76/100 SECURITY SCORE

Certificate Information

Subject
CN=cloudlandshop.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 22, 2026
Valid Until
April 22, 2026 67 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F3:87:E4:53:49:BE:8F:D9:FE:C7:C5:A4:CC:2E:F6:D6:F5:30:21:06:08:F1:44:73:0E:25:8F:6F:94:55:01:AB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
aireddit.com *.aireddit.com *.7minute.aireddit.com *.character.aireddit.com *.comd2l.aireddit.com *.i10x.aireddit.com *.jina.aireddit.com *.justthink.aireddit.com *.kubiya.aireddit.com *.leonardo.aireddit.com *.musicful.aireddit.com *.skywork.aireddit.com *.vidthis.aireddit.com *.zaka.aireddit.com

Other domains in certificate

allianzetravelinsurance.com *.allianzetravelinsurance.com *.dev.allianzetravelinsurance.com *.veysvpublic.allianzetravelinsurance.com
arvestfinancialcu.com *.arvestfinancialcu.com *.my.arvestfinancialcu.com *.us.arvestfinancialcu.com
bb07f93967bcf158.xyz *.bb07f93967bcf158.xyz *.random.bb07f93967bcf158.xyz *.ww25.bb07f93967bcf158.xyz *.ww38.bb07f93967bcf158.xyz
*.blog.cambridgeportfolio.com.au cambridgeportfolio.com.au *.cambridgeportfolio.com.au *.dev.cambridgeportfolio.com.au *.ww25.cambridgeportfolio.com.au *.ww38.cambridgeportfolio.com.au
*.account.cloudlandshop.com cloudlandshop.com *.cloudlandshop.com *.ww17.cloudlandshop.com
foodnrtwork.com *.foodnrtwork.com
*.cpanel.gay2g.com *.cpcontacts.gay2g.com gay2g.com *.gay2g.com *.webdisk.gay2g.com *.whm.gay2g.com *.ww.gay2g.com *.www.gay2g.com
hanime4.me *.hanime4.me *.mebwwww.hanime4.me *.ww17.hanime4.me *.wwv.hanime4.me
imagefapp.com *.imagefapp.com
jukuzyoporn555.com *.jukuzyoporn555.com
lasercuttingwelding499960.icu *.lasercuttingwelding499960.icu
macosweb.online *.macosweb.online *.ww38.macosweb.online
montaguesrestaurant.com *.montaguesrestaurant.com *.random.montaguesrestaurant.com *.ww25.montaguesrestaurant.com
sbones.com *.sbones.com *.ww38.sbones.com
tgodaddy.com *.tgodaddy.com *.ww16.tgodaddy.com
theoneoakcandleco.com.au *.theoneoakcandleco.com.au *.ww16.theoneoakcandleco.com.au
tuktukcinema.vip *.tuktukcinema.vip *.ww16.tuktukcinema.vip *.ww25.tuktukcinema.vip
*.demo.visa-nadra.com visa-nadra.com *.visa-nadra.com *.ww38.visa-nadra.com
*.test.westsidepetroleum.com.au westsidepetroleum.com.au *.westsidepetroleum.com.au *.ww16.westsidepetroleum.com.au *.ww17.westsidepetroleum.com.au *.ww25.westsidepetroleum.com.au *.ww38.westsidepetroleum.com.au