Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=finanzkopasspro.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 28, 2026
Valid Until
July 27, 2026
65 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
23:93:09:2F:5C:56:FB:25:F0:A9:00:0E:BD:7C:E8:B1:17:F4:A9:4F:C5:82:BE:F4:39:E5:D7:1A:58:BE:BC:44
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
almostmeta.com
*.almostmeta.com
949217.com
*.949217.com
95070.co
*.95070.co
951006.club
*.951006.club
a9297951a6abc6ce.com
*.a9297951a6abc6ce.com
abogadosdelesionesporhernias.top
*.abogadosdelesionesporhernias.top
anlagewupissenpr.com
*.anlagewupissenpr.com
capitalgroupwthj.com
*.capitalgroupwthj.com
cruise-discounts.com
*.cruise-discounts.com
ddef156b521558ee.com
*.ddef156b521558ee.com
detoxing.in
*.detoxing.in
dmuwy-220.com
*.dmuwy-220.com
dogcasual.com
*.dogcasual.com
dominant.group
*.dominant.group
e39e3e0e7b8d43a3.com
*.e39e3e0e7b8d43a3.com
e487x7.cyou
*.e487x7.cyou
expresswaylogistics.live
*.expresswaylogistics.live
fdoorb.cyou
*.fdoorb.cyou
feverclip.com
*.feverclip.com
finanzkopasspro.com
*.finanzkopasspro.com
fitnesssafe.run
*.fitnesssafe.run
gali.pro
*.gali.pro
game-news.site
*.game-news.site
gamesnews-today.site
*.gamesnews-today.site
gaslightrules.com
*.gaslightrules.com
generousx.com
*.generousx.com
*.webmail.generousx.com
gou55l.cyou
*.gou55l.cyou
health-care01.click
*.health-care01.click
home-value-estimator-1326-1745844568.today
*.home-value-estimator-1326-1745844568.today
km0f1p.cyou
*.km0f1p.cyou
ky4j.net
*.ky4j.net
lab-clabtest.com
*.lab-clabtest.com
m1pjqg.cyou
*.m1pjqg.cyou
manoirdesissi.com
*.manoirdesissi.com
robotouch.live
*.robotouch.live
sogo188slotonline.education
*.sogo188slotonline.education
sparkshininghome.com
*.sparkshininghome.com
toptoon.life
*.toptoon.life
trauma-therapist-24.click
*.trauma-therapist-24.click
traveltrustadvisors.live
*.traveltrustadvisors.live
tustinbanquetcenter.com
*.tustinbanquetcenter.com
water-storage-tanks-67645.click
*.water-storage-tanks-67645.click
we8xi8.cyou
*.we8xi8.cyou
xn--tuvalettkankl-82b8xdcb.com
*.xn--tuvalettkankl-82b8xdcb.com
Other domains in certificate