76/100 SECURITY SCORE

Certificate Information

Subject
CN=zjd.app
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026 78 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
73:C9:47:C2:E7:29:CA:D0:BD:84:47:0E:82:17:3F:99:96:8E:BD:90:D3:C7:89:53:E7:87:3B:1A:5C:D0:8F:F6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
threet.com *.threet.com *.autodiscover.threet.com

Other domains in certificate

899yhj301.top *.899yhj301.top *.cbb57713fb53306d2db36a8e82317ec4.899yhj301.top
bwnr489804.pro *.bwnr489804.pro
generative-ai-intelligence.click *.generative-ai-intelligence.click
genious.it *.genious.it
germanyvideo.chat *.germanyvideo.chat
giveliveaction.org *.giveliveaction.org
globos.it *.globos.it
goldmine.bet *.goldmine.bet
goodcare.it *.goodcare.it
gossipsignalbroadcast.live *.gossipsignalbroadcast.live
grazieditutto.it *.grazieditutto.it
halterdress.it *.halterdress.it
happenerp.com *.happenerp.com
hardcoregamer.it *.hardcoregamer.it
heterotransplant.com *.heterotransplant.com
lashawn.com *.lashawn.com *.portal.lashawn.com
*.apps.rakonjac.com rakonjac.com *.rakonjac.com *.remote.rakonjac.com
shrink-sleeves-vn-110.click *.shrink-sleeves-vn-110.click
sledges.it *.sledges.it
snowdog.it *.snowdog.it
soc88vina.co *.soc88vina.co
socialdirectconnect.com *.socialdirectconnect.com
software-jp2.click *.software-jp2.click
software-mx2.click *.software-mx2.click
software-platforms-160064189.click *.software-platforms-160064189.click
soupayam.xyz *.soupayam.xyz
spedizionepostale.it *.spedizionepostale.it
squid.capital *.squid.capital
www374466.com *.www374466.com
wwwart.it *.wwwart.it
wyg45.top *.wyg45.top
xjxx49.xyz *.xjxx49.xyz
xmax789pro.net *.xmax789pro.net
ymmde.academy *.ymmde.academy
yourbestbuy.it *.yourbestbuy.it
youthleague.it *.youthleague.it
yprmu.org *.yprmu.org
yuvalumeo.com *.yuvalumeo.com
zehulu.com *.zehulu.com
*.blog.zeune.com zeune.com *.zeune.com
zjd.app *.zjd.app