Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=fitnessoutcome.run
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 24, 2026
Valid Until
August 22, 2026
65 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DB:E8:6E:FE:96:C7:67:04:F1:11:66:8A:DC:47:64:77:B9:99:D6:BC:FC:38:BF:8F:47:36:1A:25:78:3B:F8:C0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
flets-0.sbs
*.flets-0.sbs
fitnessoutcome.run
*.fitnessoutcome.run
fitnesspronetwork.run
*.fitnesspronetwork.run
fitnessresiliencepath.run
*.fitnessresiliencepath.run
fitnessresolutionsphere.run
*.fitnessresolutionsphere.run
fitnessresolveedge.run
*.fitnessresolveedge.run
fitnesssustainablehub.run
*.fitnesssustainablehub.run
fitnesstruelegacy.run
*.fitnesstruelegacy.run
fitnessvirtuepulse.run
*.fitnessvirtuepulse.run
foodprostrust.food
*.foodprostrust.food
foragecutter-br-13.sbs
*.foragecutter-br-13.sbs
foresightvoyage.xyz
*.foresightvoyage.xyz
fortitudetravelers.xyz
*.fortitudetravelers.xyz
forwardescapades.xyz
*.forwardescapades.xyz
fr-digitalmarketing4.sbs
*.fr-digitalmarketing4.sbs
francesgobeneficios.click
*.francesgobeneficios.click
francesonline.click
*.francesonline.click
fs069385.cc
*.fs069385.cc
funeral-services-0523.sbs
*.funeral-services-0523.sbs
futurecareerinsights.xyz
*.futurecareerinsights.xyz
gaming-pc-in-installments-de-2.sbs
*.gaming-pc-in-installments-de-2.sbs
gbfp530.org
*.gbfp530.org
geminiglobalvips.me
*.geminiglobalvips.me
ggfftt.xyz
*.ggfftt.xyz
givemypapers.xyz
*.givemypapers.xyz
gkggy560.com
*.gkggy560.com
global-mobil-cuzdan.click
*.global-mobil-cuzdan.click
globethrive.xyz
*.globethrive.xyz
gossipdistrict.xyz
*.gossipdistrict.xyz
gossipinnovations.xyz
*.gossipinnovations.xyz
gossipnest.xyz
*.gossipnest.xyz
gosstalk.xyz
*.gosstalk.xyz
gracefulweddingssphere.beauty
*.gracefulweddingssphere.beauty
grainboy.shop
*.grainboy.shop
greengrowthguru.xyz
*.greengrowthguru.xyz
greenthumbadvisor.xyz
*.greenthumbadvisor.xyz
herti.com
*.herti.com
intexcorp.shop
*.intexcorp.shop
joeberg-global.com
*.joeberg-global.com
kjtepi.app
*.kjtepi.app
lakeparkelitegaragedoorservice.cc
*.lakeparkelitegaragedoorservice.cc
lottovip998v4.xyz
*.lottovip998v4.xyz
meapp.club
*.meapp.club
na1flw2p.com
*.na1flw2p.com
naeus.work
*.naeus.work
Other domains in certificate