Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tagfog.shop
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 28, 2025
Valid Until
March 28, 2026
39 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9D:A3:3F:F1:CC:35:9B:D5:A6:71:65:4A:E3:84:B6:D1:AF:AF:2B:60:D4:4D:EC:D8:BB:FA:A7:6F:35:4F:1E:E4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
87 domains
fflockerroom.com
*.fflockerroom.com
ambershaye.com
*.ambershaye.com
borsaajans.com
*.borsaajans.com
byarwa.com
*.byarwa.com
carlosartglass.com
*.carlosartglass.com
cos-yt.com
*.cos-yt.com
davidleeedtech.org
*.davidleeedtech.org
deltavalue.pro
*.deltavalue.pro
dy6444.com
*.dy6444.com
feed.bio
*.feed.bio
*.m.feed.bio
gloxfx.site
*.gloxfx.site
jungsuyun.life
*.jungsuyun.life
kamukhi.com
*.kamukhi.com
*.hostmaster.lenonade.com
lenonade.com
*.lenonade.com
lifehaschanged.com
*.lifehaschanged.com
*.api.mcmod.info
*.hostmaster.mcmod.info
mcmod.info
*.mcmod.info
*.pfqblww25.mcmod.info
*.sjje4zryc5.mcmod.info
*.ww1.mcmod.info
meesg.me
*.meesg.me
nameathlon.com
*.nameathlon.com
palomnik-sumy.com
*.palomnik-sumy.com
*.ww25.palomnik-sumy.com
*.app.plugsgold.com
*.cpanel.plugsgold.com
plugsgold.com
*.plugsgold.com
portobet453.com
*.portobet453.com
reckulucka.com
*.reckulucka.com
salaudsdepauvres.com
*.salaudsdepauvres.com
searchforsmthing.com
*.searchforsmthing.com
sharemarketinmarathi.com
*.sharemarketinmarathi.com
*.api.tagfog.shop
*.app.tagfog.shop
*.bigboss.tagfog.shop
*.boss.tagfog.shop
*.dev.tagfog.shop
*.home.tagfog.shop
*.m.tagfog.shop
*.mobile.tagfog.shop
*.news.tagfog.shop
*.s.tagfog.shop
tagfog.shop
*.tagfog.shop
*.wap.tagfog.shop
*.web.tagfog.shop
*.ww25.tagfog.shop
*.www.tagfog.shop
timecriticalalerts.com
*.timecriticalalerts.com
tvoy-dvor.com
*.tvoy-dvor.com
westchesterunitescoalition.org
*.westchesterunitescoalition.org
*.random.woodline.store
woodline.store
*.woodline.store
worldlibertyfintech.com
*.worldlibertyfintech.com
Other domains in certificate