Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=clubbe.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CD:92:DD:D6:9F:6C:50:AB:A6:13:59:B5:62:FD:D5:C3:A4:E3:A7:A7:F8:95:A0:1B:7C:21:07:B8:92:24:5D:DF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
hampeh.com
*.hampeh.com
*.fw.hampeh.com
*.gateway.hampeh.com
*.sitemap.hampeh.com
*.uthm.hampeh.com
*.vpn.hampeh.com
buscalos.com
*.buscalos.com
*.ww11.buscalos.com
chorlton.com
*.chorlton.com
*.portal.chorlton.com
*.acceptatie.clubbe.com
*.authsmtp.clubbe.com
clubbe.com
*.clubbe.com
*.ww17.clubbe.com
*.activesync.dhe.com.pl
*.autodiscover.dhe.com.pl
*.cas.dhe.com.pl
*.correo.dhe.com.pl
*.dev.dhe.com.pl
dhe.com.pl
*.dhe.com.pl
*.eas.dhe.com.pl
*.email.dhe.com.pl
*.mail.dhe.com.pl
*.mail1.dhe.com.pl
*.mail2.dhe.com.pl
*.mobile.dhe.com.pl
*.mymail.dhe.com.pl
*.outlook.dhe.com.pl
*.owa.dhe.com.pl
*.remote.dhe.com.pl
*.sitemap.dhe.com.pl
*.sitemaps.dhe.com.pl
*.staging.dhe.com.pl
*.sync.dhe.com.pl
*.wp.dhe.com.pl
*.www.dhe.com.pl
*.avito.fluid3.com
*.blablacar.fluid3.com
fluid3.com
*.fluid3.com
*.imap.fluid3.com
*.sitemap.fluid3.com
*.sitemaps.fluid3.com
*.ww16.fluid3.com
*.app.keyinsuranceagency.com
keyinsuranceagency.com
*.keyinsuranceagency.com
lamie.com
*.lamie.com
*.mail.lamie.com
*.demo.myfreetaxs.com
*.dev.myfreetaxs.com
*.hostmaster.myfreetaxs.com
myfreetaxs.com
*.myfreetaxs.com
*.vpn.myfreetaxs.com
*.admin.pompa138honda.com
pompa138honda.com
*.pompa138honda.com
*.construccionlivianasteelframe.shopyone.co
*.guiasdemanejo.shopyone.co
*.maxiface.shopyone.co
shopyone.co
*.shopyone.co
*.shopypet.shopyone.co
*.steel-frame.shopyone.co
*.steel-frames.shopyone.co
*.steelframecolombia.shopyone.co
*.steelframecursos.shopyone.co
*.sitemap.syncphotos.com
syncphotos.com
*.syncphotos.com
*.0ve.umw.net
*.1a.umw.net
*.pukmehostmaster.umw.net
umw.net
*.umw.net
*.ww16.umw.net
xnlqm.co
*.xnlqm.co
ydqujx.pro
*.ydqujx.pro
znwdh15.xyz
*.znwdh15.xyz
Other domains in certificate