Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=eagleairindonesia.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
68 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:5D:5D:3C:08:70:B7:F4:DB:52:2B:39:B8:80:61:6A:0A:CF:2E:FA:E1:27:9C:EE:37:7A:7E:B1:88:53:D2:2C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
gence.it
*.gence.it
barefootslippers.com
*.barefootslippers.com
*.random.barefootslippers.com
*.ww38.barefootslippers.com
dzqku.net
*.dzqku.net
eagleairindonesia.com
*.eagleairindonesia.com
elainecristina.com
*.elainecristina.com
emotional-well-938016422.click
*.emotional-well-938016422.click
en25.top
*.en25.top
enriched.it
*.enriched.it
eo88bet.com
*.eo88bet.com
eportalnow.net
*.eportalnow.net
evaso.it
*.evaso.it
executiveclassic.com
*.executiveclassic.com
exoticfoodelegance.food
*.exoticfoodelegance.food
f1c6f8784fb34d8f.com
*.f1c6f8784fb34d8f.com
f64442580.com
*.f64442580.com
f64465176.com
*.f64465176.com
f64474971.com
*.f64474971.com
facelessaccount.com
*.facelessaccount.com
fakephonepe.pro
*.fakephonepe.pro
fastenertradeshow.info
*.fastenertradeshow.info
fbinter.com
*.fbinter.com
fedlife.com
*.fedlife.com
ffhh7.cc
*.ffhh7.cc
fin4bids.click
*.fin4bids.click
financetoolskit.com
*.financetoolskit.com
fingame77.pro
*.fingame77.pro
fitnessessencelife.live
*.fitnessessencelife.live
fixedratemortgages.it
*.fixedratemortgages.it
floods.co
*.floods.co
fm69kk.college
*.fm69kk.college
fmfundo.com
*.fmfundo.com
fomosummit.com
*.fomosummit.com
forfashion.it
*.forfashion.it
fortschritt-akademie-24.org
*.fortschritt-akademie-24.org
foya88nibos.org
*.foya88nibos.org
freshhouse.it
*.freshhouse.it
furlanet.com
*.furlanet.com
g9av21.top
*.g9av21.top
gemoydarius.cfd
*.gemoydarius.cfd
generalmills.it
*.generalmills.it
getyourshiftright.net
*.getyourshiftright.net
gingerayodhya.com
*.gingerayodhya.com
globecarrental.it
*.globecarrental.it
ethiopianembassy.org.in
*.ethiopianembassy.org.in
Other domains in certificate