Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=craftedbalm.shop
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 24, 2026
Valid Until
August 22, 2026
68 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BF:90:EA:A4:36:9E:74:EF:89:8A:7B:5D:1F:F8:C2:B1:84:69:F6:16:4B:B4:BF:17:01:8D:73:67:C5:46:F4:03
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
84 domains
byuti.shop
*.byuti.shop
4ty.shop
*.4ty.shop
9movis.shop
*.9movis.shop
absolutelinklogin.shop
*.absolutelinklogin.shop
achitcity.com
*.achitcity.com
*.love.achitcity.com
*.mail.achitcity.com
*.test.achitcity.com
blk6b5.shop
*.blk6b5.shop
coconutmayorista.shop
*.coconutmayorista.shop
craftedbalm.shop
*.craftedbalm.shop
cumhas.shop
*.cumhas.shop
dreamboosters.shop
*.dreamboosters.shop
easyclick-24.shop
*.easyclick-24.shop
endmants.online
*.endmants.online
*.ww25.endmants.online
*.ai.fera.com
*.almir.fera.com
*.app.fera.com
*.apples.fera.com
*.colegi.fera.com
*.cqbdri.fera.com
*.devita.fera.com
fera.com
*.fera.com
*.fhj.fera.com
*.hotmail.fera.com
*.int.fera.com
*.random.fera.com
*.ww25.fera.com
*.ww7.fera.com
*.you.fera.com
findluv.shop
*.findluv.shop
folus.shop
*.folus.shop
gitcombust.shop
*.gitcombust.shop
jicamasosteal.shop
*.jicamasosteal.shop
mjsqus5.shop
*.mjsqus5.shop
moviezota14.shop
*.moviezota14.shop
nanweitoole.shop
*.nanweitoole.shop
ovovegas.shop
*.ovovegas.shop
raregem.shop
*.raregem.shop
subliblanksj.shop
*.subliblanksj.shop
superkumi.shop
*.superkumi.shop
taiime.shop
*.taiime.shop
tenhun.shop
*.tenhun.shop
tenthousands.shop
*.tenthousands.shop
thinkpikeblenny.shop
*.thinkpikeblenny.shop
typemaker.shop
*.typemaker.shop
vroutfitters.shop
*.vroutfitters.shop
*.global.windowsazurebootcamp.com
*.mta-sts.windowsazurebootcamp.com
windowsazurebootcamp.com
*.windowsazurebootcamp.com
yumekirara.shop
*.yumekirara.shop
Other domains in certificate