76/100 SECURITY SCORE

Certificate Information

Subject
CN=kitabingo.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 24, 2026
Valid Until
September 22, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:AF:BD:2D:DB:38:E0:66:07:43:BA:01:E3:5A:10:BD:28:0A:E1:72:89:3E:63:62:E9:82:59:8D:FF:C7:53:7F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
verifypast.com *.verifypast.com *.filter.verifypast.com *.m.verifypast.com *.members.verifypast.com *.sitemaps.verifypast.com *.smtp2.verifypast.com

Other domains in certificate

bbaiaide.com *.bbaiaide.com
bight.it *.bight.it *.www.bight.it
bitdexcoin.com *.bitdexcoin.com *.mail.bitdexcoin.com *.webdisk.bitdexcoin.com
bretbyvanhire.co.uk *.bretbyvanhire.co.uk *.support.bretbyvanhire.co.uk
*.4euefe.crunch.casino *.admin.crunch.casino *.apps.crunch.casino crunch.casino *.crunch.casino *.demo.crunch.casino
data.org.in *.data.org.in *.ielts.data.org.in *.system.data.org.in
dracarysgames.cl *.dracarysgames.cl
giantessnovel.com *.giantessnovel.com
*.autodiscover.interracialcomicporn.com *.cpanel.interracialcomicporn.com *.cpcalendars.interracialcomicporn.com *.cpcontacts.interracialcomicporn.com *.directory.interracialcomicporn.com interracialcomicporn.com *.interracialcomicporn.com *.mail.interracialcomicporn.com *.webdisk.interracialcomicporn.com *.webmail.interracialcomicporn.com *.ww1.interracialcomicporn.com *.ww7.interracialcomicporn.com *.ww99.interracialcomicporn.com *.www.interracialcomicporn.com
*.a3d96d41-d3b8-462f-bcb8-fa9fbf620a8c.kerstdecoraties.vip *.api.kerstdecoraties.vip *.demo.kerstdecoraties.vip kerstdecoraties.vip *.kerstdecoraties.vip *.vip.kerstdecoraties.vip
*.google.kitabingo.com kitabingo.com *.kitabingo.com *.ww25.kitabingo.com
*.7kykjl.ktv789.info ktv789.info *.ktv789.info *.ww25.ktv789.info
*.admin.livingandhome.hk *.assets.livingandhome.hk *.dev.livingandhome.hk livingandhome.hk *.livingandhome.hk *.test.livingandhome.hk
*.bbblanyueliang.lyl740033abc.xyz lyl740033abc.xyz *.lyl740033abc.xyz
speedymd.com *.speedymd.com *.vblsk1b3zc1m7j0d.speedymd.com
*.org.testinggg.com testinggg.com *.testinggg.com
*.3nxyc.voyagers50.top *.aowpq.voyagers50.top *.cxie3.voyagers50.top *.ebwif.voyagers50.top *.kwid9.voyagers50.top *.pwb3b.voyagers50.top *.ques8.voyagers50.top voyagers50.top *.voyagers50.top
*.2tf7yg7.xh3vip076.shop *.4wv8ht3.xh3vip076.shop *.5wv8yw4.xh3vip076.shop xh3vip076.shop *.xh3vip076.shop