Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=goocli.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 19, 2025
Valid Until
March 19, 2026
33 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FD:D7:08:72:B5:50:2B:6C:15:D1:4E:9A:6E:C4:64:55:2E:62:38:00:32:51:BD:4F:26:90:31:80:51:22:38:D8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
goocli.com
*.goocli.com
*.ww25.goocli.com
*.ww7.goocli.com
*.www.goocli.com
d247news.com
*.d247news.com
epicor.au
*.epicor.au
*.ww25.epicor.au
*.ww38.epicor.au
faxzer.com
*.faxzer.com
*.workflow.faxzer.com
fxadvice.net
*.fxadvice.net
greenskynline.com
*.greenskynline.com
*.workflow.greenskynline.com
hauskaras.de
*.hauskaras.de
irfisng.it
*.irfisng.it
le-kd-om.xyz
*.le-kd-om.xyz
*.682f739f-075d-4155-93de-344f46d4ee88.lives.bet
*.api.lives.bet
*.app.lives.bet
*.blog.lives.bet
*.cdn.lives.bet
*.dev.lives.bet
*.emv1.lives.bet
*.graphql.lives.bet
*.home.lives.bet
lives.bet
*.lives.bet
*.m.lives.bet
*.mail.lives.bet
*.mobile.lives.bet
*.news.lives.bet
*.notexistsemv.lives.bet
*.notexistsemv1.lives.bet
*.notexistssitemap.lives.bet
*.notexistssitemaps.lives.bet
*.phhlfnews.lives.bet
*.premier.lives.bet
*.remote.lives.bet
*.sitemap.lives.bet
*.sitemaps.lives.bet
*.staging.lives.bet
*.support.lives.bet
*.vpn.lives.bet
*.wap.lives.bet
*.web.lives.bet
*.www.lives.bet
mahasalemansson.xyz
*.mahasalemansson.xyz
*.brawl.poper.xyz
*.cash.poper.xyz
*.clans.poper.xyz
*.cm.poper.xyz
*.cnf.poper.xyz
*.coinmasterfreespin.poper.xyz
*.coinsp.poper.xyz
*.csm.poper.xyz
*.dice.poper.xyz
*.duty.poper.xyz
*.fire.poper.xyz
*.fun.poper.xyz
*.gems.poper.xyz
*.iphone.poper.xyz
*.mastercoins.poper.xyz
*.mat.poper.xyz
*.match.poper.xyz
*.matchmaster.poper.xyz
*.me.poper.xyz
*.ms.poper.xyz
*.poly.poper.xyz
poper.xyz
*.poper.xyz
*.sp.poper.xyz
*.spins.poper.xyz
*.sum.poper.xyz
*.summt.poper.xyz
*.vbuc.poper.xyz
*.xyz.poper.xyz
sttarbucks.com
*.sttarbucks.com
web3axis.com
*.web3axis.com
Other domains in certificate