Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=comedy-gallery.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 25, 2026
Valid Until
July 24, 2026
36 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1C:2D:C2:64:8F:D6:D9:42:84:7F:4C:76:51:2A:1C:0E:8A:C6:CD:DE:AE:BA:80:5E:02:46:7A:F4:E6:2F:EF:34
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
grignaschi.com
*.grignaschi.com
*.api.grignaschi.com
*.intelligence.grignaschi.com
avalon-bathrooms.co.uk
*.avalon-bathrooms.co.uk
*.random.avalon-bathrooms.co.uk
*.ww38.avalon-bathrooms.co.uk
*.autodiscover.bionoten.com
bionoten.com
*.bionoten.com
*.mysql10.bionoten.com
calma.bet
*.calma.bet
*.api.cattle.insure
*.backup.cattle.insure
cattle.insure
*.cattle.insure
*.dashboard.cattle.insure
*.dev.cattle.insure
*.hostmaster.cattle.insure
*.mta-sts.cattle.insure
*.secure.cattle.insure
*.stg.cattle.insure
*.uat.cattle.insure
*.v2.cattle.insure
*.web.cattle.insure
*.authsmtp.comedy-gallery.com
comedy-gallery.com
*.comedy-gallery.com
*.posta.comedy-gallery.com
*.trytvout.comedy-gallery.com
*.vpn.comedy-gallery.com
*.www.comedy-gallery.com
*.fcpd.fcpd.net
fcpd.net
*.fcpd.net
*.hostmaster.fcpd.net
*.m.fcpd.net
*.www.fcpd.net
lakehillstexas.com
*.lakehillstexas.com
lawlyerly.com
*.lawlyerly.com
*.vdoi.lawlyerly.com
mrjuandafulhandsoflove.com
*.mrjuandafulhandsoflove.com
*.blog.nagarasensha.com
nagarasensha.com
*.nagarasensha.com
*.shop.nagarasensha.com
*.api.organotebook.com
*.dev.organotebook.com
*.hostmaster.organotebook.com
organotebook.com
*.organotebook.com
*.www.organotebook.com
suscof.com
*.suscof.com
*.www.suscof.com
*.api.tantor.io
*.apiz.tantor.io
*.app.tantor.io
*.cred-dev.tantor.io
*.darch-dev.tantor.io
*.keycloak.tantor.io
*.login.tantor.io
*.monitoring.tantor.io
tantor.io
*.tantor.io
*.ui.tantor.io
un2scn.shop
*.un2scn.shop
uu-gg.ink
*.uu-gg.ink
*.ww4.uu-gg.ink
*.ww5.uu-gg.ink
*.www.uu-gg.ink
*.m.xn--j6w007c4ghvlh.com
*.www.xn--j6w007c4ghvlh.com
xn--j6w007c4ghvlh.com
*.xn--j6w007c4ghvlh.com
*.shop.xn--kpuq7f0zat20i.com
xn--kpuq7f0zat20i.com
*.xn--kpuq7f0zat20i.com
*.hostmaster.xn--yhqy36ksog.com
*.www.xn--yhqy36ksog.com
xn--yhqy36ksog.com
*.xn--yhqy36ksog.com
Other domains in certificate