Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=paintinspire.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 13, 2026
Valid Until
August 11, 2026 52 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:64:19:F2:9F:B7:C4:87:FA:30:FC:C0:3F:EB:B3:4D:BC:76:67:71:64:64:E0:56:F9:B2:C6:AA:1B:89:D5:DB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bdsmbound.com *.bdsmbound.com *.mail.bdsmbound.com *.www.bdsmbound.com

Other domains in certificate

astromuse.pro *.astromuse.pro *.www.astromuse.pro
authorizetime.com *.authorizetime.com *.bk.authorizetime.com *.vpn.authorizetime.com *.www.authorizetime.com
batikai.com *.batikai.com *.checkin.batikai.com *.www.batikai.com
bernard-group.com *.bernard-group.com *.sitemaps.bernard-group.com *.www.bernard-group.com
berry-on-rune.mobi *.berry-on-rune.mobi *.www.berry-on-rune.mobi
birthstoneshop.com *.birthstoneshop.com *.www.birthstoneshop.com
bo11ywoodsenjoy.top *.bo11ywoodsenjoy.top *.www.bo11ywoodsenjoy.top
breeze-nova.pro *.breeze-nova.pro *.isy4ie.breeze-nova.pro *.www.breeze-nova.pro
breeze-nova.world *.breeze-nova.world *.u0wzti.breeze-nova.world *.www.breeze-nova.world
*.34qaqn.breeze-on-nova.info breeze-on-nova.info *.breeze-on-nova.info *.www.breeze-on-nova.info
breezedash.pro *.breezedash.pro *.dhycnz.breezedash.pro *.www.breezedash.pro
bycasino36.com *.bycasino36.com *.www.bycasino36.com
corrine.au *.corrine.au *.wildcard.corrine.au *.ww25.corrine.au
cotti.co *.cotti.co *.www.cotti.co
creditcardcents.com *.creditcardcents.com *.mncredit.creditcardcents.com *.www.creditcardcents.com
*.en.gate14.be gate14.be *.gate14.be *.ww16.gate14.be
grupogioia.com.br *.grupogioia.com.br
*.76f56658-e98b-4b87-9558-fc53b064a015.lacorop.org *.admin.lacorop.org *.demo.lacorop.org *.dev.lacorop.org *.hostmaster.lacorop.org lacorop.org *.lacorop.org *.www.lacorop.org
*.2334f7b2-0121-4136-a755-8889dc456b8f.nivara.fun *.api.nivara.fun nivara.fun *.nivara.fun *.staging.nivara.fun
*.blwq0i.paintinspire.com paintinspire.com *.paintinspire.com
spqnsl.xyz *.spqnsl.xyz *.ww16.spqnsl.xyz
*.bmail.tuiliwu.cn tuiliwu.cn *.tuiliwu.cn
*.track.vastgreylogistics.com vastgreylogistics.com *.vastgreylogistics.com