Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=kgvthiemannshof.de
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 30, 2026
Valid Until
April 30, 2026
76 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DF:CB:E6:4E:C1:1F:4F:0F:75:14:FF:B1:47:B5:C7:D0:C8:21:A9:26:B3:B0:C8:A4:AB:9B:7A:C0:0C:77:AE:6E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
cuntpost.com
*.cuntpost.com
17696.top
*.17696.top
18221.loan
*.18221.loan
195268.loan
*.195268.loan
19605.loan
*.19605.loan
1sd8hni.net
*.1sd8hni.net
23103.pizza
*.23103.pizza
238216.top
*.238216.top
246536.loan
*.246536.loan
25416.loan
*.25416.loan
256213.loan
*.256213.loan
27652.one
*.27652.one
28516.locker
*.28516.locker
33728.locker
*.33728.locker
53584.mobi
*.53584.mobi
71908.loan
*.71908.loan
74250.loan
*.74250.loan
922659.vip
*.922659.vip
aleriadesigns.com
*.aleriadesigns.com
atsservicesgroup.com
*.atsservicesgroup.com
bloomingpathwaysonline.live
*.bloomingpathwaysonline.live
bmhcm.com
*.bmhcm.com
coffee-m.info
*.coffee-m.info
*.ap2y4.duerckglthk93fow8lnk.top
*.ap5ee.duerckglthk93fow8lnk.top
duerckglthk93fow8lnk.top
*.duerckglthk93fow8lnk.top
*.gansf.duerckglthk93fow8lnk.top
*.gxkk7.duerckglthk93fow8lnk.top
*.q836v.duerckglthk93fow8lnk.top
*.tz7et.duerckglthk93fow8lnk.top
*.wdxmx.duerckglthk93fow8lnk.top
*.x7g6h.duerckglthk93fow8lnk.top
dyorexchange.com
*.dyorexchange.com
*.can.easily.work
easily.work
*.easily.work
*.v.easily.work
hairouna.com
*.hairouna.com
kgvthiemannshof.de
*.kgvthiemannshof.de
*.mail.kgvthiemannshof.de
manwafz.com
*.manwafz.com
*.app.manyimags.com
*.hostmaster.manyimags.com
manyimags.com
*.manyimags.com
*.uat.manyimags.com
midasswap.com
*.midasswap.com
patriley.com
*.patriley.com
pelhammanor.com
*.pelhammanor.com
*.explorer.read.academy
*.hotfix.read.academy
*.insight.read.academy
*.insights.read.academy
*.monitoring.read.academy
*.qa.read.academy
read.academy
*.read.academy
*.report.read.academy
*.superset.read.academy
Other domains in certificate