76/100 SECURITY SCORE

Certificate Information

Subject
CN=zvo.us
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
March 11, 2026
Valid Until
June 09, 2026 59 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
01:73:6B:1F:9F:4E:23:E0:0A:5C:97:08:80:E9:65:8B:B7:9C:FB:A9:63:0D:CE:56:C0:33:8E:66:06:F4:CB:1C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
trumpistaf.com *.trumpistaf.com *.docs.trumpistaf.com

Other domains in certificate

500amoxicillin.com *.500amoxicillin.com *.www.500amoxicillin.com
dirks.us *.dirks.us *.git.dirks.us
emobility.live *.emobility.live *.ww38.emobility.live
fxhte.gdn *.fxhte.gdn
gentlepathway.sbs *.gentlepathway.sbs
germanspecialtiesinc.com *.germanspecialtiesinc.com
*.adhere.getsmartnepal.com *.au.getsmartnepal.com *.civilhomes.getsmartnepal.com *.com.getsmartnepal.com getsmartnepal.com *.getsmartnepal.com *.nepcan.getsmartnepal.com *.org.getsmartnepal.com *.rajivbista.getsmartnepal.com
goodslooke.net *.goodslooke.net
hedrastudio.com *.hedrastudio.com
larvarium.com *.larvarium.com
*.hostmaster.malvito.com malvito.com *.malvito.com
mama.kitchen *.mama.kitchen
nbajersey26.shop *.nbajersey26.shop
phim18av.com *.phim18av.com
pskh.org *.pskh.org
rnovebodr.com *.rnovebodr.com
robolawyer.co *.robolawyer.co
royalofindia.com *.royalofindia.com
rurukuy.com *.rurukuy.com
rwbzk.qpon *.rwbzk.qpon
sacasinogames.org *.sacasinogames.org
sammd.com *.sammd.com
semplichef.com *.semplichef.com
siagent.ca *.siagent.ca
sobnrm.gdn *.sobnrm.gdn
*.sitemaps.soraprompts.io soraprompts.io *.soraprompts.io
spectralbiotech.com *.spectralbiotech.com
taconmama.com *.taconmama.com
tcjoqdbvhnmfnmo.com *.tcjoqdbvhnmfnmo.com
terentino.pl *.terentino.pl
theranchgrill.com *.theranchgrill.com
thericehut.com *.thericehut.com
tiopablotacos.com *.tiopablotacos.com
ungut.net *.ungut.net
windjammernj.com *.windjammernj.com
*.abuse.zvo.us *.hostmaster.zvo.us zvo.us *.zvo.us