Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=mobtakeranmashhad.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 06, 2026
Valid Until
August 04, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:0B:90:1D:61:DF:1E:37:2A:74:2A:FA:21:47:5E:15:2F:D7:04:3A:0E:4B:46:E3:14:38:5C:1C:A4:F9:44:37
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
d000h.com
*.d000h.com
*.ww38.d000h.com
77mh.app
*.77mh.app
*.i.77mh.app
*.ww17.77mh.app
alexwerner.pro
*.alexwerner.pro
*.forum.alexwerner.pro
*.games.alexwerner.pro
*.music.alexwerner.pro
*.neo.alexwerner.pro
*.rovision.alexwerner.pro
auraaccesorios.shop
*.auraaccesorios.shop
betkom169.com
*.betkom169.com
cpe.co.uk
*.cpe.co.uk
*.remote.cpe.co.uk
gaydorm.us
*.gaydorm.us
*.km.gaydorm.us
*.mail.gaydorm.us
*.nas1.gaydorm.us
*.serverhosting238.gaydorm.us
*.ww25.gaydorm.us
*.www.gaydorm.us
gondavalekarmaharaj.online
*.gondavalekarmaharaj.online
gozumyagmurlara.online
*.gozumyagmurlara.online
*.ww25.gozumyagmurlara.online
*.forum.grandbonus.online
grandbonus.online
*.grandbonus.online
iatradesignalsx.online
*.iatradesignalsx.online
*.3ig1k7.main188-1000.site
*.autoconfig.main188-1000.site
*.m.main188-1000.site
*.mail.main188-1000.site
main188-1000.site
*.main188-1000.site
*.webmail.main188-1000.site
*.www.main188-1000.site
*.admin.mobtakeranmashhad.com
*.api.mobtakeranmashhad.com
*.beta.mobtakeranmashhad.com
mobtakeranmashhad.com
*.mobtakeranmashhad.com
*.student.mobtakeranmashhad.com
mollyzelvon.com
*.mollyzelvon.com
*.online.mollyzelvon.com
*.solutions.mollyzelvon.com
*.50b4c48.musictap.site
*.cf25.musictap.site
musictap.site
*.musictap.site
*.cpanel.nccym.info
*.mail.nccym.info
nccym.info
*.nccym.info
*.ns2.nccym.info
*.www.nccym.info
obol.website
*.obol.website
onlineflix.me
*.onlineflix.me
*.ww38.onlineflix.me
*.0m3xm.royal77vip.com
*.4tcev.royal77vip.com
*.dwd24.royal77vip.com
royal77vip.com
*.royal77vip.com
*.wczgw.royal77vip.com
*.xq4bl.royal77vip.com
segodnja-ne-rabotaet.store
*.segodnja-ne-rabotaet.store
terica.online
*.terica.online
troop464.us
*.troop464.us
vendredi13.store
*.vendredi13.store
xilueo.com
*.xilueo.com
Other domains in certificate