76/100 SECURITY SCORE

Certificate Information

Subject
CN=kazanel.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 09, 2026
Valid Until
May 10, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
67:11:53:F3:22:75:FB:C2:67:B4:C7:D2:C1:B7:1B:22:EA:C1:AA:AC:55:65:57:41:93:C7:6E:5C:99:E2:2F:2C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
einstellung.com *.einstellung.com *.crm.einstellung.com *.demo.einstellung.com *.forum.einstellung.com *.forums.einstellung.com *.help.einstellung.com *.isle.einstellung.com *.pp-www.einstellung.com *.sitemap.einstellung.com *.vpn.einstellung.com *.ww25.einstellung.com *.ww38.einstellung.com

Other domains in certificate

*.backup.boboras.com *.beta.boboras.com boboras.com *.boboras.com *.demo.boboras.com *.forum.boboras.com *.forums.boboras.com *.hostmaster.boboras.com *.mail.boboras.com *.random.boboras.com *.sitemap.boboras.com *.sitemaps.boboras.com *.vpn.boboras.com *.ww16.boboras.com *.ww25.boboras.com
*.admin.euykp.net euykp.net *.euykp.net
*.com.exo.asia exo.asia *.exo.asia *.gw.exo.asia *.ns.exo.asia *.www.exo.asia
expand3.com *.expand3.com *.m.expand3.com
*.access.juana.net *.admin.juana.net *.autodiscover.juana.net *.cloud.juana.net *.connect.juana.net *.cpanel.juana.net *.drvpn.juana.net *.email.juana.net *.firewall.juana.net *.gateway.juana.net *.imap.juana.net juana.net *.juana.net *.login.juana.net *.mail.juana.net *.portal.juana.net *.ra.juana.net *.rd.juana.net *.rdp.juana.net *.rds.juana.net *.rdweb.juana.net *.remote.juana.net *.smtp.juana.net *.ssl.juana.net *.sslvpn.juana.net *.vpn.juana.net *.vps131912.juana.net *.webapps.juana.net *.webmail.juana.net *.webvpn.juana.net *.ww1.juana.net *.ww38.juana.net
*.demo.kazanel.com kazanel.com *.kazanel.com
*.feew6.kkffff.top kkffff.top *.kkffff.top *.nslow.kkffff.top
*.3c41efc4-3c48-4957-9f8f-30f88fd2c396.thai99live.ink *.api.thai99live.ink *.ftp.thai99live.ink *.portal.thai99live.ink *.share.thai99live.ink *.sharepoint.thai99live.ink thai99live.ink *.thai99live.ink *.wildcardsubdomaintoprocess.thai99live.ink