76/100 SECURITY SCORE

Certificate Information

Subject
CN=fifearmsbraemar.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
November 26, 2025
Valid Until
February 24, 2026 52 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:C4:25:9C:56:84:1F:34:37:EF:1C:7C:0D:45:C4:E8:C1:CF:DF:3C:7F:97:C8:AC:1F:76:90:AC:8C:C8:A7:D6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

79 domains
cloudflareinsights.co *.cloudflareinsights.co *.static.cloudflareinsights.co

Other domains in certificate

allegratintas.com *.allegratintas.com
basics4mac.com *.basics4mac.com *.sitemap.basics4mac.com
cadetships.com.au *.cadetships.com.au
cigarempire.store *.cigarempire.store *.pop.cigarempire.store
daskey4.store *.daskey4.store *.random.daskey4.store *.visualizations.daskey4.store
dctcasino.club *.dctcasino.club *.mail.dctcasino.club *.ww25.dctcasino.club *.www.dctcasino.club
fifearmsbraemar.com *.fifearmsbraemar.com *.www.fifearmsbraemar.com
fincraftwealthnavigator.com *.fincraftwealthnavigator.com *.ww25.fincraftwealthnavigator.com
*.bftnr.gribbersmaller.online *.bgolm.gribbersmaller.online *.ckjoawcc.gribbersmaller.online *.dfahxd.gribbersmaller.online *.dnhpj.gribbersmaller.online *.epuubiup.gribbersmaller.online *.fmdkvwzm.gribbersmaller.online *.gpacoxmou.gribbersmaller.online gribbersmaller.online *.gribbersmaller.online *.grouqdjzh.gribbersmaller.online *.gscjvre.gribbersmaller.online *.hdwpi.gribbersmaller.online *.ljgoorfsz.gribbersmaller.online *.ljhgi.gribbersmaller.online *.mwpdnsnyag.gribbersmaller.online *.ncbptqnoh.gribbersmaller.online *.opfqnq.gribbersmaller.online *.otelnj.gribbersmaller.online *.oyisort.gribbersmaller.online *.ozazmjl.gribbersmaller.online *.sdxgvbcnb.gribbersmaller.online *.sfzymvhaea.gribbersmaller.online *.sgxupg.gribbersmaller.online *.svwetimhmr.gribbersmaller.online *.tkzlah.gribbersmaller.online *.ubxqdt.gribbersmaller.online *.udbjj.gribbersmaller.online *.urrsd.gribbersmaller.online *.usukkgdmxw.gribbersmaller.online *.vlvhkkeo.gribbersmaller.online *.ygiferk.gribbersmaller.online
guatl3.com *.guatl3.com *.ww25.guatl3.com
hospitalcare.xyz *.hospitalcare.xyz
librosonline4.com *.librosonline4.com
onlyplants.store *.onlyplants.store *.ww25.onlyplants.store
sextop01.org *.sextop01.org *.testing.sextop01.org
susunabati-david24.click *.susunabati-david24.click *.www.susunabati-david24.click
*.f.westbrook.club westbrook.club *.westbrook.club