76/100 SECURITY SCORE

Certificate Information

Subject
CN=ipsasap.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 12, 2026
Valid Until
September 10, 2026 78 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6C:1B:48:A0:F4:9D:7D:B4:1E:92:13:E2:29:B4:97:20:EC:2B:C3:D3:EA:CA:58:26:64:39:84:50:F4:AC:1C:E0
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
readingjob.info *.readingjob.info *.app.readingjob.info *.com90e-bcae-4646c75a8601.readingjob.info

Other domains in certificate

15yc.info *.15yc.info *.app.15yc.info *.bgptools-wildcard-confirmed.15yc.info *.wallet.15yc.info
aifreethink.com *.aifreethink.com *.dev.aifreethink.com *.flmubstaging.aifreethink.com
*.admin.conformismo.it *.app.conformismo.it conformismo.it *.conformismo.it *.demo.conformismo.it *.mail.conformismo.it *.report.conformismo.it *.staging.conformismo.it *.ww.conformismo.it
*.ak.epicgams.com epicgams.com *.epicgams.com *.launcher.epicgams.com *.ol.epicgams.com *.sac.epicgams.com *.statns.epicgams.com *.statu.epicgams.com *.statun.epicgams.com *.status.epicgams.com *.stor.epicgams.com *.store.epicgams.com *.ww38.epicgams.com
*.blog.hanydmd.com hanydmd.com *.hanydmd.com *.members.hanydmd.com
hirens.com *.hirens.com *.random.hirens.com *.ww2.hirens.com *.ww25.hirens.com
*.api.homesafer.com homesafer.com *.homesafer.com *.jenkins.homesafer.com
ipsasap.com *.ipsasap.com *.superset.ipsasap.com
*.api.mrburbank.com mrburbank.com *.mrburbank.com
primetravelfocus.live *.primetravelfocus.live
*.hostmaster.roll20.de *.random.roll20.de roll20.de *.roll20.de *.ww38.roll20.de
*.32.tennancydepositscheme.com *.random.tennancydepositscheme.com tennancydepositscheme.com *.tennancydepositscheme.com
*.api.videocellulars.com *.app.videocellulars.com *.backend.videocellulars.com videocellulars.com *.videocellulars.com
*.app.vina58ok.vip *.dashboard.vina58ok.vip *.demo.vina58ok.vip *.dev.vina58ok.vip *.kxipdbackup.vina58ok.vip *.mail.vina58ok.vip *.marketing.vina58ok.vip *.members.vina58ok.vip *.secure.vina58ok.vip *.test.vina58ok.vip *.uat.vina58ok.vip vina58ok.vip *.vina58ok.vip *.vuhiwapi.vina58ok.vip
*.dev.winchlines.com *.whm.winchlines.com winchlines.com *.winchlines.com *.ww38.winchlines.com