.com
*.bayrize.com
bbbagg-ou2t-880myg.agency
*.bbbagg-ou2t-880myg.agency
beyondwhiskey.com
*.beyondwhiskey.com
carsz1brcity.sbs
*.carsz1brcity.sbs
casamansa.com
*.casamansa.com
cashapp.in
*.cashapp.in
dpqky.town
*.dpqky.town
drug-expert.com
*.drug-expert.com
dy78e9ezm6.top
*.dy78e9ezm6.top
ebeta.net
*.ebeta.net
ehwyf.town
*.ehwyf.town
emtdiscovery.com
*.emtdiscovery.com
eng-cour-uae-1.sbs
*.eng-cour-uae-1.sbs
enjitechhub.com
*.enjitechhub.com
eraybagamma.com
*.eraybagamma.com
evenfrown.info
*.evenfrown.info
exitfund.net
*.exitfund.net
f64818673.com
*.f64818673.com
leadacid.com
*.leadacid.com
leakiest.com
*.leakiest.com
legxotopcasino7.com
*.legxotopcasino7.com
lewispestcontrol.com
*.lewispestcontrol.com
lifedrawing.wales
*.lifedrawing.wales
myqsl.info
*.myqsl.info
naples-cruise-packages.sbs
*.naples-cruise-packages.sbs
neuralnaked.com
*.neuralnaked.com
speed-one.com
*.speed-one.com
vr-space.com
*.vr-space.com
vv6975.com
*.vv6975.com
vv9185.com
*.vv9185.com
walmarth.com
*.walmarth.com
warehouse-jobs-8i3p0w8x4c7.sbs
*.warehouse-jobs-8i3p0w8x4c7.sbs
water-storage-tanks-60788.click
*.water-storage-tanks-60788.click
wisegardenerschoice.live
*.wisegardenerschoice.live
wlceb6.cyou
*.wlceb6.cyou
worldrecord.group
*.worldrecord.group
xwzj8.com
*.xwzj8.com
xzzybyq.com
*.xzzybyq.com
yay1686.cc
*.yay1686.cc
Other domains in certificate