Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=berry-fig.life
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026
78 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
45:98:55:72:73:E7:98:9B:A3:38:99:8B:8A:A6:7D:BD:07:0D:3C:E9:DF:AE:43:9C:7F:93:9E:AF:9C:74:B8:8F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
glowscopejolt.rest
*.glowscopejolt.rest
57j5.com
*.57j5.com
60win.click
*.60win.click
988030.co
*.988030.co
988slotcofe.lat
*.988slotcofe.lat
*.p473ad.988slotcofe.lat
astro-fig.mobi
*.astro-fig.mobi
berry-fig.life
*.berry-fig.life
berry-rune.cloud
*.berry-rune.cloud
berryrune.rest
*.berryrune.rest
bnk.asia
*.bnk.asia
breeze-dash.team
*.breeze-dash.team
breeze-twin.team
*.breeze-twin.team
breezespark.world
*.breezespark.world
breezetwin.click
*.breezetwin.click
businesssetupifza.com
*.businesssetupifza.com
cloud-nova.pro
*.cloud-nova.pro
clouddash.city
*.clouddash.city
codecraft.company
*.codecraft.company
crowagentic.com
*.crowagentic.com
dkitop88.live
*.dkitop88.live
dylans.co
*.dylans.co
event-planner-592774613.click
*.event-planner-592774613.click
gdfqb.gdn
*.gdfqb.gdn
gdpasrnjqnjwkln.cc
*.gdpasrnjqnjwkln.cc
*.02dljw.glow-scope-jolt.rest
glow-scope-jolt.rest
*.glow-scope-jolt.rest
goviralclub.com
*.goviralclub.com
*.m.goviralclub.com
*.www.goviralclub.com
hbhongma.cn
*.hbhongma.cn
heart-land.biz
*.heart-land.biz
hemmatlawgroup.com
*.hemmatlawgroup.com
hengheng289.bet
*.hengheng289.bet
hyperwizard723.info
*.hyperwizard723.info
jokerakty.com
*.jokerakty.com
*.34h1po.justinphillyliving.com
justinphillyliving.com
*.justinphillyliving.com
kbcc340.org
*.kbcc340.org
kutustore.biz
*.kutustore.biz
lime-byte.vip
*.lime-byte.vip
mencarihappy.org
*.mencarihappy.org
*.api.mindgridais.com
*.h402v7.mindgridais.com
mindgridais.com
*.mindgridais.com
*.server.mindgridais.com
*.vps.mindgridais.com
*.www.mindgridais.com
misthawk.top
*.misthawk.top
moussa-dembele-ar.biz
*.moussa-dembele-ar.biz
Other domains in certificate