Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=droomms.net
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 26, 2026
Valid Until
July 25, 2026
63 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:C8:CA:EE:79:75:22:4E:65:29:B6:6B:29:E7:5D:AB:4F:D6:88:CA:BE:67:D7:61:0C:82:49:AD:BE:0B:49:A3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
82 domains
ccchhh2.cc
*.ccchhh2.cc
*.random.ccchhh2.cc
3205.live
*.3205.live
acnetreatment.com.au
*.acnetreatment.com.au
*.ci.acnetreatment.com.au
*.production.acnetreatment.com.au
androidalle.com
*.androidalle.com
arable.au
*.arable.au
autotok.studio
*.autotok.studio
backingamericas.com
*.backingamericas.com
bekasitoto.org
*.bekasitoto.org
bizimasia.com
*.bizimasia.com
bratashop.me
*.bratashop.me
btcearns3786.com
*.btcearns3786.com
*.pipeline.btcearns3786.com
*.random.btcearns3786.com
cooltextfonts.com
*.cooltextfonts.com
downloads-expert.com
*.downloads-expert.com
*.www.downloads-expert.com
droomms.net
*.droomms.net
dwwallsludlow.co.uk
*.dwwallsludlow.co.uk
expressvitals.org
*.expressvitals.org
foodillo.co
*.foodillo.co
injured.au
*.injured.au
jobinfinland.com
*.jobinfinland.com
kawaiikitty.co
*.kawaiikitty.co
lsjxx13.club
*.lsjxx13.club
malayalam.live
*.malayalam.live
*.soft.malayalam.live
meckpac.org
*.meckpac.org
*.adsys.myfbshare.net
*.cpanel.myfbshare.net
myfbshare.net
*.myfbshare.net
*.webmail.myfbshare.net
picassobeach.com
*.picassobeach.com
*.ww25.picassobeach.com
*.ww38.picassobeach.com
ql3t8g.cyou
*.ql3t8g.cyou
*.random.saleclipz4u.com
saleclipz4u.com
*.saleclipz4u.com
shortfilms.au
*.shortfilms.au
shuteharbour.au
*.shuteharbour.au
startupnet.io
*.startupnet.io
twraboatcert.com
*.twraboatcert.com
ventspace.org
*.ventspace.org
vetacademy2021.com
*.vetacademy2021.com
*.random.xfm.au
xfm.au
*.xfm.au
Other domains in certificate