Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=bankoftheunitedstate.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EF:B9:42:F9:8C:94:E6:FF:6F:27:D5:58:41:F6:84:89:F9:93:F6:78:E9:32:67:59:E6:D6:1A:AD:BF:12:13:32
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
breitenberg.it
*.breitenberg.it
bankoftheunitedstate.com
*.bankoftheunitedstate.com
basement-wall-repair-leak.click
*.basement-wall-repair-leak.click
belujis.click
*.belujis.click
bergers.it
*.bergers.it
best-water-filtration-systems.click
*.best-water-filtration-systems.click
bestcompanies.it
*.bestcompanies.it
bnpglobal-team.com
*.bnpglobal-team.com
bnpglobalteam.com
*.bnpglobalteam.com
booter.it
*.booter.it
breakfromgaming.com
*.breakfromgaming.com
breakice.it
*.breakice.it
breakit.it
*.breakit.it
brenttilley.com
*.brenttilley.com
bresciablog.it
*.bresciablog.it
bretmora.cfd
*.bretmora.cfd
brewed.it
*.brewed.it
brewmaster.it
*.brewmaster.it
brewshop.it
*.brewshop.it
brianzahotels.it
*.brianzahotels.it
brick-foundation-943106409.click
*.brick-foundation-943106409.click
bridgetofunding.com
*.bridgetofunding.com
buyandgo.it
*.buyandgo.it
c59s01.shop
*.c59s01.shop
cargofive-team.com
*.cargofive-team.com
carpenters.it
*.carpenters.it
carpet-cleaning-job-grey-pan.click
*.carpet-cleaning-job-grey-pan.click
cenik.it
*.cenik.it
centerenergy.net
*.centerenergy.net
centroassistenza.net
*.centroassistenza.net
changsheng288m.cc
*.changsheng288m.cc
cheap-phone-aus1.click
*.cheap-phone-aus1.click
cigarmarket.it
*.cigarmarket.it
cleanfox.click
*.cleanfox.click
climated.it
*.climated.it
comfortclass.it
*.comfortclass.it
compri-team.com
*.compri-team.com
connectwithleadifyhq.com
*.connectwithleadifyhq.com
conpassassociate.com
*.conpassassociate.com
couponcodesr.us
*.couponcodesr.us
crispfelira.com
*.crispfelira.com
critter.camera
*.critter.camera
defaitech.xyz
*.defaitech.xyz
derajat.org
*.derajat.org
desires.it
*.desires.it
Other domains in certificate