Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=santanatura.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
79:B2:52:32:FF:EF:AA:8C:92:9C:D5:86:48:46:AC:17:04:81:7F:9F:1A:73:82:87:92:38:F4:DF:99:35:D9:C9
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ziafat.com *.ziafat.com *.api.ziafat.com *.mobileconnect.ziafat.com

Other domains in certificate

*.andin.badlo.com badlo.com *.badlo.com *.ww.badlo.com
biezhen.com *.biezhen.com *.random.biezhen.com *.ww25.biezhen.com
*.acidman.bird.to *.al.bird.to *.b-well.bird.to bird.to *.bird.to *.breeze.bird.to *.cg-i.bird.to *.charles.bird.to *.comune.bird.to *.easygoing.bird.to *.edaya.bird.to *.english.bird.to *.firebird.bird.to *.flowers.bird.to *.gekijyou.bird.to *.heart.bird.to *.hokuto.bird.to *.kmaker.bird.to *.maruyaki.bird.to *.ms.bird.to *.nao.bird.to *.net.bird.to *.obscure.bird.to *.okusay.bird.to *.radio-k.bird.to *.see-la.bird.to *.shingo.bird.to *.shio.bird.to *.sky.bird.to *.solarman.bird.to *.tfm.bird.to *.trick.bird.to *.usagi.bird.to *.ushigome.bird.to *.valkyrie.bird.to *.ww38.bird.to
*.a.dproject.org dproject.org *.dproject.org *.events.dproject.org *.hostmaster.dproject.org *.wildcard.dproject.org
*.blog.gnula.com *.client.gnula.com *.gateway.gnula.com gnula.com *.gnula.com *.m.gnula.com *.pa.gnula.com *.se.gnula.com *.sign.gnula.com *.vpn.gnula.com *.wwww.gnula.com
*.demo.lainvasora.com lainvasora.com *.lainvasora.com
*.api.newtransfer.com *.dev.newtransfer.com newtransfer.com *.newtransfer.com
nijenhuis.com *.nijenhuis.com *.store.nijenhuis.com
*.cpanel.ocupar.com ocupar.com *.ocupar.com *.rdweb.ocupar.com *.remote.ocupar.com
santanatura.com *.santanatura.com *.ts.santanatura.com
*.portal.virtual-buero.com *.random.virtual-buero.com virtual-buero.com *.virtual-buero.com
*.comune.yomi.com.au yomi.com.au *.yomi.com.au