76/100 SECURITY SCORE

Certificate Information

Subject
CN=omantradingllc.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
05:17:7B:A5:1E:B2:50:DC:64:6D:B7:73:77:6A:E2:93:FE:21:D0:91:BA:08:F6:DF:9F:A2:92:01:92:0E:2C:85
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
gonflable.com *.gonflable.com *.api.gonflable.com *.cairn.gonflable.com *.dev.gonflable.com *.mail.gonflable.com *.test.gonflable.com *.ww25.gonflable.com

Other domains in certificate

2930.my *.2930.my *.cpanel.2930.my *.webdisk.2930.my *.whm.2930.my
*.admin.buyleads.net *.af06ef13-33e2-4b74-8b09-a53cbeaf2b20.buyleads.net *.api.buyleads.net *.app.buyleads.net *.b28a6872-9d5a-4148-96e3-60dcd6d27026.buyleads.net buyleads.net *.buyleads.net *.dan.buyleads.net *.dev.buyleads.net *.hostmaster.buyleads.net *.kmfnpwebmail.buyleads.net *.mail.buyleads.net *.random.buyleads.net *.remote.buyleads.net *.stape.buyleads.net *.webmail.buyleads.net *.www.buyleads.net *.wwww.buyleads.net *.yandex-staff.buyleads.net
*.backend.chiarina.it chiarina.it *.chiarina.it *.metrics.chiarina.it *.remote.chiarina.it
*.admin.crypto-tips.com *.cpanel.crypto-tips.com crypto-tips.com *.crypto-tips.com *.fornex.crypto-tips.com *.intranet.crypto-tips.com *.m.crypto-tips.com *.old.crypto-tips.com *.pop.crypto-tips.com *.vpn.crypto-tips.com *.www.crypto-tips.com *.www1.crypto-tips.com
frank.net.au *.frank.net.au *.mail.frank.net.au *.remote.frank.net.au
*.hs2.naijanet.xyz naijanet.xyz *.naijanet.xyz *.voorraad.naijanet.xyz *.ww16.naijanet.xyz *.ww25.naijanet.xyz *.ww38.naijanet.xyz
*.acoffeebean.nrtb.org *.atlanticheatandair.nrtb.org *.boxarec.nrtb.org *.campusdiets.nrtb.org *.ceramihvac.nrtb.org *.colonoscopyrisks.nrtb.org *.countrywideac.nrtb.org *.dailydose.nrtb.org *.deadflamingoes.nrtb.org *.dustbureau.nrtb.org *.easyrvrentals.nrtb.org *.efcsw.nrtb.org *.financerns.nrtb.org *.floridaclimatealliance.nrtb.org *.infoballet.nrtb.org nrtb.org *.nrtb.org *.pennyswellnesssolutions.nrtb.org *.pglo.nrtb.org *.ratingdietplans.nrtb.org *.savvymusic.nrtb.org *.sportsbookends.nrtb.org *.supercoloncleanses.nrtb.org *.weightlosscop.nrtb.org *.wvicfa.nrtb.org
*.connect.omantradingllc.com omantradingllc.com *.omantradingllc.com
rebourne.org *.rebourne.org