Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=520529.vip
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 07, 2026
Valid Until
June 05, 2026
54 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6E:6D:87:01:9B:E4:5B:FC:B4:1F:09:32:F2:10:8E:88:E9:C7:53:46:90:E6:C8:4E:80:FB:74:2C:CC:33:AF:08
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
cqszx.com.cn
*.cqszx.com.cn
*.yyd9f3.cqszx.com.cn
30876.net
*.30876.net
319913.app
*.319913.app
35892.ceo
*.35892.ceo
35below.shop
*.35below.shop
3cc9.com
*.3cc9.com
3uy5.top
*.3uy5.top
40921.locker
*.40921.locker
41gr.top
*.41gr.top
50382.locker
*.50382.locker
5151hu.cn
*.5151hu.cn
51658.locker
*.51658.locker
51cg91.xyz
*.51cg91.xyz
51cgfun.top
*.51cgfun.top
51cgz1.xyz
*.51cgz1.xyz
520529.vip
*.520529.vip
522248.vip
*.522248.vip
53553.locker
*.53553.locker
538038.vip
*.538038.vip
538275.mobi
*.538275.mobi
54q4.com
*.54q4.com
552654.vip
*.552654.vip
553190.club
*.553190.club
55895.locker
*.55895.locker
56125.shop
*.56125.shop
56948.locker
*.56948.locker
569821.bid
*.569821.bid
57259.locker
*.57259.locker
57357.loan
*.57357.loan
579609.top
*.579609.top
58287.locker
*.58287.locker
58ms.cc
*.58ms.cc
58s8.cc
*.58s8.cc
59348.ceo
*.59348.ceo
5j7nr1.top
*.5j7nr1.top
60407.loan
*.60407.loan
cyabkz.net
*.cyabkz.net
*.members.cyabkz.net
gardeninguniversezone.live
*.gardeninguniversezone.live
*.upload.gardeninguniversezone.live
koicuan88.monster
*.koicuan88.monster
large-desiccant-107786102.click
*.large-desiccant-107786102.click
littlegardeningmiracles.live
*.littlegardeningmiracles.live
maxcartx.shop
*.maxcartx.shop
metaadv.click
*.metaadv.click
*.violate.metaadv.click
Other domains in certificate