76/100 SECURITY SCORE

Certificate Information

Subject
CN=gasburner.com.au
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 25, 2026
Valid Until
August 23, 2026 63 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EE:16:9B:1A:9C:B8:75:63:74:B2:47:B3:B3:E2:24:D8:FE:95:77:C8:69:C0:67:C8:EF:64:C8:F9:A6:43:76:15
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
groostle.info *.groostle.info *.1002cb4e-ae78-4f69-aed6-1e72329e90aa.groostle.info *.api.groostle.info *.app.groostle.info *.backup.groostle.info *.dev.groostle.info *.mail.groostle.info *.members.groostle.info *.staging.groostle.info *.uat.groostle.info

Other domains in certificate

abritempo.com *.abritempo.com
buybuildinvest.com *.buybuildinvest.com
crosstraining.au *.crosstraining.au
currentaccountsswitch.co.uk *.currentaccountsswitch.co.uk
dimmschalter.de *.dimmschalter.de *.random.dimmschalter.de
garyslafondabaja.com *.garyslafondabaja.com
gasburner.com.au *.gasburner.com.au
impromptu.com.au *.impromptu.com.au
ioa.au *.ioa.au
irsa.au *.irsa.au
klo.eu *.klo.eu
kuba.au *.kuba.au
*.autodiscover.lurry.com lurry.com *.lurry.com *.wiki.lurry.com *.ww16.lurry.com
maddinka.com *.maddinka.com
*.billing.modalhotspot.com *.client.modalhotspot.com modalhotspot.com *.modalhotspot.com *.modalsemangat.modalhotspot.com *.portal.modalhotspot.com *.www.modalhotspot.com
*.admin.oylamm.com oylamm.com *.oylamm.com *.test.oylamm.com
paintwithnumbers.co *.paintwithnumbers.co
paperrate.com *.paperrate.com *.users.paperrate.com *.ww1.paperrate.com *.ww16.paperrate.com *.ww17.paperrate.com *.www.paperrate.com
petsbynumbers.co.nz *.petsbynumbers.co.nz
*.hostmaster.shakumbari.com *.m.shakumbari.com shakumbari.com *.shakumbari.com *.sitemaps.shakumbari.com *.ww25.shakumbari.com
*.6018d057-bde4-4e52-8be7-b6c03f31359f.sublotzsky.com *.baa1c18e-6f91-479f-b753-ea0d054efbad.sublotzsky.com *.core.sublotzsky.com *.moodle.sublotzsky.com *.school.sublotzsky.com sublotzsky.com *.sublotzsky.com *.tst.sublotzsky.com *.vpn.sublotzsky.com *.www.sublotzsky.com
*.random.suitbags.com.au suitbags.com.au *.suitbags.com.au
*.random.swedish.au swedish.au *.swedish.au *.ww38.swedish.au
teaminbox.com.au *.teaminbox.com.au