Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=californiacovered.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 23, 2026
Valid Until
May 24, 2026
87 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9F:5C:83:38:5F:A7:BD:DB:21:A0:C6:3A:1D:4A:6B:0E:61:BB:DC:6E:97:F4:DC:DD:90:DB:D5:C6:7D:64:07:85
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
vanngoc.com
*.vanngoc.com
*.admin.vanngoc.com
*.api.vanngoc.com
*.blog.vanngoc.com
*.dev.vanngoc.com
*.eml.vanngoc.com
*.home.vanngoc.com
*.hostmaster.vanngoc.com
*.m.vanngoc.com
*.members.vanngoc.com
*.mx.vanngoc.com
*.ns1.vanngoc.com
*.rds1.vanngoc.com
*.remoto.vanngoc.com
*.send.vanngoc.com
*.shop.vanngoc.com
*.site1.vanngoc.com
*.sitemaps.vanngoc.com
*.sniper.vanngoc.com
*.staging.vanngoc.com
*.test.vanngoc.com
*.vpn2.vanngoc.com
*.ww1.vanngoc.com
*.ww15.vanngoc.com
*.ww16.vanngoc.com
*.ww17.vanngoc.com
*.ww25.vanngoc.com
*.ww38.vanngoc.com
*.ww5.vanngoc.com
991dmy301.top
*.991dmy301.top
*.autodiscover.californiacovered.com
californiacovered.com
*.californiacovered.com
*.ww25.californiacovered.com
cershqu528.vip
*.cershqu528.vip
crnseraronioasdalwise.cyou
*.crnseraronioasdalwise.cyou
crudeoiledge.com
*.crudeoiledge.com
customquads.com.au
*.customquads.com.au
kansaspremiumbeef.com
*.kansaspremiumbeef.com
kapvi.com
*.kapvi.com
*.www.kapvi.com
kcc6473.cc
*.kcc6473.cc
kkhxl4c.cyou
*.kkhxl4c.cyou
kween.chat
*.kween.chat
*.49102a1c-ae69-4097-be3a-9875223acd2a.mctundra.net
*.4f73df7f-ad86-4c9b-b554-4566db5ae1eb.mctundra.net
*.52004447-b78c-41b8-a17f-ddc3e18c25d4.mctundra.net
*.6992be4f-f173-4f02-86c8-eabc4ed6768c.mctundra.net
*.76b57039-0f8a-4fc8-8a87-e741d0246747.mctundra.net
*.93084a6e-f473-4b3a-8073-fc12d52e69a5.mctundra.net
*.9410309c-68f9-46ce-9499-21ce697e3a00.mctundra.net
*.admin.mctundra.net
*.backup.mctundra.net
*.c3f89ed9-dad9-4824-8c4e-9caf7cd6b9e7.mctundra.net
*.c6a7ae7b-7caa-4e12-8d8a-5877deafb12b.mctundra.net
*.calhost.mctundra.net
*.e7b74bf2-2a1a-4b42-9256-c435164a3baa.mctundra.net
*.f9de77fd-5350-4d8c-ac2d-52d84acdbde4.mctundra.net
*.fd79f762-55c0-4019-a808-631179cd5df3.mctundra.net
*.ftp.mctundra.net
*.hm.mctundra.net
*.hostmaster.mctundra.net
*.kbcyrcpanel.mctundra.net
*.khvehsst.mctundra.net
*.localhost.mctundra.net
*.mail.mctundra.net
mctundra.net
*.mctundra.net
*.pop.mctundra.net
*.skbnghostmaster.mctundra.net
*.smtp.mctundra.net
*.soa.mctundra.net
*.vpn.mctundra.net
*.whm.mctundra.net
moda.toys
*.moda.toys
panzer.de
*.panzer.de
*.poeschmann.panzer.de
Other domains in certificate