Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=handmadecardsbykd.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
March 26, 2026
Valid Until
June 24, 2026
45 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
45:D8:32:59:CA:26:27:80:61:31:4C:58:75:DC:F8:05:0D:6C:D3:22:B0:92:55:D5:2B:3C:CC:B1:2E:E5:2C:A7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
greatdeepbrewing.com
*.greatdeepbrewing.com
*.ask.greatdeepbrewing.com
affidavitservice.com.au
*.affidavitservice.com.au
arthillmazda.com
*.arthillmazda.com
*.ww1.arthillmazda.com
cafe-magnet.info
*.cafe-magnet.info
compasscourse.com
*.compasscourse.com
*.forum.compasscourse.com
en-eclaireur.com
*.en-eclaireur.com
facialhairremoval.com
*.facialhairremoval.com
*.random.facialhairremoval.com
feebytest.eu
*.feebytest.eu
*.familysearch.findagrave.au
findagrave.au
*.findagrave.au
*.gov.findagrave.au
*.ww38.findagrave.au
flightwatch.com.au
*.flightwatch.com.au
*.ww38.flightwatch.com.au
*.www.flightwatch.com.au
*.flixdriver.flxbus.com
flxbus.com
*.flxbus.com
*.hostmaster.flxbus.com
freizei.de
*.freizei.de
goldburst.com
*.goldburst.com
*.random.goldburst.com
*.cardsbykd.handmadecardsbykd.co.uk
handmadecardsbykd.co.uk
*.handmadecardsbykd.co.uk
*.newsite.handmadecardsbykd.co.uk
idolbet.com
*.idolbet.com
javacript.de
*.javacript.de
*.admin.kayoclinic.co.uk
*.ftp.kayoclinic.co.uk
kayoclinic.co.uk
*.kayoclinic.co.uk
*.mail.kayoclinic.co.uk
kenyonroofing.co.uk
*.kenyonroofing.co.uk
lancaster-roofing.co.uk
*.lancaster-roofing.co.uk
littlebuddhayonkers.com
*.littlebuddhayonkers.com
loancalculator.co.nz
*.loancalculator.co.nz
logincoloniallife.com
*.logincoloniallife.com
lyric.com.au
*.lyric.com.au
mnvproductions.at
*.mnvproductions.at
nonnenkleidung.de
*.nonnenkleidung.de
ohezpass.com
*.ohezpass.com
*.hostmaster.pmypremiercreditcard.com
pmypremiercreditcard.com
*.pmypremiercreditcard.com
*.www.pmypremiercreditcard.com
resmedair.com
*.resmedair.com
sahipub.com
*.sahipub.com
*.random.seomelb.com.au
seomelb.com.au
*.seomelb.com.au
*.ww25.seomelb.com.au
*.random.tfv.au
tfv.au
*.tfv.au
tollspaybymailny.com
*.tollspaybymailny.com
*.website.zzzttt41.com
zzzttt41.com
*.zzzttt41.com
Other domains in certificate