Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=kacangijo1.click
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 09, 2026
Valid Until
May 10, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EB:26:58:7D:26:B2:42:C9:AA:24:87:19:26:0B:29:11:AA:67:26:9C:7F:6B:2A:7B:0F:4E:57:83:0C:3D:7D:E7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
finissimo.com
*.finissimo.com
*.wiki.finissimo.com
*.ww1.finissimo.com
*.ww25.finissimo.com
*.1646691111006.as7zy5.cn
as7zy5.cn
*.as7zy5.cn
*.aumen.as7zy5.cn
*.blog.as7zy5.cn
*.guanfang.as7zy5.cn
bottelsen.com
*.bottelsen.com
*.demo.bottelsen.com
*.eb.bottelsen.com
*.gis.bottelsen.com
*.home.bottelsen.com
*.intranet.bottelsen.com
*.load.bottelsen.com
*.mobile.bottelsen.com
*.news.bottelsen.com
*.test.bottelsen.com
*.ww11.bottelsen.com
*.app.burggraaff.com
burggraaff.com
*.burggraaff.com
*.cloud.burggraaff.com
*.gateway.burggraaff.com
*.hostmaster.burggraaff.com
*.m.burggraaff.com
*.mail.burggraaff.com
*.portal.burggraaff.com
*.rds.burggraaff.com
*.rds1.burggraaff.com
*.rdweb.burggraaff.com
*.remote.burggraaff.com
*.sitemap.burggraaff.com
*.staging.burggraaff.com
*.ts.burggraaff.com
*.ww1.burggraaff.com
fullfilment.company
*.fullfilment.company
gpstatic.net
*.gpstatic.net
*.www.gpstatic.net
homeequityloc.com
*.homeequityloc.com
*.cpcalendars.kacangijo1.click
kacangijo1.click
*.kacangijo1.click
*.api.kenyana.com
*.demo.kenyana.com
*.forum.kenyana.com
*.help.kenyana.com
*.hostmaster.kenyana.com
*.ibank.kenyana.com
kenyana.com
*.kenyana.com
*.mail.kenyana.com
*.test.kenyana.com
*.ww1.kenyana.com
*.ww16.kenyana.com
*.ww25.kenyana.com
*.www.kenyana.com
loandoc.com.au
*.loandoc.com.au
*.admin.loren.net
*.app.loren.net
*.cf.loren.net
*.demo.loren.net
*.dev.loren.net
*.hospital.loren.net
loren.net
*.loren.net
*.m.loren.net
*.mailin.loren.net
*.members.loren.net
*.ms.loren.net
*.staging.loren.net
*.test.loren.net
*.uat.loren.net
*.ww17.loren.net
*.dev.nyaker.com
nyaker.com
*.nyaker.com
yaruoislife.jp
*.yaruoislife.jp
zivstarchosruz.space
*.zivstarchosruz.space
Other domains in certificate