Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=zapmailbee.co
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
May 30, 2026
Valid Until
August 28, 2026
66 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
48:BB:D4:B1:47:D4:11:1F:92:0C:E2:07:AF:7C:C4:AD:BF:8F:52:1B:DA:CF:EF:F8:40:C6:48:28:32:C6:72:49
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
beddennl.com
*.beddennl.com
31623.my
*.31623.my
53bafdebe7f0d0cd.com
*.53bafdebe7f0d0cd.com
562179.town
*.562179.town
641h.cc
*.641h.cc
65826.my
*.65826.my
659231.cc
*.659231.cc
793251.cc
*.793251.cc
853e911396870de6.com
*.853e911396870de6.com
88hhjj.cc
*.88hhjj.cc
91ox2094.xyz
*.91ox2094.xyz
achway.my
*.achway.my
achwir.my
*.achwir.my
aibet.onl
*.aibet.onl
antalyaamp01.cfd
*.antalyaamp01.cfd
asus-rog.vip
*.asus-rog.vip
c9c4s2r6j9t4d.top
*.c9c4s2r6j9t4d.top
c9zscf3ja3.top
*.c9zscf3ja3.top
carimercy4d.cfd
*.carimercy4d.cfd
carimercy4d.cyou
*.carimercy4d.cyou
columbia-finland.com
*.columbia-finland.com
cuan500.com
*.cuan500.com
cylind.space
*.cylind.space
demojouable.com
*.demojouable.com
disuster123.com
*.disuster123.com
domainexch.com
*.domainexch.com
ebike-7-poland.today
*.ebike-7-poland.today
ekamai.vip
*.ekamai.vip
ekamai.win
*.ekamai.win
fakephonepeapkdownload.com
*.fakephonepeapkdownload.com
forcepainting.com
*.forcepainting.com
forza.asia
*.forza.asia
gaster.xyz
*.gaster.xyz
gcemix.bid
*.gcemix.bid
glassspacer.com
*.glassspacer.com
globalrui.com.cn
*.globalrui.com.cn
gottlieb09.sbs
*.gottlieb09.sbs
gpthero.io
*.gpthero.io
grpos.loan
*.grpos.loan
gsrbqgz1260.vip
*.gsrbqgz1260.vip
iiyu.cc
*.iiyu.cc
rallyathlete.com
*.rallyathlete.com
zapmailbee.co
*.zapmailbee.co
zapmailjoin.co
*.zapmailjoin.co
zapmailwin.co
*.zapmailwin.co
Other domains in certificate