76/100 SECURITY SCORE

Certificate Information

Subject
CN=bajajverma.net
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 30, 2026
Valid Until
June 28, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
13:18:78:F0:F0:24:DB:DB:97:20:A5:55:BB:0F:69:EE:84:59:FC:CE:D6:56:9A:DC:F0:00:F4:07:38:BB:FB:DF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
toptradinglatam.com *.toptradinglatam.com

Other domains in certificate

almagdavisfoundation.org *.almagdavisfoundation.org
ba546c1912c75942.com *.ba546c1912c75942.com
bajajverma.net *.bajajverma.net
bambukamishasir.com *.bambukamishasir.com
betcioz.com *.betcioz.com
biride-cifage.pro *.biride-cifage.pro
blbkgzv.cn *.blbkgzv.cn
boldim.com *.boldim.com
bookforyourbrand-team.com *.bookforyourbrand-team.com
bookforyourbrandapp.com *.bookforyourbrandapp.com
cqusru.town *.cqusru.town
dimkft.gdn *.dimkft.gdn
dkjbo.town *.dkjbo.town
dkreducations.org *.dkreducations.org
dogstarregister.com *.dogstarregister.com
doorsmelbourne.com *.doorsmelbourne.com
electrickeyboardsreviewstore.com *.electrickeyboardsreviewstore.com
enteryourticket.com *.enteryourticket.com
ezgxn.pet *.ezgxn.pet
familywisehealth.com *.familywisehealth.com
farhabd.com *.farhabd.com
fuchsiapanthermadia.com *.fuchsiapanthermadia.com
gbuxwithcrypto.io *.gbuxwithcrypto.io *.test.gbuxwithcrypto.io
goldinmetropolitanhotel.com *.goldinmetropolitanhotel.com
hj25ja2b18.top *.hj25ja2b18.top
hlcel.loan *.hlcel.loan
hopewatch.com *.hopewatch.com
hosttzo.com *.hosttzo.com
houstonrocketshats.us *.houstonrocketshats.us
howtoguide.net *.howtoguide.net
hpoyo.soy *.hpoyo.soy
hrlrm.town *.hrlrm.town
htt403b.cyou *.htt403b.cyou
ialal.com *.ialal.com
studywise.co.in *.studywise.co.in
teslavr.com *.teslavr.com
thebookforyourbrand.com *.thebookforyourbrand.com
thecrockettsfarm.com *.thecrockettsfarm.com
thouiq.com *.thouiq.com
tqa78.top *.tqa78.top
tribalforum.org *.tribalforum.org
uceo3ykm8nvpqss.com *.uceo3ykm8nvpqss.com
valvhs.town *.valvhs.town