Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=play-lunar-arch.xyz
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D0:BC:8D:B0:1F:12:C9:F3:D7:E8:F8:86:19:21:B0:2F:8E:9D:C6:8D:D0:42:F3:39:19:BA:E1:4D:B3:AE:9D:C3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
roadless.it *.roadless.it

Other domains in certificate

play-lunar-arch.xyz *.play-lunar-arch.xyz
play-mystic-odyssey.xyz *.play-mystic-odyssey.xyz
play-phoenix-harbor.xyz *.play-phoenix-harbor.xyz
play-titan-rush.xyz *.play-titan-rush.xyz
play-venom-vault.xyz *.play-venom-vault.xyz
play-void-crossing.xyz *.play-void-crossing.xyz
polo77arc.sbs *.polo77arc.sbs
posao.info *.posao.info
posterprint.it *.posterprint.it
pregnancy-clinic-nearby-us-01.click *.pregnancy-clinic-nearby-us-01.click
pregnancy-clinic-nearby-us-04.click *.pregnancy-clinic-nearby-us-04.click
puresalty.com *.puresalty.com
pycpnq.bid *.pycpnq.bid
qbdpyw.loan *.qbdpyw.loan
qd6ygh.top *.qd6ygh.top
qdczj.net *.qdczj.net
qljvs.pro *.qljvs.pro
qualityvacationadventures.xyz *.qualityvacationadventures.xyz
quickgardeningfixes.xyz *.quickgardeningfixes.xyz
quickgetawaytravel.xyz *.quickgetawaytravel.xyz
quickvacationbreaks.xyz *.quickvacationbreaks.xyz
ratecontrol.it *.ratecontrol.it
reconversi.com *.reconversi.com
regala.it *.regala.it
relaxingvacationdestinations.xyz *.relaxingvacationdestinations.xyz
renters-insureance.click *.renters-insureance.click
reportage.it *.reportage.it
retailcompany.it *.retailcompany.it
rfkuk2i.cyou *.rfkuk2i.cyou
ricc-canada.org *.ricc-canada.org
ringraziamento.it *.ringraziamento.it
risege9.xyz *.risege9.xyz
rjceystg.xyz *.rjceystg.xyz
rniandaroniasdealrchgrid.cyou *.rniandaroniasdealrchgrid.cyou
roofing-companies-near-me.top *.roofing-companies-near-me.top
roofing-contractors-near-me-123.click *.roofing-contractors-near-me-123.click
roofingcompaniesnearme.click *.roofingcompaniesnearme.click
rory.it *.rory.it
rouseraroniiosdalmapz.cyou *.rouseraroniiosdalmapz.cyou
rtpjarwo123.com *.rtpjarwo123.com
rtptawaslot.click *.rtptawaslot.click
ruhqh.top *.ruhqh.top
runlai.vip *.runlai.vip
rushpetition.com *.rushpetition.com