Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=grupoerlocr.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
November 24, 2025
Valid Until
February 22, 2026 33 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
96:3F:20:D2:FE:62:5E:94:61:E8:AC:47:62:78:B3:57:00:CA:80:63:F8:FB:FA:C7:06:40:F3:CD:6E:67:85:B7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
extempify.org *.extempify.org

Other domains in certificate

adblockpurple.com *.adblockpurple.com *.ww25.adblockpurple.com
*.app.appmagic.online appmagic.online *.appmagic.online *.backend.appmagic.online *.bst.appmagic.online *.demo.appmagic.online *.dev.appmagic.online *.tar.appmagic.online *.time.appmagic.online *.ww38.appmagic.online
boilcorn.com *.boilcorn.com
chordle.io *.chordle.io
*.demo.fischerpaykel.com *.dev.fischerpaykel.com fischerpaykel.com *.fischerpaykel.com *.shop.fischerpaykel.com *.spport.fischerpaykel.com *.store.fischerpaykel.com *.test.fischerpaykel.com *.www.fischerpaykel.com
*.cpcontacts.grupoerlocr.com grupoerlocr.com *.grupoerlocr.com *.mail.grupoerlocr.com
*.cukimai.kantongreceh.xyz *.jancuk.kantongreceh.xyz kantongreceh.xyz *.kantongreceh.xyz *.lubangite.kantongreceh.xyz *.nc138.kantongreceh.xyz *.pukimak.kantongreceh.xyz *.rbs.kantongreceh.xyz *.rpm24.kantongreceh.xyz *.sans.kantongreceh.xyz *.slowmo.kantongreceh.xyz *.vip.kantongreceh.xyz *.vvip.kantongreceh.xyz *.ww25.kantongreceh.xyz
mybenefitacenter.com *.mybenefitacenter.com
newneedshome.com *.newneedshome.com
*.ai.ociarchitect.com ociarchitect.com *.ociarchitect.com
roaoisk8qqzk3.xyz *.roaoisk8qqzk3.xyz *.ww25.roaoisk8qqzk3.xyz
sexarabixxx.com *.sexarabixxx.com
springkim.com *.springkim.com
*.analysis.terrarien.com *.analytic1.terrarien.com *.backup.terrarien.com *.bi-dev.terrarien.com *.bi2.terrarien.com *.dash-reset.terrarien.com *.dev-data.terrarien.com *.explore-ping.terrarien.com *.job-analytic2.terrarien.com *.replication-superset4.terrarien.com *.reporting-monitor.terrarien.com *.route-dash.terrarien.com *.sset.terrarien.com *.stat.terrarien.com *.stats-id.terrarien.com *.stats-network.terrarien.com *.superset1-monitor.terrarien.com terrarien.com *.terrarien.com *.visualize-template.terrarien.com *.wildcard.terrarien.com *.ww1.terrarien.com *.ww16.terrarien.com *.ww17.terrarien.com *.ww25.terrarien.com *.ww38.terrarien.com *.www.terrarien.com
vacancyhub.org *.vacancyhub.org