76/100 SECURITY SCORE

Certificate Information

Subject
CN=00347.locker
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 30, 2026
Valid Until
April 30, 2026 75 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F3:76:DF:78:43:35:E9:33:7E:D8:2F:E0:ED:6A:E6:8A:68:1B:5F:3F:BD:EC:8A:7D:CA:D1:31:29:7E:14:60:5A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
keywest.charity *.keywest.charity *.dev.keywest.charity

Other domains in certificate

00347.locker *.00347.locker
0pf52m9.top *.0pf52m9.top
123milk.com *.123milk.com
14093.locker *.14093.locker
185017.bid *.185017.bid
25084.locker *.25084.locker
254047.com *.254047.com
591846.loan *.591846.loan
65673.cc *.65673.cc
710750.com *.710750.com
805761.club *.805761.club
94279.net *.94279.net
app-services-550964107.click *.app-services-550964107.click
aremjsj400.vip *.aremjsj400.vip
asvgr.academy *.asvgr.academy
baku.cc *.baku.cc
balancenation.com *.balancenation.com
beinghumanfoundation.in *.beinghumanfoundation.in
bookingcelebinfo.com *.bookingcelebinfo.com
bs3ohei.cc *.bs3ohei.cc
cancer-strategies-190360213.click *.cancer-strategies-190360213.click
daycare-companies-us-pablo.click *.daycare-companies-us-pablo.click
drunk-driving-504578896.click *.drunk-driving-504578896.click
epizzas.com *.epizzas.com
esquiremarketing.com *.esquiremarketing.com
*.dev.fb88.camp fb88.camp *.fb88.camp
fckjw2.net *.fckjw2.net
foot-doctor.click *.foot-doctor.click
glenhansardtickets.com *.glenhansardtickets.com
godandbeautiful.com *.godandbeautiful.com
holo.yoga *.holo.yoga
auspins.it.com *.auspins.it.com aussiewinzone.it.com *.aussiewinzone.it.com
jandmpools.com *.jandmpools.com
kayakcoin.com *.kayakcoin.com
*.dev.keywest.reviews keywest.reviews *.keywest.reviews
*.dev.kiemeel.toys kiemeel.toys *.kiemeel.toys
kuvamall.com *.kuvamall.com
legal-services-566609577.click *.legal-services-566609577.click
luxury-villas-291542186.click *.luxury-villas-291542186.click
thenewfujixerox.com *.thenewfujixerox.com
uvf64.top *.uvf64.top