Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=life-advance.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 15, 2025
Valid Until
March 15, 2026 32 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
40:A6:DA:BD:D0:48:C2:8F:13:CC:82:B7:B3:F4:BB:81:CC:54:46:D2:2D:50:57:A5:D5:EB:5B:AB:00:90:86:27
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
arposters.com *.arposters.com *.cpanel.arposters.com *.hosting.arposters.com *.sandbox.arposters.com

Other domains in certificate

2cox.net *.2cox.net *.outbound.2cox.net *.yjszs.2cox.net
australiasport.com.au *.australiasport.com.au
collectifpolar.com *.collectifpolar.com
floralicious.com.au *.floralicious.com.au
*.cdek.fungold365.com fungold365.com *.fungold365.com *.nalozhka.fungold365.com *.ozon.fungold365.com *.pay.fungold365.com *.pochta.fungold365.com *.pochtabank.fungold365.com *.sber.fungold365.com *.sbermarket.fungold365.com *.sbermegamarket.fungold365.com *.ww38.fungold365.com *.www.fungold365.com
*.ci1.hermesdefi.io *.dev.hermesdefi.io *.docs.hermesdefi.io *.fm.hermesdefi.io *.ftp.hermesdefi.io hermesdefi.io *.hermesdefi.io *.imap.hermesdefi.io *.localhost.hermesdefi.io *.mail.hermesdefi.io *.mx.hermesdefi.io *.onlinebanking.hermesdefi.io *.pop3.hermesdefi.io *.shared.hermesdefi.io *.smtp.hermesdefi.io *.volkswagen.hermesdefi.io *.wiki.hermesdefi.io *.ww25.hermesdefi.io
injections.com.au *.injections.com.au *.mailserver.injections.com.au
*.es.life-advance.com life-advance.com *.life-advance.com *.new.life-advance.com *.users.life-advance.com
mailbox.au *.mailbox.au
*.idesign.needajob.com *.mail.needajob.com needajob.com *.needajob.com *.scrm.needajob.com *.ww42.needajob.com
rinkers.com *.rinkers.com *.ww1.rinkers.com
ruilweb.be *.ruilweb.be *.ww31.ruilweb.be
*.shop.tokyo-box.de tokyo-box.de *.tokyo-box.de *.ww25.tokyo-box.de
*.office.vestiaire.com vestiaire.com *.vestiaire.com
*.mabry.woolcom.net woolcom.net *.woolcom.net
*.ww25.youdeservetoberichbook.co *.ww38.youdeservetoberichbook.co youdeservetoberichbook.co *.youdeservetoberichbook.co
*.hostmaster.zimbabe.com *.m.zimbabe.com *.mx.zimbabe.com *.random.zimbabe.com *.www.zimbabe.com zimbabe.com *.zimbabe.com