76/100 SECURITY SCORE

Certificate Information

Subject
CN=amb126.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 09, 2026
Valid Until
May 10, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:BB:D6:E3:62:87:F5:B7:E3:4D:E3:B4:AD:9F:16:58:A6:F2:3E:EF:46:8A:11:D6:B6:A5:BA:93:C1:5E:D5:EE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bednarczuk.com *.bednarczuk.com *.access.bednarczuk.com *.aceckapi.bednarczuk.com *.admin.bednarczuk.com *.app.bednarczuk.com *.assets.bednarczuk.com *.demo.bednarczuk.com *.dev.bednarczuk.com *.gateway.bednarczuk.com *.hostmaster.bednarczuk.com *.landings.bednarczuk.com *.m.bednarczuk.com *.mail.bednarczuk.com *.mailout.bednarczuk.com *.rdp.bednarczuk.com *.rdweb.bednarczuk.com *.remote.bednarczuk.com *.sitemap.bednarczuk.com *.vpn.bednarczuk.com *.ww16.bednarczuk.com *.ww17.bednarczuk.com *.ww25.bednarczuk.com *.ww38.bednarczuk.com

Other domains in certificate

000186gg.xyz *.000186gg.xyz *.w9iw.000186gg.xyz
alret.com *.alret.com *.emv1.alret.com *.freejob.alret.com *.jobs.alret.com *.m.alret.com *.mvideo.alret.com *.sitemap.alret.com *.sitemaps.alret.com *.ww38.alret.com *.wwwfreejob.alret.com
amb126.com *.amb126.com *.sitemap.amb126.com *.sitemaps.amb126.com
*.api.artstorecafe.com *.app.artstorecafe.com artstorecafe.com *.artstorecafe.com *.backup.artstorecafe.com *.beta.artstorecafe.com *.dashboard.artstorecafe.com *.demo.artstorecafe.com *.dev.artstorecafe.com *.m.artstorecafe.com *.mail.artstorecafe.com *.mailer.artstorecafe.com *.marketing.artstorecafe.com *.members.artstorecafe.com *.qa.artstorecafe.com *.secure.artstorecafe.com *.sitemap.artstorecafe.com *.staging.artstorecafe.com *.test.artstorecafe.com *.uat.artstorecafe.com *.v1.artstorecafe.com *.web.artstorecafe.com *.ww1.artstorecafe.com *.ww16.artstorecafe.com *.ww17.artstorecafe.com
erfolg-beginnt-im-kopf.com *.erfolg-beginnt-im-kopf.com *.notexistsipv6.erfolg-beginnt-im-kopf.com
info-nexus.xyz *.info-nexus.xyz *.kwid9.info-nexus.xyz *.wsct4.info-nexus.xyz *.xjytdb5hyr.info-nexus.xyz
*.backup.moigovqa.com moigovqa.com *.moigovqa.com *.qwnjrf.moigovqa.com *.ww38.moigovqa.com
*.ftp.servixai.com *.itnzhrdweb.servixai.com *.localhost.servixai.com *.members.servixai.com *.rds.servixai.com servixai.com *.servixai.com
*.go.tryaaro.com tryaaro.com *.tryaaro.com