Open
Cached
·
just now
79/100
SECURITY SCORE
Certificate Information
Subject
CN=instantarticles.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 01, 2026
Valid Until
May 02, 2026
83 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
02:FF:CA:6A:5D:30:79:5D:E1:B3:95:4B:2C:F9:B2:81:D5:E1:3F:E3:3C:80:E4:31:5A:35:9C:01:76:B5:89:76
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
bionicwall.top
*.bionicwall.top
5236.net
*.5236.net
*.secure.5236.net
971crxy301.top
*.971crxy301.top
972clx301.top
*.972clx301.top
adelaiderestaurants.com
*.adelaiderestaurants.com
agroouro.com
*.agroouro.com
aidiligence.pro
*.aidiligence.pro
alrefaidamas.com
*.alrefaidamas.com
arrhib.gifts
*.arrhib.gifts
*.demo.arrhib.gifts
assalampanel.org
*.assalampanel.org
beeviveuk.com
*.beeviveuk.com
blood-distribution-works-near.xyz
*.blood-distribution-works-near.xyz
bloq.com.au
*.bloq.com.au
blowhealth.com
*.blowhealth.com
bluebashcanada.com
*.bluebashcanada.com
breast-cancer-therapy-0131.click
*.breast-cancer-therapy-0131.click
buradakiurunlerebakmadanbaskayeregitmeyin.shop
*.buradakiurunlerebakmadanbaskayeregitmeyin.shop
bycarinfo.com
*.bycarinfo.com
caviarcut.com
*.caviarcut.com
chancle.org
*.chancle.org
compassionafricaaid.org
*.compassionafricaaid.org
createwithcrescendo.com
*.createwithcrescendo.com
cuili.com
*.cuili.com
*.mobileconnect.cuili.com
dapsactivemints.com
*.dapsactivemints.com
datingservices.com.au
*.datingservices.com.au
davidandgoliath.com.au
*.davidandgoliath.com.au
designstudiosbyjustin.com
*.designstudiosbyjustin.com
dubrovniktourism.com
*.dubrovniktourism.com
emailingtrigifyplatform.com
*.emailingtrigifyplatform.com
entrance-exam-256839733.click
*.entrance-exam-256839733.click
eycwr.net
*.eycwr.net
f04hbxa.top
*.f04hbxa.top
fordealdeg.shop
*.fordealdeg.shop
freshknot.com
*.freshknot.com
ggbet-pl.casino
*.ggbet-pl.casino
gulfyy.com
*.gulfyy.com
infer.com.au
*.infer.com.au
instantarticles.com
*.instantarticles.com
*.m.instantarticles.com
invisibledentalaligners089794.icu
*.invisibledentalaligners089794.icu
joni88rtp32.cfd
*.joni88rtp32.cfd
kansasexchange.com
*.kansasexchange.com
kzamr.net
*.kzamr.net
Other domains in certificate