Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=windmill.ca
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
78 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
90:98:3A:92:4D:EF:28:82:EA:1F:85:2D:1E:C1:73:03:0A:26:1D:9C:D3:CC:C0:DB:DF:83:9A:94:6D:D1:B1:71
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
genxvacations.com
*.genxvacations.com
airtrackr.com
*.airtrackr.com
angelalee.com
*.angelalee.com
*.benjaminoechsler.benlocal.de
benlocal.de
*.benlocal.de
bolsjer.com
*.bolsjer.com
*.ww17.bolsjer.com
delhipolice.com
*.delhipolice.com
*.webvpn.delhipolice.com
dubstep-light.info
*.dubstep-light.info
*.ww38.dubstep-light.info
*.admin.ekino.cc
ekino.cc
*.ekino.cc
*.web.ekino.cc
fotografik.com
*.fotografik.com
*.we.fotografik.com
gpspromos.com
*.gpspromos.com
instander.me
*.instander.me
*.lime.instander.me
*.mail.instander.me
*.webmail.instander.me
*.ww25.instander.me
*.beta.mitchard.com
*.hostmaster.mitchard.com
mitchard.com
*.mitchard.com
munkcollective.com
*.munkcollective.com
*.ww38.munkcollective.com
*.ba.nastgirls.com
nastgirls.com
*.nastgirls.com
*.office.nastgirls.com
*.painel.nastgirls.com
oldecarriagerealty.com
*.oldecarriagerealty.com
plasticextrusion.com.au
*.plasticextrusion.com.au
*.app.postegrolili.net
*.backend.postegrolili.net
*.heroku.postegrolili.net
*.image.postegrolili.net
*.mobile.postegrolili.net
postegrolili.net
*.postegrolili.net
pricivity.com
*.pricivity.com
*.cpanel.redifindia.com
*.mail.redifindia.com
*.pop.redifindia.com
redifindia.com
*.redifindia.com
*.role.redifindia.com
*.webdisk.redifindia.com
*.webmail.redifindia.com
*.www.redifindia.com
restorationrehab.com.au
*.restorationrehab.com.au
*.ilgiardinorotwww.stolf.today
stolf.today
*.stolf.today
summerprogram.com
*.summerprogram.com
*.ww1.summerprogram.com
taxepertnow.com
*.taxepertnow.com
*.ww25.taxepertnow.com
*.mail.toptiertrove.store
toptiertrove.store
*.toptiertrove.store
*.www.toptiertrove.store
*.hostmaster.windmill.ca
windmill.ca
*.windmill.ca
*.test.xweight.com
xweight.com
*.xweight.com
zenappointment.co
*.zenappointment.co
Other domains in certificate