Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=redstone.company
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 28, 2026
Valid Until
April 28, 2026
78 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:05:60:6A:15:D3:C7:A4:48:A4:D4:FC:BE:44:8C:F9:74:2D:77:38:9D:40:F7:8B:6E:DD:75:B7:D5:66:36:58
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
bjsrestuants.com
*.bjsrestuants.com
5starsworldwide.store
*.5starsworldwide.store
avj4.us
*.avj4.us
baseballmenace.com
*.baseballmenace.com
broadstone57.com
*.broadstone57.com
buythemone.com
*.buythemone.com
calypsosowavy.com
*.calypsosowavy.com
cbotv0al6tnaav1i6-5.com
*.cbotv0al6tnaav1i6-5.com
courtpaytinc.com
*.courtpaytinc.com
crmservicescareers.us
*.crmservicescareers.us
db7eece89b.com
*.db7eece89b.com
deltarune.us
*.deltarune.us
denwwticon.com
*.denwwticon.com
dexmmlftj.com
*.dexmmlftj.com
egtqwibcej.com
*.egtqwibcej.com
frontsteops.com
*.frontsteops.com
gardengrown.com.au
*.gardengrown.com.au
gdlmh6seh.com
*.gdlmh6seh.com
gmc-de.com
*.gmc-de.com
gmstaffingny.com
*.gmstaffingny.com
h1-obylo4lvoirz.com
*.h1-obylo4lvoirz.com
harriscreditlaw.com
*.harriscreditlaw.com
igtampe.co
*.igtampe.co
jp-films.co
*.jp-films.co
jwcviinfo.com
*.jwcviinfo.com
ktpdev.com
*.ktpdev.com
legashieldexpo.com
*.legashieldexpo.com
lesaubergesdejeunessedesardennes.be
*.lesaubergesdejeunessedesardennes.be
liga365gacor.com
*.liga365gacor.com
marriottvacations-worldwide.com
*.marriottvacations-worldwide.com
mydashborad.com
*.mydashborad.com
neuvmmjfyknq.com
*.neuvmmjfyknq.com
newscity.store
*.newscity.store
nhetai.website
*.nhetai.website
nordicasanua.com
*.nordicasanua.com
nortec.cc
*.nortec.cc
*.8.obrqv.site
*.f.obrqv.site
obrqv.site
*.obrqv.site
redstone.company
*.redstone.company
rondoniaplus.com.br
*.rondoniaplus.com.br
sapcommissionsondemand.com
*.sapcommissionsondemand.com
searchautoreport.com
*.searchautoreport.com
shorebreak.com.au
*.shorebreak.com.au
uaoc.net
*.uaoc.net
weitenoffice.com
*.weitenoffice.com
Other domains in certificate