Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=aequitas-network.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:02:96:EC:04:C9:52:68:81:36:9C:A4:06:45:85:16:6F:5E:69:F3:A3:21:ED:B5:EA:D1:1E:C6:D1:D9:2E:FB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
avac.it
*.avac.it
aequitas-network.com
*.aequitas-network.com
alert.finance
*.alert.finance
alfalakbank.co
*.alfalakbank.co
antwerp.rent
*.antwerp.rent
apk2-kijangwin.icu
*.apk2-kijangwin.icu
artframe.it
*.artframe.it
attestatnow1.top
*.attestatnow1.top
badutselalu.sbs
*.badutselalu.sbs
balapak189.org
*.balapak189.org
bayartuntas.click
*.bayartuntas.click
boletindeprensa.com
*.boletindeprensa.com
boucherbnsa.com
*.boucherbnsa.com
brwin.love
*.brwin.love
child-psychology-eng-8393.click
*.child-psychology-eng-8393.click
conman.io
*.conman.io
curationofart.art
*.curationofart.art
curtainshaven.nz
*.curtainshaven.nz
decadeproject.com
*.decadeproject.com
electric-car-my-10.click
*.electric-car-my-10.click
energyprovider.it
*.energyprovider.it
folfsys.com
*.folfsys.com
frogontour.net
*.frogontour.net
grapestellar.vip
*.grapestellar.vip
grhistz.buzz
*.grhistz.buzz
griggsbespoke.com
*.griggsbespoke.com
gtuduqaklah.com
*.gtuduqaklah.com
healthcover.click
*.healthcover.click
helflowz.xyz
*.helflowz.xyz
hs52y.xyz
*.hs52y.xyz
if-it.com
*.if-it.com
jouib.xyz
*.jouib.xyz
jyofd.pro
*.jyofd.pro
k560736.cc
*.k560736.cc
kaizensac.com
*.kaizensac.com
kaq5668.cc
*.kaq5668.cc
kiemtoan.info
*.kiemtoan.info
kkvip18677.shop
*.kkvip18677.shop
leatheroutlet.it
*.leatheroutlet.it
leon-zerkalo-o80g.xyz
*.leon-zerkalo-o80g.xyz
longleafbicycles.com
*.longleafbicycles.com
lpo88kasihjp.com
*.lpo88kasihjp.com
lqhuqp.top
*.lqhuqp.top
lrxcpzr.biz
*.lrxcpzr.biz
lspasmr.com
*.lspasmr.com
Other domains in certificate