Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=gzxlsj.cn
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026 86 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AB:A6:B8:64:F5:3D:92:2B:4D:B4:B1:83:01:DC:59:01:1A:D7:ED:59:22:A4:29:6E:50:D9:6C:13:48:B2:13:B6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
cofounder.ca *.cofounder.ca *.admin.cofounder.ca *.api.cofounder.ca *.m.cofounder.ca *.staging.cofounder.ca

Other domains in certificate

cocoyoungphotography.com *.cocoyoungphotography.com
coinbaseescrow.tech *.coinbaseescrow.tech *.test.coinbaseescrow.tech *.www.coinbaseescrow.tech
ekhtybg208.vip *.ekhtybg208.vip
*.cabinet.firstchoiceflooring.us firstchoiceflooring.us *.firstchoiceflooring.us *.m.firstchoiceflooring.us *.sitemap.firstchoiceflooring.us *.wildcard.firstchoiceflooring.us *.ww38.firstchoiceflooring.us
gocoldemailnow.com *.gocoldemailnow.com
*.gqihg3.gray-mesa.com gray-mesa.com *.gray-mesa.com
*.bio.gzxlsj.cn gzxlsj.cn *.gzxlsj.cn *.kr.gzxlsj.cn *.org.gzxlsj.cn *.rg.gzxlsj.cn *.yule.gzxlsj.cn
*.cloud.highlyrecommendthis.com *.fachhandel.highlyrecommendthis.com highlyrecommendthis.com *.highlyrecommendthis.com *.rds.highlyrecommendthis.com *.rdweb.highlyrecommendthis.com
*.autodiscover.jxdriver.cn *.bs.jxdriver.cn *.fx.jxdriver.cn jxdriver.cn *.jxdriver.cn
lode88vn.pro *.lode88vn.pro
*.api.myrgccsid.org *.backend.myrgccsid.org myrgccsid.org *.myrgccsid.org *.test.myrgccsid.org *.testing.myrgccsid.org *.ww1.myrgccsid.org
*.gmail.nftath.com *.help.nftath.com *.m.nftath.com nftath.com *.nftath.com *.random.nftath.com *.rd.nftath.com *.rds.nftath.com *.www.nftath.com
*.a.saltstoneearth.info *.app.saltstoneearth.info *.ikc9u7.saltstoneearth.info saltstoneearth.info *.saltstoneearth.info *.server.saltstoneearth.info
*.access.woodmanhill.com *.cisapp.woodmanhill.com *.gp.woodmanhill.com *.rdweb.woodmanhill.com *.secure.woodmanhill.com *.secureaccess.woodmanhill.com *.webvpn.woodmanhill.com woodmanhill.com *.woodmanhill.com
*.backup.xn--ngbv2w.com *.dev.xn--ngbv2w.com *.localhost.xn--ngbv2w.com *.m.xn--ngbv2w.com *.mail.xn--ngbv2w.com *.test.xn--ngbv2w.com *.testing.xn--ngbv2w.com *.vpn.xn--ngbv2w.com *.ww12.xn--ngbv2w.com *.www.xn--ngbv2w.com xn--ngbv2w.com *.xn--ngbv2w.com