Open
Cached
·
just now
79/100
SECURITY SCORE
Certificate Information
Subject
CN=cinnrs.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 30, 2026
Valid Until
April 30, 2026
80 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
24:63:17:4A:84:FA:B6:CC:72:A3:8A:A8:24:83:5A:68:BB:4C:DB:9C:D8:6D:0F:F0:7E:D9:B6:E9:3F:23:D1:68
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
dabmediaventures.com
*.dabmediaventures.com
*.www.dabmediaventures.com
cinnr.com
*.cinnr.com
*.www.cinnr.com
cinnr.org
*.cinnr.org
*.www.cinnr.org
cinnrs.com
*.cinnrs.com
*.www.cinnrs.com
cinnrs.org
*.cinnrs.org
*.www.cinnrs.org
ejw7z9pq.top
*.ejw7z9pq.top
*.rczhl.ejw7z9pq.top
gooseantlerz.com
*.gooseantlerz.com
*.staging.gooseantlerz.com
methodswap.com
*.methodswap.com
mg5d5y3.top
*.mg5d5y3.top
ninamiss.com
*.ninamiss.com
nvzhoqh378.vip
*.nvzhoqh378.vip
oyqmw6pm.top
*.oyqmw6pm.top
p67001o.cyou
*.p67001o.cyou
qo12kpz7.top
*.qo12kpz7.top
qvwbgcu1674.vip
*.qvwbgcu1674.vip
rationalmachine.com
*.rationalmachine.com
realmississauga.com
*.realmississauga.com
rossiter.consulting
*.rossiter.consulting
schrift-generator.info
*.schrift-generator.info
seriesorg.com
*.seriesorg.com
sg108.me
*.sg108.me
signum.world
*.signum.world
*.staging.signum.world
sneakernews23.net
*.sneakernews23.net
snowthaproducttour.com
*.snowthaproducttour.com
stakedify.com
*.stakedify.com
system-ceramics.cn
*.system-ceramics.cn
tdx.ventures
*.tdx.ventures
theforcebelief.com
*.theforcebelief.com
theomgbrand.com
*.theomgbrand.com
thequantizedquark.com
*.thequantizedquark.com
top10hacker.com
*.top10hacker.com
untitledcoin.com
*.untitledcoin.com
virtusplaypro.com
*.virtusplaypro.com
vocalcoachingonline.com
*.vocalcoachingonline.com
wellnessswap.com
*.wellnessswap.com
wn3z4g7.top
*.wn3z4g7.top
*.staging.xq9x1g1.top
xq9x1g1.top
*.xq9x1g1.top
ym8x8x4.top
*.ym8x8x4.top
ywolf.com
*.ywolf.com
z97oq2jk.top
*.z97oq2jk.top
Other domains in certificate