Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=calcifer.studio
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 11, 2026
Valid Until
September 09, 2026
74 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3E:A3:8E:85:76:6A:40:FE:F5:D7:4E:AB:E4:A7:C5:8E:57:6F:53:F2:33:94:2E:F0:6E:07:03:DA:E1:19:1B:93
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
erectiledysfunctionpills365.com
*.erectiledysfunctionpills365.com
calcifer.studio
*.calcifer.studio
en-regainrejuvenate.us
*.en-regainrejuvenate.us
eternal.skin
*.eternal.skin
evtm.xyz
*.evtm.xyz
familyfuncentral.com
*.familyfuncentral.com
finallipbalm.com
*.finallipbalm.com
fongfiafia.asia
*.fongfiafia.asia
furnitur3.com
*.furnitur3.com
fxstreet-spanish.com
*.fxstreet-spanish.com
getbzauto.com
*.getbzauto.com
golfteeai.com
*.golfteeai.com
goupcrunchloop.co
*.goupcrunchloop.co
happyheartinfo3434.info
*.happyheartinfo3434.info
headlinedrift.vip
*.headlinedrift.vip
hkasd.bid
*.hkasd.bid
homecentre.xyz
*.homecentre.xyz
ipsak.my
*.ipsak.my
kfs9657.cc
*.kfs9657.cc
l0lvb9lwkpq3p.top
*.l0lvb9lwkpq3p.top
laresidentialroofing.com
*.laresidentialroofing.com
lifequotesintamil.in
*.lifequotesintamil.in
lime-channel.com
*.lime-channel.com
ljkiy.com
*.ljkiy.com
maptenscope.click
*.maptenscope.click
marquelabs.com
*.marquelabs.com
meatwala.com
*.meatwala.com
meetfoundersclubhub.top
*.meetfoundersclubhub.top
miamiantique.com
*.miamiantique.com
nordicnexuzconversionhub.click
*.nordicnexuzconversionhub.click
nordicnexuzdealflow.click
*.nordicnexuzdealflow.click
nordicnexuzdirect.click
*.nordicnexuzdirect.click
nordicnexuzmailboost.click
*.nordicnexuzmailboost.click
nordicnexuzqualified.click
*.nordicnexuzqualified.click
nordicnexuzreachengine.click
*.nordicnexuzreachengine.click
nrteu.loan
*.nrteu.loan
nruew.my
*.nruew.my
ocuvist.online
*.ocuvist.online
olympicbid.icu
*.olympicbid.icu
onezapnetic.com
*.onezapnetic.com
onvoicops.com
*.onvoicops.com
outboundschool.com
*.outboundschool.com
outdoorinstall.com
*.outdoorinstall.com
ownercapitalpartners.com
*.ownercapitalpartners.com
ox3836.com
*.ox3836.com
Other domains in certificate