Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=imaginewellc.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 29, 2026
Valid Until
August 27, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
34:0F:95:AF:67:48:1A:4D:CE:65:16:11:80:6A:3D:E5:F0:2F:69:52:D0:57:68:7F:C2:D5:45:6E:14:1B:E8:39
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
mechi.com *.mechi.com *.alba.mechi.com *.amo.mechi.com *.att.mechi.com *.autodiscover.mechi.com *.beta.mechi.com *.crm.mechi.com *.sitemap.mechi.com *.ww11.mechi.com *.ww16.mechi.com

Other domains in certificate

*.app.authenticate.bot authenticate.bot *.authenticate.bot *.demo.authenticate.bot *.dev.authenticate.bot *.mdipjacc.authenticate.bot *.mvsnquat.authenticate.bot *.test.authenticate.bot *.v2.authenticate.bot
*.autodiscover.cambopop.com cambopop.com *.cambopop.com *.test.cambopop.com
d019quiz0205s.sbs *.d019quiz0205s.sbs
*.bookstore.imaginewellc.com *.bos89.imaginewellc.com *.colok-138.imaginewellc.com *.ebank.imaginewellc.com *.erek2-89.imaginewellc.com *.harmoni-kewajiban-dan-hak.imaginewellc.com imaginewellc.com *.imaginewellc.com *.jingga-888.imaginewellc.com *.ori777.imaginewellc.com *.rojh.imaginewellc.com *.shiokuda2-login.imaginewellc.com *.slot-200-login.imaginewellc.com
*.desktop.mainaves.com *.dev.mainaves.com mainaves.com *.mainaves.com *.monitoring.mainaves.com *.vdi.mainaves.com *.webvpn.mainaves.com
ment-ticketmaster.online *.ment-ticketmaster.online *.qgnh17.ment-ticketmaster.online *.www.ment-ticketmaster.online
project-haven.xyz *.project-haven.xyz *.rammerhead.project-haven.xyz *.web.project-haven.xyz
*.atwvqfyc.seffishing.shop *.dashboard.seffishing.shop *.dev.seffishing.shop *.ekb.seffishing.shop *.m.seffishing.shop *.mail.seffishing.shop *.marketing.seffishing.shop *.mcgakstg.seffishing.shop *.pay.seffishing.shop *.rustore.seffishing.shop *.s9q6hl.seffishing.shop *.secure.seffishing.shop seffishing.shop *.seffishing.shop *.shop.seffishing.shop *.staging.seffishing.shop *.stg.seffishing.shop *.test.seffishing.shop *.web.seffishing.shop *.www.seffishing.shop
*.access.syaze.com *.admin.syaze.com *.apps.syaze.com *.dev.syaze.com *.gateway.syaze.com *.m.syaze.com *.mail.syaze.com syaze.com *.syaze.com *.test.syaze.com *.ts.syaze.com *.vpn.syaze.com
vizebet566.com *.vizebet566.com
weddingsoar.beauty *.weddingsoar.beauty