Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=pathfindershirt.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026 53 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
41:A8:0A:F7:A5:A0:D2:56:C5:F2:DD:EF:CF:CC:4C:83:3B:56:D5:F6:53:65:29:09:54:4A:DD:3B:9B:61:BA:B8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
expiring.mobi *.expiring.mobi *.net.expiring.mobi

Other domains in certificate

0i0o.sbs *.0i0o.sbs *.support.0i0o.sbs
711117.cc *.711117.cc
artbythebay.com *.artbythebay.com *.billing.artbythebay.com *.mx.artbythebay.com *.random.artbythebay.com
*.api.atcinfohk.com atcinfohk.com *.atcinfohk.com *.exchange.atcinfohk.com *.f.atcinfohk.com *.insurance.atcinfohk.com *.intranet.atcinfohk.com *.mta-sts.atcinfohk.com *.remoteaccess.atcinfohk.com *.secure.atcinfohk.com *.terminal.atcinfohk.com *.uog9.atcinfohk.com *.wildcard.atcinfohk.com *.wwww.atcinfohk.com
berufsunfaehigkeitsversicherung-vergleichen.org *.berufsunfaehigkeitsversicherung-vergleichen.org *.mail.berufsunfaehigkeitsversicherung-vergleichen.org *.vpn.berufsunfaehigkeitsversicherung-vergleichen.org *.www.berufsunfaehigkeitsversicherung-vergleichen.org
downunderauto.com.au *.downunderauto.com.au *.www.downunderauto.com.au
*.dashboard.eventtix.live eventtix.live *.eventtix.live *.mail.eventtix.live *.members.eventtix.live *.staging.eventtix.live *.stg.eventtix.live *.uat.eventtix.live *.v2.eventtix.live *.web.eventtix.live *.www.eventtix.live
fukushima-toyota.info *.fukushima-toyota.info *.www.fukushima-toyota.info
nicolas-barry.com *.nicolas-barry.com
pathfindershirt.com *.pathfindershirt.com *.ww1.pathfindershirt.com
sororiterh.com *.sororiterh.com *.www.sororiterh.com
*.c.sykes.it *.dashs.sykes.it *.mail.sykes.it *.r.sykes.it sykes.it *.sykes.it *.www.sykes.it
*.jeffreygoldberg.theatlanti.com theatlanti.com *.theatlanti.com *.ww11.theatlanti.com *.ww17.theatlanti.com *.ww25.theatlanti.com *.ww38.theatlanti.com *.www2.theatlanti.com
*.chat.tilleyhomes.com *.eml.tilleyhomes.com *.pool.tilleyhomes.com *.reg.tilleyhomes.com *.ticket.tilleyhomes.com tilleyhomes.com *.tilleyhomes.com *.video.tilleyhomes.com *.ww1.tilleyhomes.com
*.static.wwwmyaarp.com *.store.wwwmyaarp.com *.ww25.wwwmyaarp.com *.ww38.wwwmyaarp.com wwwmyaarp.com *.wwwmyaarp.com
*.t50c3n.xn--it-hmeencollege-1kbc.org xn--it-hmeencollege-1kbc.org *.xn--it-hmeencollege-1kbc.org