Cached · 4h ago
76/100 SECURITY SCORE

Certificate Information

Subject
CN=askingforafriend.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 04, 2026
Valid Until
July 03, 2026 30 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:7B:22:36:79:5E:A8:7E:31:0E:8F:6E:66:A5:8C:A9:56:43:81:3F:1E:B1:3F:C2:61:21:BC:19:49:DF:77:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ccrain.com *.ccrain.com *.feedback.ccrain.com *.forms.ccrain.com *.img.ccrain.com *.mobile.ccrain.com *.movies.ccrain.com *.qa.ccrain.com *.random.ccrain.com *.stage.ccrain.com *.ww25.ccrain.com

Other domains in certificate

ageingcare.com.au *.ageingcare.com.au
alienvrspredator.com *.alienvrspredator.com
*.8joac.askingforafriend.xyz askingforafriend.xyz *.askingforafriend.xyz *.c6udy.askingforafriend.xyz *.cclpcxbzeu0afmf.askingforafriend.xyz *.d.askingforafriend.xyz *.m.askingforafriend.xyz *.rczhl.askingforafriend.xyz *.v6j6e.askingforafriend.xyz
autowrecks.com *.autowrecks.com
boya.life *.boya.life *.website.boya.life
clcq.org *.clcq.org
compareandswitch.au *.compareandswitch.au *.ww25.compareandswitch.au
drakerock.com *.drakerock.com *.poc.drakerock.com *.promo.drakerock.com *.random.drakerock.com *.reporting.drakerock.com *.sandbox.drakerock.com *.ww16.drakerock.com *.ww31.drakerock.com
ezacter.com *.ezacter.com
*.blog.gmaptool.com *.co.gmaptool.com gmaptool.com *.gmaptool.com *.ww25.gmaptool.com *.youtube.gmaptool.com
hj4f6f.com *.hj4f6f.com
hj87e5.com *.hj87e5.com
intermountainmotorsportspark.com *.intermountainmotorsportspark.com
*.edu.jiusetv.xyz jiusetv.xyz *.jiusetv.xyz *.ww38.jiusetv.xyz
k-v.de *.k-v.de *.service.k-v.de
*.ac.lww.au *.g.lww.au lww.au *.lww.au *.ww25.lww.au *.wxwamb.lww.au
otgsolar.com *.otgsolar.com
ozi.com.pl *.ozi.com.pl
philipsflattv.com *.philipsflattv.com
searsliquidationcenter.com *.searsliquidationcenter.com
sparrows.org *.sparrows.org
stardomainbroker.com *.stardomainbroker.com
*.demo.sunocobusinessaccountonline.com *.old.sunocobusinessaccountonline.com sunocobusinessaccountonline.com *.sunocobusinessaccountonline.com *.test.sunocobusinessaccountonline.com *.ww16.sunocobusinessaccountonline.com
womensbikinis.com *.womensbikinis.com