Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=239786.cc
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 18, 2026
Valid Until
August 16, 2026
66 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
68:D9:74:04:75:98:D8:6D:42:20:A1:15:62:36:08:22:6E:F4:D8:15:1C:39:31:E4:5C:BC:11:21:4C:6B:B9:F8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ctsy2.digital
*.ctsy2.digital
016168x.cc
*.016168x.cc
1clicklistbuilder.com
*.1clicklistbuilder.com
1fmeuf.xyz
*.1fmeuf.xyz
239786.cc
*.239786.cc
25se.com
*.25se.com
494z.cc
*.494z.cc
52942.vip
*.52942.vip
5569297.xyz
*.5569297.xyz
5ga.io
*.5ga.io
63731.win
*.63731.win
73882m.co
*.73882m.co
757928.xyz
*.757928.xyz
775392.cn
*.775392.cn
839643.xyz
*.839643.xyz
843a38.app
*.843a38.app
864675.xyz
*.864675.xyz
901589.xyz
*.901589.xyz
981673.xyz
*.981673.xyz
99re5.cn
*.99re5.cn
afroporia.com
*.afroporia.com
agenjudi.loan
*.agenjudi.loan
am113.vip
*.am113.vip
amhb77.cc
*.amhb77.cc
amorepastaco.com
*.amorepastaco.com
arifmarket.com
*.arifmarket.com
atlsyscu.click
*.atlsyscu.click
b3idro.top
*.b3idro.top
baikanpingtai.cn
*.baikanpingtai.cn
best-safe-app.click
*.best-safe-app.click
bizsign.io
*.bizsign.io
c28j2ebgp.world
*.c28j2ebgp.world
cavaazul.com
*.cavaazul.com
gettingridofpimples.com
*.gettingridofpimples.com
globaiinvestmentshop.com
*.globaiinvestmentshop.com
globalwakaf.com
*.globalwakaf.com
helpefxforms.us
*.helpefxforms.us
homedaycaremassapequa.com
*.homedaycaremassapequa.com
ilaxd.sbs
*.ilaxd.sbs
indbingo2.in
*.indbingo2.in
juryclackcountycourts.us
*.juryclackcountycourts.us
karmania.org
*.karmania.org
kulinariya.pw
*.kulinariya.pw
leo88.legal
*.leo88.legal
mokateafamilybusiness.com
*.mokateafamilybusiness.com
Other domains in certificate