76/100 SECURITY SCORE

Certificate Information

Subject
CN=guaranis.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C1:0A:FB:FC:50:45:39:24:08:30:46:C0:2A:E1:69:06:70:C9:E4:21:48:DB:6C:43:E4:89:2E:E8:EB:98:F7:BE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
nesvrstani.com *.nesvrstani.com *.api.nesvrstani.com *.dev.nesvrstani.com *.mail.nesvrstani.com *.sitemaps.nesvrstani.com *.test.nesvrstani.com *.ww17.nesvrstani.com *.ww25.nesvrstani.com *.ww38.nesvrstani.com *.ww5.nesvrstani.com

Other domains in certificate

broodjeszaak.com *.broodjeszaak.com *.ebay.broodjeszaak.com *.ww16.broodjeszaak.com *.ww25.broodjeszaak.com
*.access.eyedol.com *.asa.eyedol.com *.autoconfig.eyedol.com *.bad-camera.eyedol.com *.ciscoasa.eyedol.com *.ciscovpn.eyedol.com *.cleartech-consulting.eyedol.com *.cleartechdesign.eyedol.com *.cloud.eyedol.com *.cpcalendars.eyedol.com *.dev.eyedol.com *.email.eyedol.com eyedol.com *.eyedol.com *.firewall.eyedol.com *.gate.eyedol.com *.m.eyedol.com *.maximumescape.eyedol.com *.moodyjim.eyedol.com *.owa.eyedol.com *.ravpn.eyedol.com *.relay.eyedol.com *.remote.eyedol.com *.secure.eyedol.com *.secureaccess.eyedol.com *.test.eyedol.com *.vpn.eyedol.com *.vpn1.eyedol.com *.webmail.eyedol.com *.webvpn.eyedol.com *.ww16.eyedol.com
*.api.guaranis.com *.beta.guaranis.com guaranis.com *.guaranis.com *.m.guaranis.com *.sitemaps.guaranis.com *.staging.guaranis.com *.ww1.guaranis.com *.ww16.guaranis.com *.ww25.guaranis.com *.ww38.guaranis.com
imovie-time.club *.imovie-time.club *.ww38.imovie-time.club
musclegayclip.com *.musclegayclip.com *.ww12.musclegayclip.com
*.api.oszustwa.com *.dev.oszustwa.com *.hostmaster.oszustwa.com *.mail.oszustwa.com oszustwa.com *.oszustwa.com *.test.oszustwa.com *.vpn.oszustwa.com *.ww16.oszustwa.com *.ww17.oszustwa.com *.ww5.oszustwa.com
*.hostmaster.preliminar.com preliminar.com *.preliminar.com *.ww17.preliminar.com *.ww25.preliminar.com
thegunexchange.com *.thegunexchange.com *.ww16.thegunexchange.com
*.ftp.vocacion.com vocacion.com *.vocacion.com *.ww1.vocacion.com *.ww25.vocacion.com