Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=contacombo.com.br
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 10, 2026
Valid Until
August 08, 2026
60 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0B:CE:74:D2:53:E7:DD:95:26:BD:77:51:97:A6:BD:48:3A:F5:9E:F7:F2:9F:B7:A1:27:92:5D:09:A1:C6:A9:1F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
avaxsearch.pro
*.avaxsearch.pro
*.hostmaster.avaxsearch.pro
*.noc.avaxsearch.pro
*.postmaster.avaxsearch.pro
*.ww25.avaxsearch.pro
*.ww38.avaxsearch.pro
*.www.avaxsearch.pro
*.yfzhuw.avaxsearch.pro
*.32.asla.bet
asla.bet
*.asla.bet
bagel.bet
*.bagel.bet
*.preview.bagel.bet
*.ww38.bagel.bet
*.32.bookbundle.info
bookbundle.info
*.bookbundle.info
*.ww25.bookbundle.info
*.32.contacombo.com.br
contacombo.com.br
*.contacombo.com.br
*.app.ganso.io
*.chat.ganso.io
ganso.io
*.ganso.io
*.ww25.ganso.io
*.32.gaurdian.life
gaurdian.life
*.gaurdian.life
jammedicalcenter.com
*.jammedicalcenter.com
*.ww38.jammedicalcenter.com
*.32.kuview.io
kuview.io
*.kuview.io
*.32.laaf.io
laaf.io
*.laaf.io
*.analytics.loyalty.bet
loyalty.bet
*.loyalty.bet
*.32.maxhdtv.vip
maxhdtv.vip
*.maxhdtv.vip
*.a.meownovel.com
*.adilraya.meownovel.com
*.animeraya.meownovel.com
*.ar.meownovel.com
*.bitenda.meownovel.com
*.com.meownovel.com
*.dddd.meownovel.com
*.gusnovel.meownovel.com
*.id.meownovel.com
*.iraya.meownovel.com
*.komikraya.meownovel.com
*.loopapk.meownovel.com
*.mantraku.meownovel.com
meownovel.com
*.meownovel.com
*.meowscan.meownovel.com
*.nekomodapk.meownovel.com
*.net.meownovel.com
*.nsfw.meownovel.com
*.recehku.meownovel.com
*.rom.meownovel.com
*.sayaotaku.meownovel.com
*.32.mithu.live
mithu.live
*.mithu.live
*.line.rs4ott.com
rs4ott.com
*.rs4ott.com
*.32.rugbundle.pro
rugbundle.pro
*.rugbundle.pro
*.32.sciwrite.pro
sciwrite.pro
*.sciwrite.pro
*.32.tenzkin.pro
tenzkin.pro
*.tenzkin.pro
*.32.underdog-dayz.online
underdog-dayz.online
*.underdog-dayz.online
*.32.xone.bet
xone.bet
*.xone.bet
Other domains in certificate