Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=139640.club
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 10, 2026
Valid Until
July 09, 2026
58 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:CE:0C:75:BB:AD:78:AD:E1:BE:88:97:70:D7:AA:2A:CF:B6:5A:A0:6D:14:EC:30:E2:25:AA:6F:73:44:3B:0C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
cruxdevelopment.com
*.cruxdevelopment.com
139640.club
*.139640.club
249663.club
*.249663.club
46512.town
*.46512.town
51tv250410.top
*.51tv250410.top
56135.town
*.56135.town
56455.town
*.56455.town
64516.town
*.64516.town
aukokioula.com
*.aukokioula.com
castingbay.in
*.castingbay.in
cloudtopcenter.biz
*.cloudtopcenter.biz
clubgame-vip.com
*.clubgame-vip.com
crimsonsteelcobramedia.info
*.crimsonsteelcobramedia.info
datatec.io
*.datatec.io
dental-implants-near-me-2443.click
*.dental-implants-near-me-2443.click
dfh-longisland.com
*.dfh-longisland.com
dmimo.forsale
*.dmimo.forsale
emailingrivlyplatform.co
*.emailingrivlyplatform.co
erectile-dysfunction-37514.click
*.erectile-dysfunction-37514.click
ewmkeodca.com
*.ewmkeodca.com
expeditionbhutan.com
*.expeditionbhutan.com
lwiesqgo.info
*.lwiesqgo.info
mediamaxsolutionsnetwork.co
*.mediamaxsolutionsnetwork.co
mesembryanthemaceae.com
*.mesembryanthemaceae.com
mijasguide.com
*.mijasguide.com
mk510.xyz
*.mk510.xyz
palatograph.com
*.palatograph.com
perfectcoupmpani.com
*.perfectcoupmpani.com
pgritmo.com
*.pgritmo.com
piaoxue9.info
*.piaoxue9.info
piejus.com
*.piejus.com
platform-lifts-usa-1326-1744278235.sbs
*.platform-lifts-usa-1326-1744278235.sbs
playbet247.vip
*.playbet247.vip
pretty-offers-18954.click
*.pretty-offers-18954.click
projectsklientboostservices.co
*.projectsklientboostservices.co
qcvyde.ren
*.qcvyde.ren
qolap.my
*.qolap.my
ragaccess.com
*.ragaccess.com
rbdx46.lat
*.rbdx46.lat
reachinggrowthexpert.co
*.reachinggrowthexpert.co
remotecrewai.com
*.remotecrewai.com
remotecrewtech.com
*.remotecrewtech.com
tvynovelas.cl
*.tvynovelas.cl
www999881.com
*.www999881.com
ydshaot.com
*.ydshaot.com
Other domains in certificate