Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=brandnests.in
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 02, 2026
Valid Until
July 31, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
55:9E:43:29:02:ED:77:2C:BF:87:5E:E5:88:81:19:FD:43:D0:85:38:59:12:D0:DB:25:CF:DA:F2:02:63:38:89
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
feng182.com
*.feng182.com
acest.academy
*.acest.academy
*.cpanel.acest.academy
*.cpcalendars.acest.academy
*.members.acest.academy
*.pop.acest.academy
*.webdisk.acest.academy
artecreativo.com
*.artecreativo.com
brandnests.in
*.brandnests.in
*.nextbuy.brandnests.in
curlsmonthy.com
*.curlsmonthy.com
descubrir-trabajo-en-el-sitio.sbs
*.descubrir-trabajo-en-el-sitio.sbs
enduroactiveindustries.com
*.enduroactiveindustries.com
*.admin.epik1.digital
*.api.epik1.digital
*.demo.epik1.digital
*.dev.epik1.digital
epik1.digital
*.epik1.digital
*.test.epik1.digital
*.webmail.epik1.digital
*.www.epik1.digital
evayim.mobi
*.evayim.mobi
fire-insights.com
*.fire-insights.com
*.fire-insights.fire-insights.com
*.adellum.inate.com
*.bancapopolaredelcass.inate.com
*.bom.inate.com
*.cloud.inate.com
*.co.inate.com
*.comune.inate.com
*.es.inate.com
*.firewall.inate.com
*.golu.inate.com
*.ha.inate.com
inate.com
*.inate.com
*.lum.inate.com
*.m.inate.com
*.or.inate.com
*.poll.inate.com
*.prom.inate.com
*.random.inate.com
*.rds.inate.com
*.ru.inate.com
*.connectvpn.info21c.com
info21c.com
*.info21c.com
*.m.info21c.com
*.vpn2.info21c.com
*.webvpn.info21c.com
learnily.com
*.learnily.com
*.m.learnily.com
meggyogyultam.com
*.meggyogyultam.com
meiwu.club
*.meiwu.club
oninstudio.com
*.oninstudio.com
ovunq.town
*.ovunq.town
paretoagentic.com
*.paretoagentic.com
premier-exhibitshub.com
*.premier-exhibitshub.com
*.hostmaster.routineplaylist.com
*.m.routineplaylist.com
routineplaylist.com
*.routineplaylist.com
*.hostmaster.russianspeakingagent.com
russianspeakingagent.com
*.russianspeakingagent.com
*.www.russianspeakingagent.com
scalewithbsvlaw.xyz
*.scalewithbsvlaw.xyz
thinklands.com.cn
*.thinklands.com.cn
*.www.thinklands.com.cn
*.wwww.thinklands.com.cn
Other domains in certificate