Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=espd7.us
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 08, 2026
Valid Until
May 09, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6F:31:4A:9D:1F:E8:A8:5D:1D:7C:8D:39:11:FB:3E:AA:27:C8:EB:CB:CC:F6:18:8B:79:6E:FD:89:52:14:EF:28
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
whaspp.com
*.whaspp.com
*.support.whaspp.com
*.web.whaspp.com
777trvaegean.com
*.777trvaegean.com
*.api.astrovastu.com
*.app-test.astrovastu.com
astrovastu.com
*.astrovastu.com
*.dev.astrovastu.com
*.hostmaster.astrovastu.com
*.test.astrovastu.com
*.ww17.astrovastu.com
clisat.com
*.clisat.com
*.cpcalendars.donnait.com
*.cpcontacts.donnait.com
donnait.com
*.donnait.com
*.random.donnait.com
espd7.us
*.espd7.us
hzs.com.au
*.hzs.com.au
*.mail.hzs.com.au
*.scrm.hzs.com.au
*.shadow.hzs.com.au
*.tlk.hzs.com.au
*.tumour.hzs.com.au
*.cadastro.listastings.com
*.cloud.listastings.com
*.demo.listastings.com
*.dev.listastings.com
*.fgaopapi.listastings.com
*.files.listastings.com
listastings.com
*.listastings.com
*.mail.listastings.com
*.new.listastings.com
*.public.listastings.com
*.rd.listastings.com
*.rds.listastings.com
*.sgffordweb.listastings.com
*.staging.listastings.com
*.test.listastings.com
*.uat.listastings.com
*.webmail.listastings.com
listingfix.com
*.listingfix.com
mutaldirect.com
*.mutaldirect.com
*.ww38.mutaldirect.com
*.n.neri.es
neri.es
*.neri.es
newsonair.in
*.newsonair.in
*.0www.rankyou.com
*.random.rankyou.com
rankyou.com
*.rankyou.com
*.ws.rankyou.com
*.wss.rankyou.com
*.campanha.redcarpetmuseum.com
*.mobile1.redcarpetmuseum.com
*.rdg.redcarpetmuseum.com
redcarpetmuseum.com
*.redcarpetmuseum.com
*.sitemaps.redcarpetmuseum.com
saeter.com
*.saeter.com
scottezpay.com
*.scottezpay.com
*.ww25.scottezpay.com
*.ww38.scottezpay.com
tinyzonetc.cc
*.tinyzonetc.cc
*.th.uwk.au
uwk.au
*.uwk.au
welcomefinance.com
*.welcomefinance.com
*.hostmaster.xn--grouon-6ya.de
xn--grouon-6ya.de
*.xn--grouon-6ya.de
*.hostmaster.yfs.in
yfs.in
*.yfs.in
Other domains in certificate