76/100 SECURITY SCORE

Certificate Information

Subject
CN=newpalm.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A7:00:14:EF:8E:B7:39:6D:17:10:A6:0C:DD:B2:D6:D5:A8:29:43:A5:C7:E6:5C:30:BD:44:EC:F1:7E:32:03:CC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
tradersbanking.com *.tradersbanking.com *.asa.tradersbanking.com *.auth.tradersbanking.com *.gate.tradersbanking.com *.owa.tradersbanking.com *.ra.tradersbanking.com

Other domains in certificate

1449jwm.top *.1449jwm.top *.nktjv.1449jwm.top
aknight.com *.aknight.com *.forum.aknight.com *.m.aknight.com *.random.aknight.com *.sitemap.aknight.com *.ww38.aknight.com
*.admin.baroquemansion.com baroquemansion.com *.baroquemansion.com *.bbs.baroquemansion.com *.hostmaster.baroquemansion.com *.website.baroquemansion.com *.ww6.baroquemansion.com *.www.baroquemansion.com
fopdonate.com *.fopdonate.com *.portal.fopdonate.com *.ww31.fopdonate.com
getmsn.com *.getmsn.com *.rds.getmsn.com
*.6409ea56-6be2-4b02-a387-03760e41bb80.morphingheadphones.com *.admin.morphingheadphones.com *.api.morphingheadphones.com *.app.morphingheadphones.com *.backup.morphingheadphones.com *.blog.morphingheadphones.com *.dashboard.morphingheadphones.com *.demo.morphingheadphones.com *.dev.morphingheadphones.com *.hostmaster.morphingheadphones.com *.mail.morphingheadphones.com *.mailer.morphingheadphones.com *.marketing.morphingheadphones.com morphingheadphones.com *.morphingheadphones.com *.secure.morphingheadphones.com *.staging.morphingheadphones.com *.test.morphingheadphones.com *.v1.morphingheadphones.com *.v2.morphingheadphones.com *.vpn.morphingheadphones.com *.web.morphingheadphones.com
*.bbs.newpalm.com *.emai.newpalm.com *.email.newpalm.com *.emali.newpalm.com *.help.newpalm.com *.mms.newpalm.com newpalm.com *.newpalm.com
*.admin.precisionclass.com precisionclass.com *.precisionclass.com
*.1.wusuntt.com *.7.wusuntt.com *.abcd123.wusuntt.com *.autodiscover.wusuntt.com *.bell.wusuntt.com *.bgptools-wildcard-confirmed.wusuntt.com *.dev.wusuntt.com *.ebay.wusuntt.com *.git.wusuntt.com *.hostmaster.wusuntt.com *.m.wusuntt.com *.notexistsgit.wusuntt.com *.notexistshostmaster.wusuntt.com *.owa.wusuntt.com *.sitemaps.wusuntt.com *.vpn.wusuntt.com *.webmail.wusuntt.com *.wildcard.wusuntt.com wusuntt.com *.wusuntt.com *.ww1.wusuntt.com *.ww12.wusuntt.com *.ww7.wusuntt.com *.www.wusuntt.com *.wwww.wusuntt.com