Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=bofillservices.online
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 20, 2026
Valid Until
April 20, 2026
55 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A5:D0:1B:40:E5:2F:6B:8F:CF:CC:02:37:7E:87:7D:AB:2D:AA:24:71:57:0E:FB:1C:14:31:67:01:94:0B:3D:94
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
cleverpet.com
*.cleverpet.com
457hh.com
*.457hh.com
*.ww25.457hh.com
airadar.online
*.airadar.online
arz-cleveland.site
*.arz-cleveland.site
*.forum.arz-cleveland.site
*.fp4hqitpin.arz-cleveland.site
*.yahoo.arz-cleveland.site
astra.law
*.astra.law
*.component.astra.law
*.ww38.astra.law
bma01.xyz
*.bma01.xyz
*.ww25.bma01.xyz
bnw.life
*.bnw.life
*.gov.bnw.life
bofillservices.online
*.bofillservices.online
*.ww25.bofillservices.online
boma.life
*.boma.life
*.com.boma.life
*.gov.boma.life
brucej.com
*.brucej.com
*.mail.brucej.com
*.random.brucej.com
*.ww33.brucej.com
conte.studio
*.conte.studio
*.com.deli.life
deli.life
*.deli.life
*.gov.deli.life
*.api.heatpumpsprices02.online
*.gzpfxm.heatpumpsprices02.online
heatpumpsprices02.online
*.heatpumpsprices02.online
*.m.heatpumpsprices02.online
*.random.heatpumpsprices02.online
*.www.heatpumpsprices02.online
hilltopmd.com
*.hilltopmd.com
*.remote.hilltopmd.com
*.h7hm5herxkf3bupy.lucidspark.online
lucidspark.online
*.lucidspark.online
*.random.lucidspark.online
*.ww25.lucidspark.online
*.blog.makerun.io
makerun.io
*.makerun.io
minerltc.com
*.minerltc.com
*.ww25.minerltc.com
myfreshapps.net
*.myfreshapps.net
omnimedicalcare.com
*.omnimedicalcare.com
*.random.omnimedicalcare.com
*.ww38.omnimedicalcare.com
*.pagamento.pedeacai.site
pedeacai.site
*.pedeacai.site
powerpunchshop.store
*.powerpunchshop.store
*.ww38.powerpunchshop.store
retro.net.au
*.retro.net.au
sasis.cc
*.sasis.cc
*.random.trongs.co.uk
trongs.co.uk
*.trongs.co.uk
*.hostmaster.unifor.online
*.magento.unifor.online
*.random.unifor.online
*.st.unifor.online
*.staging.unifor.online
*.test.unifor.online
unifor.online
*.unifor.online
*.ww38.unifor.online
Other domains in certificate