Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=xfcou.plus
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 12, 2026
Valid Until
July 11, 2026
50 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:0A:26:E4:E9:A3:EA:C0:30:4F:BD:31:3C:48:2B:FC:DB:56:82:FB:7F:33:1B:DB:AE:5A:39:89:77:8F:F7:2F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
82 domains
benchmarkaimatrix.co
*.benchmarkaimatrix.co
27285710.vip
*.27285710.vip
47912.co
*.47912.co
5376853.cc
*.5376853.cc
826539.co
*.826539.co
8395.loan
*.8395.loan
98866.town
*.98866.town
99867.games
*.99867.games
allrenaisbenefit.co
*.allrenaisbenefit.co
aquark.co
*.aquark.co
atlasiptv1.xyz
*.atlasiptv1.xyz
benchmarkaiprofile.co
*.benchmarkaiprofile.co
benchmarknetwork.co
*.benchmarknetwork.co
camelseoleads.co
*.camelseoleads.co
chlenokrut.com
*.chlenokrut.com
crbozy.com
*.crbozy.com
csc90053.cc
*.csc90053.cc
dataquantum.co
*.dataquantum.co
g2fs7a.shop
*.g2fs7a.shop
gethelpline.com
*.gethelpline.com
gossipconfidence.xyz
*.gossipconfidence.xyz
grand-cherokee-507116730.click
*.grand-cherokee-507116730.click
jetcircle.co
*.jetcircle.co
lawffa.us
*.lawffa.us
lmnop.today
*.lmnop.today
mortgagehunter.com
*.mortgagehunter.com
pavonixtrader-2-8-prime.org
*.pavonixtrader-2-8-prime.org
tokenizegame.com
*.tokenizegame.com
wkdxg.ren
*.wkdxg.ren
xfcou.plus
*.xfcou.plus
*.app.zionshill.com
*.autodiscover.zionshill.com
*.hostmaster.zionshill.com
*.m.zionshill.com
*.old.zionshill.com
*.sitemap.zionshill.com
*.support.zionshill.com
*.vpn.zionshill.com
*.wildcard.zionshill.com
*.ww62.zionshill.com
*.ww82.zionshill.com
*.www.zionshill.com
zionshill.com
*.zionshill.com
zrscan.com
*.zrscan.com
zrvvc.quest
*.zrvvc.quest
zzz326.cc
*.zzz326.cc
zzz596.cc
*.zzz596.cc
Other domains in certificate