76/100 SECURITY SCORE

Certificate Information

Subject
CN=mitsubishi-truongchinh3s.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 09, 2026
Valid Until
April 09, 2026 46 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DB:58:8E:28:92:43:86:CE:80:1B:12:B2:BD:76:38:62:2F:AF:B7:A8:3C:32:C1:A8:72:51:B5:98:05:21:EB:4F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
darksoul.com *.darksoul.com *.demand.darksoul.com *.hello.darksoul.com

Other domains in certificate

ausprotectionkeychains.store *.ausprotectionkeychains.store
basebear.pro *.basebear.pro
chestertoncc.org *.chestertoncc.org *.chestertonsportscentrecom.chestertoncc.org *.chestertonsportscentrecouk.chestertoncc.org *.csc.chestertoncc.org *.theblaze.chestertoncc.org *.ww38.chestertoncc.org
dillinghamdps.us *.dillinghamdps.us *.posta.dillinghamdps.us
fansta.me *.fansta.me *.ww25.fansta.me
hpmbi.com *.hpmbi.com *.test.hpmbi.com
itcoin.tv *.itcoin.tv *.sitemaps.itcoin.tv
jpmrganchase.com *.jpmrganchase.com *.random.jpmrganchase.com
mitsubishi-truongchinh3s.com *.mitsubishi-truongchinh3s.com
mutation.live *.mutation.live
naicha14110.sbs *.naicha14110.sbs
pleisplus.me *.pleisplus.me
roket.studio *.roket.studio
seevii.com *.seevii.com *.www.seevii.com
*.cpanel.sharesrc.pro *.mail.sharesrc.pro sharesrc.pro *.sharesrc.pro
tapless.io *.tapless.io *.ww38.tapless.io
*.63o0fqw91wwmekcd.teh-vip-shop.site *.d2btgtpvjk5s739p4m5g.teh-vip-shop.site *.random.teh-vip-shop.site *.reporting.teh-vip-shop.site teh-vip-shop.site *.teh-vip-shop.site *.ww.teh-vip-shop.site *.ww38.teh-vip-shop.site
tetka.com.au *.tetka.com.au
*.220-server2.tvseriale.com *.dc-f0300aef3e3a.tvseriale.com *.fembed.tvseriale.com *.flow.tvseriale.com *.flowise.tvseriale.com *.hostmaster.tvseriale.com *.kvq.tvseriale.com *.mail.tvseriale.com *.ns1.tvseriale.com *.ns2.tvseriale.com *.server.tvseriale.com *.server1.tvseriale.com *.server2.tvseriale.com tvseriale.com *.tvseriale.com *.ww38.tvseriale.com *.www.tvseriale.com
tyyzxk.com *.tyyzxk.com
unahallgrimsdottir.com *.unahallgrimsdottir.com
*.sitemaps.voomghadmn.com voomghadmn.com *.voomghadmn.com
*.dev.wuyi20.xyz wuyi20.xyz *.wuyi20.xyz *.ww25.wuyi20.xyz *.ww38.wuyi20.xyz