Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=sumupstor.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 07, 2026
Valid Until
May 08, 2026
74 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D3:8B:89:A5:E8:F7:01:87:D0:FC:97:89:DB:06:5E:F5:33:47:00:A5:29:78:4E:A1:E4:CD:74:01:46:A8:5E:A4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
braindeads.com
*.braindeads.com
178007.vip
*.178007.vip
36313.one
*.36313.one
53150.loan
*.53150.loan
54a4mw.top
*.54a4mw.top
59299.one
*.59299.one
70593.loan
*.70593.loan
79165.one
*.79165.one
813925.ltd
*.813925.ltd
87072.top
*.87072.top
95597.me
*.95597.me
977734.com
*.977734.com
99959.loan
*.99959.loan
abalonapp.com
*.abalonapp.com
ai-trained.com
*.ai-trained.com
aikuaikao.com
*.aikuaikao.com
alovetiga.my
*.alovetiga.my
alugueldegeradorrj785570.icu
*.alugueldegeradorrj785570.icu
annamoreno.com
*.annamoreno.com
anndaramola.net
*.anndaramola.net
anndaramola.org
*.anndaramola.org
architectureassimilation.top
*.architectureassimilation.top
armscoop.com
*.armscoop.com
ascis--shoes.site
*.ascis--shoes.site
avantgardejapan.com
*.avantgardejapan.com
aviso.one
*.aviso.one
b14879769.com
*.b14879769.com
bage.it
*.bage.it
baisha.co
*.baisha.co
bankingonline2025.buzz
*.bankingonline2025.buzz
bathcat.lol
*.bathcat.lol
betyap672.com
*.betyap672.com
biotinforhair.site
*.biotinforhair.site
bonusbonaza.life
*.bonusbonaza.life
brixora.com
*.brixora.com
capitalevents.online
*.capitalevents.online
carpet-cleaning-au-pablo.click
*.carpet-cleaning-au-pablo.click
bjnsk.com.cn
*.bjnsk.com.cn
*.askimkcbio.sumupstor.com
*.biondo-shop.sumupstor.com
*.bulltay.sumupstor.com
*.cesenteurs.sumupstor.com
*.greenmanpowerplants.sumupstor.com
*.mariconceptstore.sumupstor.com
*.sabcreabijoux.sumupstor.com
sumupstor.com
*.sumupstor.com
tourbooking.asia
*.tourbooking.asia
wangxiansheng.site
*.wangxiansheng.site
Other domains in certificate