Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=shutter.today
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 17, 2026
Valid Until
May 18, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
54:C3:25:E3:D9:5E:85:74:88:D9:CA:E0:15:B8:8F:BB:2B:B1:CA:71:6A:8B:AC:D7:F2:1E:0A:5D:36:0D:BF:DA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bethlemitas.com *.bethlemitas.com *.access.bethlemitas.com *.apps.bethlemitas.com *.cloud.bethlemitas.com *.connect.bethlemitas.com *.cpanel.bethlemitas.com *.gateway.bethlemitas.com *.hostmaster.bethlemitas.com *.portal.bethlemitas.com *.rdp.bethlemitas.com *.rdweb.bethlemitas.com *.secureconnect.bethlemitas.com *.sitemaps.bethlemitas.com *.sslvpn.bethlemitas.com *.ts.bethlemitas.com *.vdi.bethlemitas.com *.vpn.bethlemitas.com *.vpnssl.bethlemitas.com *.ww1.bethlemitas.com *.ww16.bethlemitas.com *.ww25.bethlemitas.com *.ww38.bethlemitas.com

Other domains in certificate

dancersblog.com *.dancersblog.com *.www.dancersblog.com
haicao113.com *.haicao113.com *.sso.haicao113.com
*.admin.machinegunkelly.net *.api.machinegunkelly.net *.app.machinegunkelly.net *.backup.machinegunkelly.net *.blog.machinegunkelly.net *.dan.machinegunkelly.net *.dev.machinegunkelly.net *.m.machinegunkelly.net machinegunkelly.net *.machinegunkelly.net *.members.machinegunkelly.net *.new.machinegunkelly.net *.sitemap.machinegunkelly.net *.sitemaps.machinegunkelly.net *.staging.machinegunkelly.net *.store.machinegunkelly.net *.uat.machinegunkelly.net *.vpn.machinegunkelly.net *.werkenbij.machinegunkelly.net *.www.machinegunkelly.net
nooby.it *.nooby.it *.www.nooby.it
*.mail.paxmonsportswear.com paxmonsportswear.com *.paxmonsportswear.com
*.cpanel.shutter.today *.services.shutter.today shutter.today *.shutter.today *.webdisk.shutter.today *.ww25.shutter.today
*.access.xn--z4qr76d.com *.agent.xn--z4qr76d.com *.api.xn--z4qr76d.com *.apps.xn--z4qr76d.com *.b84026dd-3eaa-4650-9e90-40313989d7db.xn--z4qr76d.com *.dev.xn--z4qr76d.com *.gateway.xn--z4qr76d.com *.home.xn--z4qr76d.com *.hxjoomobile.xn--z4qr76d.com *.m.xn--z4qr76d.com *.mta-sts.xn--z4qr76d.com *.news.xn--z4qr76d.com *.phpmyadmin.xn--z4qr76d.com *.portal.xn--z4qr76d.com *.pxewbwebvpn.xn--z4qr76d.com *.rd.xn--z4qr76d.com *.rds.xn--z4qr76d.com *.rdweb.xn--z4qr76d.com *.remoto.xn--z4qr76d.com *.tlzxghao.xn--z4qr76d.com *.ts.xn--z4qr76d.com *.vpn.xn--z4qr76d.com *.vpn1.xn--z4qr76d.com *.vpn2.xn--z4qr76d.com *.wap.xn--z4qr76d.com *.web.xn--z4qr76d.com *.www.xn--z4qr76d.com xn--z4qr76d.com *.xn--z4qr76d.com