Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=eggenburg.de
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
March 26, 2026
Valid Until
June 24, 2026
32 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CA:DF:32:58:85:93:EC:64:72:EA:EF:5D:6F:EE:11:91:4B:2A:9F:AE:0E:27:56:CE:F5:36:F2:2D:93:20:41:77
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
84 domains
eggenburg.de
*.eggenburg.de
betriebssytem.de
*.betriebssytem.de
directversicherung.de
*.directversicherung.de
gasheizgeblaese.de
*.gasheizgeblaese.de
gusseisenpfannen.de
*.gusseisenpfannen.de
mototrrad.de
*.mototrrad.de
ontos-verlag.de
*.ontos-verlag.de
*.admin.rbx.bet
*.app.rbx.bet
*.apps.rbx.bet
*.backend.rbx.bet
*.beta.rbx.bet
*.cacti.rbx.bet
*.cms.rbx.bet
*.community.rbx.bet
*.cp.rbx.bet
*.crm.rbx.bet
*.demo.rbx.bet
*.dev.rbx.bet
*.development.rbx.bet
*.docs.rbx.bet
*.file.rbx.bet
*.gmail.rbx.bet
*.help.rbx.bet
*.helpdesk.rbx.bet
*.hosting.rbx.bet
*.http.rbx.bet
*.i.rbx.bet
*.im.rbx.bet
*.jenkins.rbx.bet
*.jira.rbx.bet
*.jobs.rbx.bet
*.jumpserver.rbx.bet
*.laravel.rbx.bet
*.lib.rbx.bet
*.lists.rbx.bet
*.live.rbx.bet
*.local.rbx.bet
*.login.rbx.bet
*.my.rbx.bet
*.mydevice.rbx.bet
*.new.rbx.bet
*.proxy.rbx.bet
rbx.bet
*.rbx.bet
*.s2.rbx.bet
*.sandbox.rbx.bet
*.secure.rbx.bet
*.server.rbx.bet
*.sip.rbx.bet
*.sites.rbx.bet
*.sp.rbx.bet
*.sqs.rbx.bet
*.staging.rbx.bet
*.stg.rbx.bet
*.support.rbx.bet
*.sv.rbx.bet
*.test.rbx.bet
*.testing.rbx.bet
*.vendor.rbx.bet
*.web.rbx.bet
*.web2.rbx.bet
*.webmail.rbx.bet
*.whm.rbx.bet
*.wiki.rbx.bet
*.www2.rbx.bet
*.zabbix.rbx.bet
schilddruse.de
*.schilddruse.de
tintaldra.com.au
*.tintaldra.com.au
*.dmxfoyvn.wecanbeheroes.io
*.stg.wecanbeheroes.io
wecanbeheroes.io
*.wecanbeheroes.io
xn--quarkbrtchen-bjb.de
*.xn--quarkbrtchen-bjb.de
Other domains in certificate