Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=sbones.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 15, 2026
Valid Until
May 16, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
27:0E:CF:69:C5:D4:57:E2:A3:80:67:56:5E:7F:D5:AF:FE:49:06:2B:DC:64:CD:A3:C4:8E:50:2B:63:6C:74:45
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
qlys37.app
*.qlys37.app
*.1487.b14879462.com
b14879462.com
*.b14879462.com
nanogenerative.com
*.nanogenerative.com
okwin.date
*.okwin.date
omjqlbg.us
*.omjqlbg.us
pd65qfdz.top
*.pd65qfdz.top
premiumteamgbtec.com
*.premiumteamgbtec.com
premiumtresscocapital.com
*.premiumtresscocapital.com
progoat43.org
*.progoat43.org
pyrammimb.vip
*.pyrammimb.vip
qlys26.app
*.qlys26.app
qwm5l.cc
*.qwm5l.cc
*.o.sbones.com
sbones.com
*.sbones.com
*.ww38.sbones.com
scalewatermarklife.com
*.scalewatermarklife.com
sea-star-beachwear.com
*.sea-star-beachwear.com
securevirtuhub.com
*.securevirtuhub.com
shieldedlink.my
*.shieldedlink.my
shieldedprofile.my
*.shieldedprofile.my
shootitonline.com
*.shootitonline.com
sini-arah4d.lol
*.sini-arah4d.lol
solutionsvirtualsecure.com
*.solutionsvirtualsecure.com
southbeachcleaners.com
*.southbeachcleaners.com
sperm-donation-center-mb4.click
*.sperm-donation-center-mb4.click
splashbaymarketing.com
*.splashbaymarketing.com
strategzilla-team.com
*.strategzilla-team.com
summitmovetop.com
*.summitmovetop.com
supergbtech.com
*.supergbtech.com
sydconhub.com
*.sydconhub.com
sydcontec.com
*.sydcontec.com
sydcontech.com
*.sydcontech.com
teamcrunchmedia.com
*.teamcrunchmedia.com
themelinagroup.com
*.themelinagroup.com
thumbnaildownloader4k.cool
*.thumbnaildownloader4k.cool
tmb66v.club
*.tmb66v.club
united-pharmacy-support.info
*.united-pharmacy-support.info
venusml.com
*.venusml.com
visionary-ml.com
*.visionary-ml.com
vv666831.com
*.vv666831.com
vv666836.com
*.vv666836.com
vv666858.com
*.vv666858.com
xysuu.sbs
*.xysuu.sbs
yskfu.net
*.yskfu.net
ztvkjc.net
*.ztvkjc.net
Other domains in certificate