Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=dashandpinch.blog
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 29, 2026
Valid Until
April 29, 2026
87 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F0:79:39:06:52:C1:1D:57:0D:D6:46:39:00:07:CF:91:57:0D:35:39:B9:15:8A:2C:39:F9:90:59:D7:93:9A:43
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
cgb.au
*.cgb.au
baufi.team
*.baufi.team
bbb24.net
*.bbb24.net
dashandpinch.blog
*.dashandpinch.blog
*.insight.dashandpinch.blog
*.sandbox.dashandpinch.blog
*.ww25.dashandpinch.blog
*.ww38.dashandpinch.blog
elsaqueocatalan.com
*.elsaqueocatalan.com
*.dc-c7b761be0407.funny.wiki
funny.wiki
*.funny.wiki
*.ww38.funny.wiki
ghostbrackets.com
*.ghostbrackets.com
*.potaufeu.ghostbrackets.com
*.secure.ghostbrackets.com
*.web.ghostbrackets.com
gothambet.vip
*.gothambet.vip
*.www.gothambet.vip
gxb.au
*.gxb.au
hyperflux.biz
*.hyperflux.biz
ikanmh.com
*.ikanmh.com
*.m.ikanmh.com
*.random.ikanmh.com
*.ww38.ikanmh.com
infrepos.com
*.infrepos.com
jova.studio
*.jova.studio
lightwatervalley.com
*.lightwatervalley.com
*.planday.lightwatervalley.com
*.ww16.lightwatervalley.com
*.ww38.lightwatervalley.com
manmdirect.de
*.manmdirect.de
milkbaragency.com.au
*.milkbaragency.com.au
ministrysofmusic.com
*.ministrysofmusic.com
mleeads.com
*.mleeads.com
moonwilly.com
*.moonwilly.com
*.ns2.moonwilly.com
*.swap.moonwilly.com
*.ww38.moonwilly.com
myfake.info
*.myfake.info
ripsteam.com
*.ripsteam.com
*.ww25.ripsteam.com
*.cbrpgjx.semkrush.com
*.random.semkrush.com
semkrush.com
*.semkrush.com
sova.au
*.sova.au
*.mx.tdcj.org
tdcj.org
*.tdcj.org
*.ww35.tdcj.org
*.ns4.tmhi.info
tmhi.info
*.tmhi.info
tomansjerry.com
*.tomansjerry.com
turneraudio.au
*.turneraudio.au
valimarketing.com
*.valimarketing.com
*.es.wikibuy.store
wikibuy.store
*.wikibuy.store
wikimatome.com
*.wikimatome.com
*.mx.wisdomoftheherbsschool.com
*.open.wisdomoftheherbsschool.com
wisdomoftheherbsschool.com
*.wisdomoftheherbsschool.com
Other domains in certificate