Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=04492.blog
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 10, 2026
Valid Until
September 08, 2026
80 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C2:3E:DA:97:51:0F:13:9A:FD:D7:9E:76:BB:4D:5C:93:D0:ED:7E:89:22:45:D6:A8:47:FD:6D:C3:4A:9D:39:07
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
84 domains
blitzsex.com
*.blitzsex.com
04492.blog
*.04492.blog
1216rpt301.top
*.1216rpt301.top
259946.pro
*.259946.pro
26498574.vip
*.26498574.vip
aitechwest.com
*.aitechwest.com
ajinetworks.com
*.ajinetworks.com
alibabamxservices.com
*.alibabamxservices.com
alkhleej.com
*.alkhleej.com
alphaintelligence.vc
*.alphaintelligence.vc
atbtasmekrjgpav.my
*.atbtasmekrjgpav.my
blackrock.me
*.blackrock.me
blcjf.my
*.blcjf.my
blockpathguard.icu
*.blockpathguard.icu
dementiacentral.com
*.dementiacentral.com
edocarehome.com
*.edocarehome.com
esportscis.com
*.esportscis.com
fahrstilgarage.com
*.fahrstilgarage.com
gurefano.com
*.gurefano.com
hjc0c3.com
*.hjc0c3.com
hpy999.vip
*.hpy999.vip
isocertificazioni.click
*.isocertificazioni.click
kaigegfg-pro.xyz
*.kaigegfg-pro.xyz
kbi2082.cc
*.kbi2082.cc
lomastick.sbs
*.lomastick.sbs
mzrkh.com
*.mzrkh.com
n5zt9.lol
*.n5zt9.lol
ncqdu.loan
*.ncqdu.loan
nztd48.net
*.nztd48.net
onewyt.cc
*.onewyt.cc
pawestruck.com
*.pawestruck.com
playcash-slot.xyz
*.playcash-slot.xyz
qianweicq.com.cn
*.qianweicq.com.cn
resmii-imajbet.com
*.resmii-imajbet.com
sacredoracleacademy.online
*.sacredoracleacademy.online
travelsavvyofficial.live
*.travelsavvyofficial.live
tryoceanvirtualassistant.top
*.tryoceanvirtualassistant.top
tryoperhand.com
*.tryoperhand.com
tryownstak-team.net
*.tryownstak-team.net
useownstaklabs.com
*.useownstaklabs.com
vekee.it.com
*.vekee.it.com
xn--fp-yqa.co
*.xn--fp-yqa.co
Other domains in certificate