Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=cutifree.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 23, 2026
Valid Until
August 21, 2026
76 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C5:BD:A8:CD:D9:97:20:1F:18:62:3B:D1:04:57:64:E8:1B:B5:4E:3C:7E:77:27:62:27:E9:E2:EC:5B:C7:1A:9A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
87 domains
moldbet.net
*.moldbet.net
*.api.moldbet.net
*.app.moldbet.net
*.assets.moldbet.net
*.backup.moldbet.net
*.dashboard.moldbet.net
*.demo.moldbet.net
*.dev.moldbet.net
*.dht0we.moldbet.net
*.dqughyso.moldbet.net
*.mailer.moldbet.net
*.marketing.moldbet.net
*.qa.moldbet.net
*.secure.moldbet.net
*.stg.moldbet.net
*.test.moldbet.net
*.uat.moldbet.net
*.v2.moldbet.net
*.web.moldbet.net
*.xevakstaging.moldbet.net
*.yakqrqa.moldbet.net
*.z6p8dl.moldbet.net
1146jwm301.top
*.1146jwm301.top
*.188c307a20.1146jwm301.top
*.36fbc63b76.1146jwm301.top
*.49e60c7b06.1146jwm301.top
*.ed22aaa48c.1146jwm301.top
automotrici.com
*.automotrici.com
*.mail2.automotrici.com
cutifree.com
*.cutifree.com
deraamschilders.be
*.deraamschilders.be
dubion.com
*.dubion.com
*.random.dubion.com
*.remote.dubion.com
*.vpn.dubion.com
hard.coach
*.hard.coach
*.17.mddqkcxudh.xyz
mddqkcxudh.xyz
*.mddqkcxudh.xyz
*.api.mechanicsville.net
*.app.mechanicsville.net
*.backup.mechanicsville.net
*.dev.mechanicsville.net
*.m.mechanicsville.net
*.mailbox.mechanicsville.net
mechanicsville.net
*.mechanicsville.net
*.owa.mechanicsville.net
*.qa.mechanicsville.net
*.remote.mechanicsville.net
*.secure.mechanicsville.net
*.sitemap.mechanicsville.net
*.sitemaps.mechanicsville.net
*.smtp.mechanicsville.net
*.staging.mechanicsville.net
*.stg.mechanicsville.net
*.test.mechanicsville.net
*.uat.mechanicsville.net
*.v1.mechanicsville.net
*.v2.mechanicsville.net
*.vpn.mechanicsville.net
*.web.mechanicsville.net
*.www.mechanicsville.net
metaverse.gal
*.metaverse.gal
*.ww16.metaverse.gal
*.hostmaster.parolechiave.it
*.owa.parolechiave.it
parolechiave.it
*.parolechiave.it
*.remote.parolechiave.it
*.webmail.parolechiave.it
studysense.be
*.studysense.be
sunshinecarrental.com
*.sunshinecarrental.com
*.backend.uncastle.com
*.ebay.uncastle.com
uncastle.com
*.uncastle.com
Other domains in certificate