76/100 SECURITY SCORE

Certificate Information

Subject
CN=braceletstore.shop
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 01, 2026
Valid Until
June 30, 2026 34 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CB:3F:AD:95:67:1E:3A:83:8F:BB:D2:7E:E6:5B:0B:30:19:1B:D7:A6:46:79:30:B0:10:AA:1E:E3:F1:5F:18:B9
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
messageforyou.it *.messageforyou.it *.admin.messageforyou.it *.bi.messageforyou.it *.dashboard.messageforyou.it *.dashs.messageforyou.it *.dev.messageforyou.it *.intelligence.messageforyou.it *.preview.messageforyou.it *.qa.messageforyou.it *.report.messageforyou.it *.superset.messageforyou.it *.test.messageforyou.it

Other domains in certificate

anli5688.com *.anli5688.com *.maaayq0.anli5688.com
*.467ed9b6-5867-4079-bc0e-4ad5ffbdd665.braceletstore.shop *.admin.braceletstore.shop *.afda45e9-9614-4627-a7a1-ccd30fe95c23.braceletstore.shop *.api.braceletstore.shop *.app.braceletstore.shop *.assets.braceletstore.shop *.backup.braceletstore.shop braceletstore.shop *.braceletstore.shop *.demo.braceletstore.shop *.dev.braceletstore.shop *.homolog.braceletstore.shop *.hostmaster.braceletstore.shop *.lwogatest.braceletstore.shop *.m.braceletstore.shop *.members.braceletstore.shop *.sitemap.braceletstore.shop *.sitemaps.braceletstore.shop *.test.braceletstore.shop *.uat.braceletstore.shop
*.api-dev.developpaper.com *.api.developpaper.com *.back.developpaper.com *.collaborate.developpaper.com *.demo.developpaper.com developpaper.com *.developpaper.com *.imgs.developpaper.com *.mall.developpaper.com *.mh.developpaper.com *.ww7.developpaper.com *.xcx.developpaper.com
gameingera.biz *.gameingera.biz
*.admin.iwin93.club *.demo.iwin93.club iwin93.club *.iwin93.club *.www.iwin93.club
*.admin.photooftheday.it *.api.photooftheday.it *.backend.photooftheday.it *.dev.photooftheday.it photooftheday.it *.photooftheday.it
postingat.holdings *.postingat.holdings *.rustore.postingat.holdings
skateshop24.be *.skateshop24.be
*.05643a98-c8a2-4051-97b1-0dcca3956e8c.smooth.best *.1829d33c-4492-4203-a3d0-4a5ed4ea4d85.smooth.best *.api.smooth.best *.app.smooth.best *.backup.smooth.best *.dan.smooth.best *.demo.smooth.best *.dev.smooth.best *.hostmaster.smooth.best *.m.smooth.best *.mail.smooth.best smooth.best *.smooth.best *.staging.smooth.best *.uat.smooth.best
*.sitemaps.topcarschicago.com topcarschicago.com *.topcarschicago.com *.www.topcarschicago.com *.wwww.topcarschicago.com
xn--0trp26b.com *.xn--0trp26b.com
xn--3wty45i.com *.xn--3wty45i.com