Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=buildingsocietyloans.au
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
64:E3:19:D5:0B:B6:1B:54:10:65:A2:1D:B1:09:13:7E:F6:73:1B:55:1A:B7:A3:E5:35:0A:6B:6E:7B:DD:70:95
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
youseries.com
*.youseries.com
*.api.youseries.com
*.dev.youseries.com
*.mail.youseries.com
*.test.youseries.com
*.ww1.youseries.com
*.ww16.youseries.com
*.ww38.youseries.com
buildingsocietyloans.au
*.buildingsocietyloans.au
expeditors.au
*.expeditors.au
girlstore.com.au
*.girlstore.com.au
glucotester.com
*.glucotester.com
*.m.glucotester.com
*.qkhgym.glucotester.com
*.ww1.glucotester.com
*.ww16.glucotester.com
*.ww25.glucotester.com
gymwarehouse.au
*.gymwarehouse.au
handbikes.au
*.handbikes.au
*.957f9619-93bb-4130-977c-b78874bb06c9.parisar.com
*.hostmaster.parisar.com
parisar.com
*.parisar.com
*.store.parisar.com
*.wiki.parisar.com
*.ww1.parisar.com
*.ww11.parisar.com
*.ww16.parisar.com
*.yhnmbold.parisar.com
*.load.popeta.com
*.m.popeta.com
popeta.com
*.popeta.com
*.send.popeta.com
*.store.popeta.com
*.vendas.popeta.com
*.webmail.popeta.com
*.ww16.popeta.com
*.ww25.popeta.com
*.ww38.popeta.com
*.ww8.popeta.com
*.api.pricevan.com
*.atendimento.pricevan.com
*.m.pricevan.com
*.mail.pricevan.com
*.members.pricevan.com
pricevan.com
*.pricevan.com
*.sitemap.pricevan.com
*.ww1.pricevan.com
*.ww16.pricevan.com
*.ww17.pricevan.com
*.ww25.pricevan.com
*.ci.protargets.com
*.cicd.protargets.com
*.id.protargets.com
*.jenkins.protargets.com
*.pipeline.protargets.com
*.production.protargets.com
protargets.com
*.protargets.com
*.speedtest.protargets.com
*.ww1.protargets.com
*.ww11.protargets.com
*.ww16.protargets.com
*.ww25.protargets.com
*.ww38.protargets.com
simtas.com
*.simtas.com
*.ww11.simtas.com
*.ww25.simtas.com
*.dev.trackengines.com
*.hostmaster.trackengines.com
*.sitemaps.trackengines.com
trackengines.com
*.trackengines.com
*.ww11.trackengines.com
*.ww16.trackengines.com
*.ww17.trackengines.com
*.ww25.trackengines.com
*.ww38.trackengines.com
Other domains in certificate