Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=man32.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 03, 2026
Valid Until
May 04, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:F0:31:7F:41:61:EC:24:BA:94:F4:6A:19:7F:F0:79:2E:3B:9A:7A:85:F3:07:72:6E:DF:57:27:02:8A:03:2B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
haler.net
*.haler.net
colonialmexico.com
*.colonialmexico.com
comotramitar.org
*.comotramitar.org
connestnetwork.com
*.connestnetwork.com
contabile.com
*.contabile.com
cv733.cn
*.cv733.cn
decoratingandstaging.com
*.decoratingandstaging.com
deltadenalco.com
*.deltadenalco.com
digitalbfcm.com
*.digitalbfcm.com
dlenor.com
*.dlenor.com
docyi.pro
*.docyi.pro
dofqr.shop
*.dofqr.shop
duoyuanjx.cn
*.duoyuanjx.cn
ecofriendlyapparel.sbs
*.ecofriendlyapparel.sbs
eslotdream.quest
*.eslotdream.quest
fliponline.net
*.fliponline.net
fsm24.top
*.fsm24.top
future-shop.com
*.future-shop.com
gjwzyv.pro
*.gjwzyv.pro
glitchesandwonders.com
*.glitchesandwonders.com
gudzila.cam
*.gudzila.cam
haliforniaapparel.com
*.haliforniaapparel.com
happishop.xyz
*.happishop.xyz
hausstyling.com
*.hausstyling.com
hdmatch.xyz
*.hdmatch.xyz
hvfcuonline.org
*.hvfcuonline.org
ilahcordelia.com
*.ilahcordelia.com
insurancebrokerageservices.com
*.insurancebrokerageservices.com
intestatario.com
*.intestatario.com
jikok47.net
*.jikok47.net
jmuzlnbes2xga.cc
*.jmuzlnbes2xga.cc
jogo520.info
*.jogo520.info
ladderalliance.org
*.ladderalliance.org
legalway.co.uk
*.legalway.co.uk
lemontreedigital.com
*.lemontreedigital.com
leprevisionimeteo.com
*.leprevisionimeteo.com
lfumachine.com
*.lfumachine.com
licia.co
*.licia.co
lotterybdt.com
*.lotterybdt.com
lznlb.cn
*.lznlb.cn
m9j7poty.top
*.m9j7poty.top
mainakarobiamwangi.org
*.mainakarobiamwangi.org
man32.com
*.man32.com
mojobrands.net
*.mojobrands.net
musicassetta.com
*.musicassetta.com
Other domains in certificate