Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=picaro.in
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E9:49:AC:15:5E:1F:FD:D6:3E:7F:2A:3A:88:ED:50:5D:9E:A5:F6:6C:89:E1:57:9E:29:AE:3F:3A:9C:E7:CB:5D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
reodx.sh *.reodx.sh

Other domains in certificate

payoal.de *.payoal.de
pazzidipizza.it *.pazzidipizza.it
pendekarkiu.com *.pendekarkiu.com
personalmarketing.it *.personalmarketing.it
petroleoconvalor.com *.petroleoconvalor.com
phantomoftheattic.com *.phantomoftheattic.com
pharcel.com *.pharcel.com
phd75.top *.phd75.top
picaro.in *.picaro.in
pickapick.store *.pickapick.store
pivotldirect.com *.pivotldirect.com
plastic-surgery-th-5452.click *.plastic-surgery-th-5452.click
play-amber-outpost.xyz *.play-amber-outpost.xyz
play-onyx-adventure.xyz *.play-onyx-adventure.xyz
play-stealth-sanctuary.xyz *.play-stealth-sanctuary.xyz
play-victory-nexus.xyz *.play-victory-nexus.xyz
play-vivid-lane.xyz *.play-vivid-lane.xyz
plvsj.bid *.plvsj.bid
pms.it *.pms.it
pokerplanets.quest *.pokerplanets.quest
prefabricatedoffices.com *.prefabricatedoffices.com
prove.chat *.prove.chat
pwn46.top *.pwn46.top
qcr25.top *.qcr25.top
qubeticswallet.global *.qubeticswallet.global
qubitpay.xyz *.qubitpay.xyz
questnexus.cfd *.questnexus.cfd
questrade-web-703540287.click *.questrade-web-703540287.click
questrade-web-796227417.click *.questrade-web-796227417.click
quick-loans-in-mb4.click *.quick-loans-in-mb4.click
radiantbrideplans.beauty *.radiantbrideplans.beauty
rady.it *.rady.it
rangeshade-moon.mobi *.rangeshade-moon.mobi
rangesprayswoop.mobi *.rangesprayswoop.mobi
readblogsdaily.com *.readblogsdaily.com
reguhubz.xyz *.reguhubz.xyz
renatoelia.com *.renatoelia.com
renovative.co *.renovative.co
reodat.io *.reodat.io
reversedns.it *.reversedns.it
revokerer.com *.revokerer.com
rfr43.top *.rfr43.top
rgbet.love *.rgbet.love
rgc92.top *.rgc92.top