Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=fesker.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 25, 2026
Valid Until
September 23, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:F8:2C:65:1D:57:EC:88:58:2F:9A:14:D6:D2:A3:CD:D3:EE:D4:E1:F3:51:07:56:27:0F:F7:B8:5B:C8:9B:C0
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
fesker.com *.fesker.com *.6aykj.fesker.com *.api.fesker.com *.caviar.fesker.com *.deaf.fesker.com *.defense.fesker.com *.dk.fesker.com *.dormancy.fesker.com *.f0o57.fesker.com *.food.fesker.com *.formality.fesker.com *.fractured.fesker.com *.guanyu.fesker.com *.handling.fesker.com *.m.fesker.com *.metallic.fesker.com *.monorail.fesker.com *.needful.fesker.com *.qq44f.fesker.com *.vibrance.fesker.com *.www.fesker.com *.zone.fesker.com

Other domains in certificate

*.alpfivpn.blancheport.be *.api.blancheport.be *.autoconfig.blancheport.be blancheport.be *.blancheport.be *.chat.blancheport.be *.dan.blancheport.be *.de.blancheport.be *.demo.blancheport.be *.dev.blancheport.be *.download.blancheport.be *.emv1.blancheport.be *.gmykubhw.blancheport.be *.godsjnew.blancheport.be *.kgjmvgodsjnew.blancheport.be *.m.blancheport.be *.mail.blancheport.be *.mx1.blancheport.be *.new.blancheport.be *.office.blancheport.be *.pay.blancheport.be *.remote.blancheport.be *.s1.blancheport.be *.secure.blancheport.be *.service.blancheport.be *.staging.blancheport.be *.vpn.blancheport.be *.wap.blancheport.be *.web.blancheport.be *.ws.blancheport.be *.ww25.blancheport.be *.ww4.blancheport.be *.www.blancheport.be
*.32.connect2yourhealth.com *.comune.connect2yourhealth.com connect2yourhealth.com *.connect2yourhealth.com *.lyncdiscover.connect2yourhealth.com *.mail.connect2yourhealth.com *.meet.connect2yourhealth.com *.mx.connect2yourhealth.com *.peoplesoft.connect2yourhealth.com *.www.connect2yourhealth.com
*.analytics.rinviata.com *.api.rinviata.com *.backend.rinviata.com *.bi.rinviata.com *.metric.rinviata.com *.reporting.rinviata.com rinviata.com *.rinviata.com
*.admin.vibeprojects.dev *.assets.vibeprojects.dev *.bk.vibeprojects.dev *.demo.vibeprojects.dev *.my.vibeprojects.dev vibeprojects.dev *.vibeprojects.dev
*.admin.visitdeauville.com *.api.visitdeauville.com *.demo.visitdeauville.com *.dev.visitdeauville.com *.m.visitdeauville.com *.staging.visitdeauville.com *.test.visitdeauville.com visitdeauville.com *.visitdeauville.com