Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=unexamined.life
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 15, 2025
Valid Until
March 15, 2026 43 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
51:36:D0:B1:70:52:E3:71:36:3C:15:49:90:CB:22:30:6A:2E:AE:34:D2:42:1E:0E:ED:2C:45:F7:2D:E0:60:83
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
besho.store *.besho.store

Other domains in certificate

adcoin.me *.adcoin.me *.hostmaster.adcoin.me *.mail.adcoin.me
analemmawater.com *.analemmawater.com *.random.analemmawater.com
bhaktistotram.xyz *.bhaktistotram.xyz
brightn.io *.brightn.io *.ww25.brightn.io *.www.brightn.io
brisbanedoctor.au *.brisbanedoctor.au
cmucanvas.shop *.cmucanvas.shop
cryptocurrencybanks.com *.cryptocurrencybanks.com *.dev.cryptocurrencybanks.com *.mail.cryptocurrencybanks.com *.test.cryptocurrencybanks.com
eogdrip.online *.eogdrip.online *.seguro.eogdrip.online
ferro.uk *.ferro.uk *.webmail.ferro.uk
humane.academy *.humane.academy
inzoi.net *.inzoi.net *.sitemaps.inzoi.net
*.2d387fa8-0214-422a-b382-75df903bf1a7.jkglobal.online *.ap.jkglobal.online *.api.jkglobal.online *.app.jkglobal.online *.autodiscover.jkglobal.online *.cpcontacts.jkglobal.online *.crm.jkglobal.online *.eb.jkglobal.online *.ebdisk.jkglobal.online *.ebmail.jkglobal.online *.home.jkglobal.online jkglobal.online *.jkglobal.online *.lime.jkglobal.online *.m.jkglobal.online *.mail.jkglobal.online *.mobile.jkglobal.online *.news.jkglobal.online *.sitemaps.jkglobal.online *.wap.jkglobal.online *.web.jkglobal.online *.webdisk.jkglobal.online *.webmail.jkglobal.online *.www.jkglobal.online
large-browed.sbs *.large-browed.sbs
lovemoney.click *.lovemoney.click
mangacast.org *.mangacast.org
nacao.bet *.nacao.bet
nejuqeyaa.space *.nejuqeyaa.space
reimbursements.au *.reimbursements.au
*.dashboard-ci.sao.bio *.dashboard.sao.bio *.dataviz.sao.bio *.lan.sao.bio *.legacy.sao.bio *.master.sao.bio sao.bio *.sao.bio *.www.sao.bio
*.hostmaster.simpsonados.club simpsonados.club *.simpsonados.club
*.puillops.unexamined.life unexamined.life *.unexamined.life
*.random.v0k.us v0k.us *.v0k.us