76/100 SECURITY SCORE

Certificate Information

Subject
CN=a16.pro
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 28, 2026
Valid Until
April 28, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
51:D5:01:56:5C:8E:B2:4F:D0:E9:09:B5:DC:B8:37:CA:49:FF:3F:A2:A0:B8:16:1E:C3:18:77:AA:4C:40:33:39
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
lestaninsdabord.com *.lestaninsdabord.com *.gitlab.lestaninsdabord.com

Other domains in certificate

1stvisitor.com *.1stvisitor.com *.ww38.1stvisitor.com
7startips.com *.7startips.com
a16.pro *.a16.pro *.ww25.a16.pro
aidshelp.cc *.aidshelp.cc
alligenceair.com *.alligenceair.com *.ww38.alligenceair.com
avropol.shop *.avropol.shop *.rustore.avropol.shop
baltosun.com *.baltosun.com *.ww38.baltosun.com
*.beta.bpn.au bpn.au *.bpn.au *.th.bpn.au *.ww38.bpn.au
dlox.io *.dlox.io
*.dev.dogbreader.com dogbreader.com *.dogbreader.com
echolink.com *.echolink.com *.web.echolink.com *.webapp.echolink.com *.ww16.echolink.com *.ww25.echolink.com *.ww38.echolink.com *.ww42.echolink.com
fogcomputingsystems.com *.fogcomputingsystems.com *.hostmaster.fogcomputingsystems.com
fyw.ai *.fyw.ai
independentobserver.com *.independentobserver.com
julen.es *.julen.es
kuwin.bet *.kuwin.bet
martijndendievel.co *.martijndendievel.co
mettaeyecare.org *.mettaeyecare.org
moviesking.pro *.moviesking.pro
nyr.de *.nyr.de
*.dxzw6g.p12.bet p12.bet *.p12.bet
*.beta.sexyvedios.com *.carpediem.sexyvedios.com *.ekaterinburg.sexyvedios.com *.its.sexyvedios.com *.mail3.sexyvedios.com *.random.sexyvedios.com *.sexy.sexyvedios.com sexyvedios.com *.sexyvedios.com *.ww17.sexyvedios.com *.xxx.sexyvedios.com
shavebox.com.au *.shavebox.com.au
tvturkru.online *.tvturkru.online
*.dashboard.unite.au unite.au *.unite.au *.ww38.unite.au
westfallen.de *.westfallen.de
witich.de *.witich.de
xn--wsenrot-n2a.de *.xn--wsenrot-n2a.de
zkb.au *.zkb.au