76/100 SECURITY SCORE

Certificate Information

Subject
CN=smmmet4rxbot.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 17, 2026
Valid Until
May 18, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:4B:08:91:35:67:95:39:93:16:BB:67:F5:0B:F3:E7:D7:BC:0A:22:47:5C:AA:FB:08:41:6C:4E:E7:A4:EC:E2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
emmersion.com *.emmersion.com *.admin.emmersion.com *.api.emmersion.com *.app.emmersion.com *.arquivos.emmersion.com *.assets.emmersion.com *.blog.emmersion.com *.demo.emmersion.com *.dev.emmersion.com *.finance.emmersion.com *.hostmaster.emmersion.com *.m.emmersion.com *.partner.emmersion.com *.test.emmersion.com *.ww25.emmersion.com *.ww38.emmersion.com *.ww41.emmersion.com

Other domains in certificate

*.api.arimura.com arimura.com *.arimura.com *.dev.arimura.com *.forums.arimura.com *.redbusprimarydns.arimura.com *.rustore.arimura.com *.smtp.arimura.com *.test.arimura.com *.ww1.arimura.com *.ww11.arimura.com *.ww16.arimura.com *.ww25.arimura.com *.ww38.arimura.com *.www.arimura.com
*.api.avtoshop.com avtoshop.com *.avtoshop.com *.dev.avtoshop.com *.mail.avtoshop.com *.test.avtoshop.com *.ww16.avtoshop.com *.ww25.avtoshop.com
boundnotebook.com *.boundnotebook.com *.m.boundnotebook.com *.sitemap.boundnotebook.com *.sitemaps.boundnotebook.com *.ww1.boundnotebook.com *.ww17.boundnotebook.com *.ww25.boundnotebook.com *.ww38.boundnotebook.com *.ww5.boundnotebook.com
*.beta.pimpurniaux.com *.blog.pimpurniaux.com *.hostmaster.pimpurniaux.com *.m.pimpurniaux.com pimpurniaux.com *.pimpurniaux.com *.sitemap.pimpurniaux.com *.sitemaps.pimpurniaux.com *.store.pimpurniaux.com *.vpn.pimpurniaux.com *.ww1.pimpurniaux.com *.ww25.pimpurniaux.com *.ww38.pimpurniaux.com
smmmet4rxbot.xyz *.smmmet4rxbot.xyz *.z4gbs.smmmet4rxbot.xyz
*.hostmaster.temporaryfile.com temporaryfile.com *.temporaryfile.com *.ww25.temporaryfile.com
*.blog.utusankarya.com *.hostmaster.utusankarya.com *.sitemaps.utusankarya.com utusankarya.com *.utusankarya.com *.ww11.utusankarya.com *.ww16.utusankarya.com *.ww17.utusankarya.com *.ww25.utusankarya.com *.ww38.utusankarya.com *.ww5.utusankarya.com
vantage3000.com *.vantage3000.com *.ww1.vantage3000.com
*.m.yardsellers.com *.ww1.yardsellers.com *.ww11.yardsellers.com yardsellers.com *.yardsellers.com