Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=epiceriefine.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
89 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3E:FA:E8:74:7E:91:9C:5B:96:74:EF:5F:79:56:2B:06:E6:F1:8A:A7:7F:72:B2:61:37:76:EE:C7:DD:3F:F8:AF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
badonk.com
*.badonk.com
12tuo8.my
*.12tuo8.my
15kui8.my
*.15kui8.my
213697.shop
*.213697.shop
223ww8.my
*.223ww8.my
805769.club
*.805769.club
afellay.com
*.afellay.com
alugueldecarro.com
*.alugueldecarro.com
anshi.net
*.anshi.net
antoniel.com
*.antoniel.com
arianda.com
*.arianda.com
arrawarra.com
*.arrawarra.com
arteybelleza.com
*.arteybelleza.com
aymelek.com
*.aymelek.com
bagaceira.com
*.bagaceira.com
bagnol.com
*.bagnol.com
bailaora.com
*.bailaora.com
bangmang.net
*.bangmang.net
*.anyconnect.cingles.com
*.api.cingles.com
*.app.cingles.com
cingles.com
*.cingles.com
*.cisco.cingles.com
*.clientesvpn.cingles.com
*.connecting.cingles.com
*.desktop.cingles.com
*.gate.cingles.com
*.intra.cingles.com
*.officevpn.cingles.com
*.ravpn.cingles.com
*.remoto.cingles.com
*.api.datsumo.com
datsumo.com
*.datsumo.com
*.dev.datsumo.com
*.ww11.datsumo.com
*.api.dryshod.co
dryshod.co
*.dryshod.co
*.api.dunmeyer.com
dunmeyer.com
*.dunmeyer.com
*.store.dunmeyer.com
*.aluno.emece.com
*.api.emece.com
*.cdn.emece.com
*.central.emece.com
emece.com
*.emece.com
*.home.emece.com
*.rds.emece.com
*.ts.emece.com
*.api.epiceriefine.com
epiceriefine.com
*.epiceriefine.com
*.transparencia.epiceriefine.com
*.web4883.epiceriefine.com
*.ww17.epiceriefine.com
*.app.stainlessconveyor.com
*.assets.stainlessconveyor.com
*.m.stainlessconveyor.com
stainlessconveyor.com
*.stainlessconveyor.com
*.yyh4y2ljoa.stainlessconveyor.com
*.api.ydqpznsy.com
*.dev.ydqpznsy.com
*.wildcard.ydqpznsy.com
*.ww38.ydqpznsy.com
*.wwww.ydqpznsy.com
ydqpznsy.com
*.ydqpznsy.com
Other domains in certificate