76/100 SECURITY SCORE

Certificate Information

Subject
CN=806085.blog
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 13, 2026
Valid Until
August 11, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
65:E1:B8:D5:6D:8D:52:1E:AA:02:34:3F:39:E4:A9:47:AE:D7:97:6A:28:5A:FA:7B:E4:F7:D9:57:6E:90:3E:97
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
crossref.it *.crossref.it *.billing.crossref.it *.demo.crossref.it *.game.crossref.it

Other domains in certificate

119472.com *.119472.com *.agf.119472.com
69219.blog *.69219.blog
806085.blog *.806085.blog
bwmgyf8zhg.top *.bwmgyf8zhg.top
*.connect.dhrintl.com dhrintl.com *.dhrintl.com *.diamondrecruiter.dhrintl.com *.help.dhrintl.com *.workflow.dhrintl.com *.ww42.dhrintl.com
erpsolutions.co *.erpsolutions.co *.www.erpsolutions.co
firstgiveaway.de *.firstgiveaway.de
*.1d400.haejung.com *.5d4so.haejung.com *.7s4n6.haejung.com *.9dwed.haejung.com *.awux2.haejung.com *.backup.haejung.com *.beta.haejung.com *.bozlp.haejung.com *.crm.haejung.com *.demo.haejung.com *.dns.haejung.com *.fjc81.haejung.com haejung.com *.haejung.com *.kne9a.haejung.com *.m.haejung.com *.remote.haejung.com *.sitemap.haejung.com *.sitemaps.haejung.com *.vpn.haejung.com *.wildcard.haejung.com *.x9ym5.haejung.com *.xxua6.haejung.com
*.adm.igoro.com.br *.admin.igoro.com.br *.api.igoro.com.br igoro.com.br *.igoro.com.br *.mail.igoro.com.br *.novo.igoro.com.br *.ns1.igoro.com.br *.ww25.igoro.com.br
*.backup.isitworthitfl.net *.ftp.isitworthitfl.net isitworthitfl.net *.isitworthitfl.net
*.backend.isuntzu.com *.cpcontacts.isuntzu.com *.dev.isuntzu.com isuntzu.com *.isuntzu.com *.mail.isuntzu.com *.mmail.isuntzu.com
*.dev.mydomainprofolio.com mydomainprofolio.com *.mydomainprofolio.com *.sitemap.mydomainprofolio.com
*.integration.nhwntai.net *.netww38.nhwntai.net nhwntai.net *.nhwntai.net *.sandbox.nhwntai.net *.ww35.nhwntai.net *.ww38.nhwntai.net
*.comune.scratchophone.com *.new.scratchophone.com scratchophone.com *.scratchophone.com
thai-massage.click *.thai-massage.click
thesunriseinn.com *.thesunriseinn.com *.ww38.thesunriseinn.com