Open
Cached
·
4h ago
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=fyist.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 02, 2026
Valid Until
August 31, 2026
65 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9D:9D:62:83:49:78:98:40:EC:D5:FE:34:DF:D7:42:8C:71:05:56:46:ED:28:48:56:00:6D:4D:5E:31:DE:BA:65
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
cannachips.com
*.cannachips.com
*.wildcard.cannachips.com
*.admin.assistance-impotgouv.com
*.api.assistance-impotgouv.com
*.app.assistance-impotgouv.com
assistance-impotgouv.com
*.assistance-impotgouv.com
*.backend.assistance-impotgouv.com
*.demo.assistance-impotgouv.com
*.dev.assistance-impotgouv.com
*.hostmaster.assistance-impotgouv.com
*.random.assistance-impotgouv.com
*.staging.assistance-impotgouv.com
*.ww1.assistance-impotgouv.com
*.ww12.assistance-impotgouv.com
*.ww7.assistance-impotgouv.com
*.www.assistance-impotgouv.com
cazpitalone.com
*.cazpitalone.com
*.ci.cazpitalone.com
*.cicd.cazpitalone.com
*.domains.cazpitalone.com
*.pipeline.cazpitalone.com
*.wpionhub.cazpitalone.com
*.ww1.cazpitalone.com
*.ww38.cazpitalone.com
coolworks.co
*.coolworks.co
*.ww38.coolworks.co
*.autodiscover.fyist.com
*.cpanel.fyist.com
*.cpcalendars.fyist.com
*.cpcontacts.fyist.com
*.eobcfw.fyist.com
fyist.com
*.fyist.com
*.lxn.fyist.com
*.m.fyist.com
*.mail.fyist.com
*.webdisk.fyist.com
*.webmail.fyist.com
*.32.kureio.com
kureio.com
*.kureio.com
*.94325fb4-d7ab-45e6-a6f3-665b99096db8.mainzu.es
*.app.mainzu.es
mainzu.es
*.mainzu.es
*.pop.mainzu.es
*.smtp.mainzu.es
*.www.mainzu.es
*.atclickschool.moyacomputech.com
moyacomputech.com
*.moyacomputech.com
*.rainbowpaintfactory.moyacomputech.com
*.staging.moyacomputech.com
*.appdon.myhayward.us
*.bumblepaul.myhayward.us
*.chimatch.myhayward.us
*.clicksgfriend.myhayward.us
*.cruisesites.myhayward.us
*.gfriendfy.myhayward.us
*.iesapp.myhayward.us
*.industriesbumble.myhayward.us
myhayward.us
*.myhayward.us
*.singlemba.myhayward.us
*.terpersonal.myhayward.us
*.worthymatch.myhayward.us
*.zooblog.myhayward.us
*.api.techinviting.art
*.pu9g8h.techinviting.art
techinviting.art
*.techinviting.art
*.mx.tvtelecast.com
tvtelecast.com
*.tvtelecast.com
*.www.tvtelecast.com
*.blog.whq.in
*.hostmaster.whq.in
*.in.whq.in
*.m.whq.in
*.mpukxqyaesns2.whq.in
*.primary.whq.in
*.qyaesns2.whq.in
whq.in
*.whq.in
*.www.whq.in
Other domains in certificate