76/100 SECURITY SCORE

Certificate Information

Subject
CN=goldendawning.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4C:AC:BF:CB:0D:3C:ED:7A:89:AB:51:62:08:E6:41:95:82:DE:1A:41:D9:11:89:90:D1:99:DB:65:68:33:6E:C5
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
goldendawning.com *.goldendawning.com

Other domains in certificate

05592.lgbt *.05592.lgbt
3115bb.top *.3115bb.top
531flux.lol *.531flux.lol
57b2.com *.57b2.com
97z6.com *.97z6.com
9sgg9a.top *.9sgg9a.top
avid.lol *.avid.lol
bluetooth-speakers-eternal-825.sbs *.bluetooth-speakers-eternal-825.sbs
bzmrwq.work *.bzmrwq.work
cleardatagate.info *.cleardatagate.info
e5481571.vip *.e5481571.vip
ecoivent.org *.ecoivent.org
ggges.com *.ggges.com
gigolo.lol *.gigolo.lol
hdriraq.com *.hdriraq.com
highmountainrealestate.net *.highmountainrealestate.net
jatrophaplatform.org *.jatrophaplatform.org
kathyceglowskiphotography.com *.kathyceglowskiphotography.com
kv-telegran.top *.kv-telegran.top
l1z423wrf.buzz *.l1z423wrf.buzz
learndon.com *.learndon.com
leon-casino-bkngo.top *.leon-casino-bkngo.top
leonbets-casino-30tvx.top *.leonbets-casino-30tvx.top
loadconnections.com *.loadconnections.com
lugha.foundation *.lugha.foundation
lurienne.com *.lurienne.com
m171.vip *.m171.vip
marskiss.com *.marskiss.com
medipeelicecream.com *.medipeelicecream.com
mezcalchocolat.com *.mezcalchocolat.com
michiganhomesandland.com *.michiganhomesandland.com
miyoav.cyou *.miyoav.cyou
mkhcj.cc *.mkhcj.cc
mtmrecogniyion.com *.mtmrecogniyion.com
multidev.xyz *.multidev.xyz
nccardinals.com *.nccardinals.com
photonotics.com *.photonotics.com
publicgoodsociety.org *.publicgoodsociety.org
rasagiline.ca *.rasagiline.ca
realidadesociologicas.org *.realidadesociologicas.org
santabarbararealty.info *.santabarbararealty.info
scielop.org *.scielop.org
tiltedscreen.com *.tiltedscreen.com
vietnam-fxgt.com *.vietnam-fxgt.com