76/100 SECURITY SCORE

Certificate Information

Subject
CN=aikidsbrain.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
26:2A:7E:A8:6A:EB:C1:0B:78:04:03:1B:B1:89:77:AE:43:87:0F:A7:C7:6C:1C:15:9E:CF:E6:58:45:AA:CF:3C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
norlander.com *.norlander.com *.admin.norlander.com *.api.norlander.com *.autodiscover.norlander.com *.backup.norlander.com *.cisco.norlander.com *.ciscoasa.norlander.com *.ciscovpn.norlander.com *.connect.norlander.com *.cpcontacts.norlander.com *.dev.norlander.com *.drvpn.norlander.com *.exmb1.norlander.com *.ftp.norlander.com *.imap.norlander.com *.m.norlander.com *.mail5.norlander.com *.mailgate.norlander.com *.mailgw.norlander.com *.openpgpkey.norlander.com *.ra.norlander.com *.ravpn.norlander.com *.relay.norlander.com *.remote.norlander.com *.secure2.norlander.com *.sslvpn.norlander.com *.test.norlander.com *.webmail2.norlander.com *.ww16.norlander.com

Other domains in certificate

aikidsbrain.com *.aikidsbrain.com *.localhost.aikidsbrain.com *.mail.aikidsbrain.com *.pop.aikidsbrain.com *.whm.aikidsbrain.com
bikiniposter.com *.bikiniposter.com *.dsp.bikiniposter.com *.games.bikiniposter.com *.mx.bikiniposter.com *.mx2.bikiniposter.com *.tr.bikiniposter.com *.users.bikiniposter.com *.wiki.bikiniposter.com
bong88.cool *.bong88.cool *.portal.bong88.cool *.random.bong88.cool *.www.bong88.cool
constructionmachinery.it *.constructionmachinery.it *.hostmaster.constructionmachinery.it
getwave.net *.getwave.net *.hostmaster.getwave.net *.image.getwave.net *.monitor.getwave.net *.nahraj.getwave.net *.pagerank.getwave.net *.proxy.getwave.net *.reklama.getwave.net *.sitemap.getwave.net *.ww25.getwave.net
*.calendar.j-a-s.com *.email.j-a-s.com *.files.j-a-s.com j-a-s.com *.j-a-s.com *.pop.j-a-s.com *.remote.j-a-s.com *.www.j-a-s.com
*.gfzmmulh.olimplpmq.xyz olimplpmq.xyz *.olimplpmq.xyz *.suovauei.olimplpmq.xyz
rnasystems.com *.rnasystems.com *.secure1.rnasystems.com *.sitemaps.rnasystems.com *.wildcard.rnasystems.com *.ww25.rnasystems.com *.ww38.rnasystems.com *.www2.rnasystems.com
salvatoreferragamo.store *.salvatoreferragamo.store
*.api.traviix.shop traviix.shop *.traviix.shop