Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=castle-estates.co
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 17, 2026
Valid Until
September 15, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
04:12:E3:2A:28:68:BB:CB:B7:67:1F:5E:3D:7C:D4:13:81:AF:39:BB:B6:D4:22:F0:EB:6A:B4:1A:62:39:4B:01
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
btcmakerpro.com
*.btcmakerpro.com
*.app.btcmakerpro.com
*.forum.btcmakerpro.com
*.it.btcmakerpro.com
*.machine.btcmakerpro.com
*.random.btcmakerpro.com
*.ww25.btcmakerpro.com
*.admin.btcczechrepublic.com
*.bmc.btcczechrepublic.com
btcczechrepublic.com
*.btcczechrepublic.com
*.czxv241xal92.btcczechrepublic.com
*.pool.btcczechrepublic.com
*.spider.btcczechrepublic.com
*.store.btcczechrepublic.com
castle-estates.co
*.castle-estates.co
*.liverpool.castle-estates.co
*.sheffield.castle-estates.co
*.ww25.castle-estates.co
*.ww38.castle-estates.co
*.access.ifs.com.pl
*.admin.ifs.com.pl
*.aniqmail.ifs.com.pl
*.asp.ifs.com.pl
*.astelmail.ifs.com.pl
*.bdo.ifs.com.pl
*.cisapp.ifs.com.pl
*.citrixcloud.ifs.com.pl
*.dash.ifs.com.pl
*.devarg.ifs.com.pl
*.email.ifs.com.pl
*.exchange2016.ifs.com.pl
*.gateway.ifs.com.pl
*.gp.ifs.com.pl
ifs.com.pl
*.ifs.com.pl
*.kra.ifs.com.pl
*.kru.ifs.com.pl
*.man.ifs.com.pl
*.msexch2k13.ifs.com.pl
*.mxynrjgf.ifs.com.pl
*.mywork.ifs.com.pl
*.notexistsifs003.ifs.com.pl
*.notexistsifs007.ifs.com.pl
*.notexistsifs011.ifs.com.pl
*.notexistsifs013.ifs.com.pl
*.notexistsifs016.ifs.com.pl
*.notexistsifs018.ifs.com.pl
*.notexistsifs021.ifs.com.pl
*.notexistsifs025.ifs.com.pl
*.notexistsifs026.ifs.com.pl
*.notexistsmobileconnect.ifs.com.pl
*.notexistsvpn5a.ifs.com.pl
*.nvdi.ifs.com.pl
*.one.ifs.com.pl
*.portal.ifs.com.pl
*.pri.ifs.com.pl
*.ra-vpn.ifs.com.pl
*.rdg.ifs.com.pl
*.rdgateway.ifs.com.pl
*.rdp.ifs.com.pl
*.rds.ifs.com.pl
*.rdweb.ifs.com.pl
*.redash.ifs.com.pl
*.remote.ifs.com.pl
*.remoteaccess.ifs.com.pl
*.remoteapps.ifs.com.pl
*.sama.ifs.com.pl
*.secureaccess.ifs.com.pl
*.sharepoint.ifs.com.pl
*.sign.ifs.com.pl
*.smtpa.ifs.com.pl
*.tsfweb.ifs.com.pl
*.vpnma.ifs.com.pl
*.vpntoj.ifs.com.pl
*.webmail05.ifs.com.pl
*.wip.ifs.com.pl
*.wwa.ifs.com.pl
*.zhydusfn.ifs.com.pl
*.zimbra.ifs.com.pl
mst88.xyz
*.mst88.xyz
*.ww11.mst88.xyz
*.ww25.mst88.xyz
*.amazon.viralpr.co.uk
*.random.viralpr.co.uk
viralpr.co.uk
*.viralpr.co.uk
Other domains in certificate