76/100 SECURITY SCORE

Certificate Information

Subject
CN=31miljoenkansen.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 27, 2026
Valid Until
August 25, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C1:CF:27:88:0D:BD:EB:AF:07:87:12:15:D5:A6:25:46:C0:79:AA:F6:81:81:34:59:82:0C:57:A4:A5:C5:34:02
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
codenilesolutions.com *.codenilesolutions.com

Other domains in certificate

31miljoenkansen.org *.31miljoenkansen.org
afbvq.mom *.afbvq.mom
animetrip.net *.animetrip.net
aplusdimensions.com *.aplusdimensions.com
ayfqs.mom *.ayfqs.mom
baodao16.com *.baodao16.com
bison-enterprises.com *.bison-enterprises.com *.stats.bison-enterprises.com
cgefp.gdn *.cgefp.gdn
chargipay.zone *.chargipay.zone
cj501.com *.cj501.com
connectlocalhublabs.com *.connectlocalhublabs.com
*.06976fae-6033-4d80-8bca-c495e241f3ab.hackathon.locker *.1d7a1268-5d17-4903-946a-63cd0e39693a.hackathon.locker *.1e0719b8-aa3b-4752-aae1-08d0a00d09f7.hackathon.locker *.50731f95-9c09-4f70-80d7-e7a120688ec4.hackathon.locker *.admin.hackathon.locker *.api.hackathon.locker *.app.hackathon.locker *.assets.hackathon.locker *.backup.hackathon.locker *.bgmqgstg.hackathon.locker *.cf9d7081-1ea5-452b-8514-268061c397e5.hackathon.locker *.dashboard.hackathon.locker *.dev.hackathon.locker hackathon.locker *.hackathon.locker *.mail.hackathon.locker *.mailer.hackathon.locker *.marketing.hackathon.locker *.oqsqzrhukfczb.hackathon.locker *.qa.hackathon.locker *.rhukfczb.hackathon.locker *.secure.hackathon.locker *.staging.hackathon.locker *.stg.hackathon.locker *.uat.hackathon.locker *.v1.hackathon.locker *.v2.hackathon.locker *.web.hackathon.locker *.www.hackathon.locker
wbictscwa.com *.wbictscwa.com *.ww25.wbictscwa.com
*.20d008ab-1e98-4c7e-8af0-e41a8e323383.zk-999.tech *.2264e0fd-82f4-495a-901d-76511db5a688.zk-999.tech *.aging.zk-999.tech *.api.zk-999.tech *.app.zk-999.tech *.assets.zk-999.tech *.b.zk-999.tech *.backup.zk-999.tech *.cure.zk-999.tech *.dashboard.zk-999.tech *.dbff6ee5-0fdd-472b-9af6-60f90bf6314e.zk-999.tech *.demo.zk-999.tech *.dev.zk-999.tech *.g.zk-999.tech *.gitlab.zk-999.tech *.l63utn.zk-999.tech *.mail.zk-999.tech *.mlvzrapi.zk-999.tech *.nwniemailer.zk-999.tech *.pagesqa.zk-999.tech *.qa.zk-999.tech *.secure.zk-999.tech *.staging.zk-999.tech *.stg.zk-999.tech *.test.zk-999.tech *.testing.zk-999.tech *.uewybhcs.zk-999.tech *.v1.zk-999.tech *.v2.zk-999.tech *.web.zk-999.tech *.www.zk-999.tech zk-999.tech *.zk-999.tech