Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=americalot.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 10, 2026
Valid Until
April 10, 2026
59 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A5:F7:A8:DA:FA:2A:F1:28:DD:F6:7D:50:90:24:CB:D4:73:AD:05:01:20:58:0E:D2:B7:47:42:1A:EC:CF:70:21
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
91 domains
bld77.com
*.bld77.com
5lsold.com
*.5lsold.com
alfabot.biz
*.alfabot.biz
amberjasmine.vip
*.amberjasmine.vip
americalot.com
*.americalot.com
americanssubsidyact.com
*.americanssubsidyact.com
amonamon.shop
*.amonamon.shop
amooshahab.website
*.amooshahab.website
amorkicks.com
*.amorkicks.com
andana.fun
*.andana.fun
anexk.com
*.anexk.com
areba.ai
*.areba.ai
avz19.org
*.avz19.org
barwatool.com
*.barwatool.com
basedgig.link
*.basedgig.link
beneficiosnomina.co
*.beneficiosnomina.co
bento123rtp.us
*.bento123rtp.us
berlessa.com
*.berlessa.com
berobello.xyz
*.berobello.xyz
bestgold.fun
*.bestgold.fun
biharinterresult.com
*.biharinterresult.com
blazeshuffel.com
*.blazeshuffel.com
brawlli.vip
*.brawlli.vip
bux.deals
*.bux.deals
buytivano.com
*.buytivano.com
buyvano.com
*.buyvano.com
buzkoa.live
*.buzkoa.live
buzkora.co
*.buzkora.co
buzzcash3.co
*.buzzcash3.co
bynet.fun
*.bynet.fun
chessonsmoke.com
*.chessonsmoke.com
clipphotvn.blog
*.clipphotvn.blog
csgopick.fun
*.csgopick.fun
*.www.csgopick.fun
dewakoin99.space
*.dewakoin99.space
dienlanhductruong.com
*.dienlanhductruong.com
dontstopgetitwedit.info
*.dontstopgetitwedit.info
downeyuspost.shop
*.downeyuspost.shop
downloadchristianbooks.info
*.downloadchristianbooks.info
dowrn.org
*.dowrn.org
drhomotion.co
*.drhomotion.co
egeeks.click
*.egeeks.click
elatestnews.click
*.elatestnews.click
elefants.shop
*.elefants.shop
hrgshoes.com
*.hrgshoes.com
whatbd.com
*.whatbd.com
Other domains in certificate