Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=hhbomax.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 26, 2026
Valid Until
August 24, 2026
81 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F9:D6:F0:17:D7:37:1E:3D:2D:2B:88:2E:F4:2C:1A:AD:1C:52:97:F0:BB:88:C0:9D:38:B8:27:4D:4D:6D:9B:9A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
fischposter.de
*.fischposter.de
*.random.fischposter.de
abgpension.com
*.abgpension.com
bratkartoffel.de
*.bratkartoffel.de
*.demo.bratkartoffel.de
calibrate.com.au
*.calibrate.com.au
*.www.calibrate.com.au
cikanskajizba.cz
*.cikanskajizba.cz
*.random.cikanskajizba.cz
cleangutter.com.au
*.cleangutter.com.au
coffebreak.com
*.coffebreak.com
*.random.coffebreak.com
doriptv.shop
*.doriptv.shop
*.www.doriptv.shop
gaba.com.au
*.gaba.com.au
*.random.gaba.com.au
hbomaax.com
*.hbomaax.com
hhbomax.com
*.hhbomax.com
idsportstore.com
*.idsportstore.com
indo.energy
*.indo.energy
*.hostmaster.khanyimbau.co.za
khanyimbau.co.za
*.khanyimbau.co.za
*.random.khanyimbau.co.za
letraslindas.org
*.letraslindas.org
*.ww38.letraslindas.org
medinadelcampo.com
*.medinadelcampo.com
nightjarwoodwork.com
*.nightjarwoodwork.com
quaijia.com
*.quaijia.com
roman.moda
*.roman.moda
*.m.rzqnw.com
*.random.rzqnw.com
rzqnw.com
*.rzqnw.com
seren.solutions
*.seren.solutions
sewsofab.com
*.sewsofab.com
shein.money
*.shein.money
*.m4.snf.de
snf.de
*.snf.de
supercar.agency
*.supercar.agency
symbio.social
*.symbio.social
teamfsociety.com
*.teamfsociety.com
*.ww25.teamfsociety.com
*.blog.thefoodiefreak.me
*.nice.thefoodiefreak.me
thefoodiefreak.me
*.thefoodiefreak.me
*.ww25.thefoodiefreak.me
thelittlefavor.com
*.thelittlefavor.com
veritapress.com
*.veritapress.com
*.vpsa.veritapress.com
*.2.vpassvolaris.com
*.radio.vpassvolaris.com
vpassvolaris.com
*.vpassvolaris.com
*.ww25.vpassvolaris.com
walbbusch.de
*.walbbusch.de
webevergreen.com
*.webevergreen.com
woodshutters.com.au
*.woodshutters.com.au
Other domains in certificate