Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=askingforafriend.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 04, 2026
Valid Until
July 03, 2026
30 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:7B:22:36:79:5E:A8:7E:31:0E:8F:6E:66:A5:8C:A9:56:43:81:3F:1E:B1:3F:C2:61:21:BC:19:49:DF:77:7D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ccrain.com
*.ccrain.com
*.feedback.ccrain.com
*.forms.ccrain.com
*.img.ccrain.com
*.mobile.ccrain.com
*.movies.ccrain.com
*.qa.ccrain.com
*.random.ccrain.com
*.stage.ccrain.com
*.ww25.ccrain.com
ageingcare.com.au
*.ageingcare.com.au
alienvrspredator.com
*.alienvrspredator.com
*.8joac.askingforafriend.xyz
askingforafriend.xyz
*.askingforafriend.xyz
*.c6udy.askingforafriend.xyz
*.cclpcxbzeu0afmf.askingforafriend.xyz
*.d.askingforafriend.xyz
*.m.askingforafriend.xyz
*.rczhl.askingforafriend.xyz
*.v6j6e.askingforafriend.xyz
autowrecks.com
*.autowrecks.com
boya.life
*.boya.life
*.website.boya.life
clcq.org
*.clcq.org
compareandswitch.au
*.compareandswitch.au
*.ww25.compareandswitch.au
drakerock.com
*.drakerock.com
*.poc.drakerock.com
*.promo.drakerock.com
*.random.drakerock.com
*.reporting.drakerock.com
*.sandbox.drakerock.com
*.ww16.drakerock.com
*.ww31.drakerock.com
ezacter.com
*.ezacter.com
*.blog.gmaptool.com
*.co.gmaptool.com
gmaptool.com
*.gmaptool.com
*.ww25.gmaptool.com
*.youtube.gmaptool.com
hj4f6f.com
*.hj4f6f.com
hj87e5.com
*.hj87e5.com
intermountainmotorsportspark.com
*.intermountainmotorsportspark.com
*.edu.jiusetv.xyz
jiusetv.xyz
*.jiusetv.xyz
*.ww38.jiusetv.xyz
k-v.de
*.k-v.de
*.service.k-v.de
*.ac.lww.au
*.g.lww.au
lww.au
*.lww.au
*.ww25.lww.au
*.wxwamb.lww.au
otgsolar.com
*.otgsolar.com
ozi.com.pl
*.ozi.com.pl
philipsflattv.com
*.philipsflattv.com
searsliquidationcenter.com
*.searsliquidationcenter.com
sparrows.org
*.sparrows.org
stardomainbroker.com
*.stardomainbroker.com
*.demo.sunocobusinessaccountonline.com
*.old.sunocobusinessaccountonline.com
sunocobusinessaccountonline.com
*.sunocobusinessaccountonline.com
*.test.sunocobusinessaccountonline.com
*.ww16.sunocobusinessaccountonline.com
womensbikinis.com
*.womensbikinis.com
Other domains in certificate