76/100 SECURITY SCORE

Certificate Information

Subject
CN=musikantiga.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 01, 2026
Valid Until
May 02, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
99:DA:A7:C7:A5:D3:3C:46:64:BC:1A:63:25:3F:69:F4:8D:A6:42:3B:8B:6D:BF:34:42:E9:A0:CF:68:2F:05:88
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
geniet.com *.geniet.com *.api.geniet.com

Other domains in certificate

*.aa.accountinline.com accountinline.com *.accountinline.com *.beatbiy.accountinline.com *.beatbuy.accountinline.com *.bedtbut.accountinline.com *.bestbiy.accountinline.com *.bestbut.accountinline.com *.bestbuy.accountinline.com *.besybuy.accountinline.com *.brandsourcecard.accountinline.com *.brestbuy.accountinline.com *.com.accountinline.com *.dillard.accountinline.com *.dillards.accountinline.com *.dillatds.accountinline.com *.dilliards.accountinline.com *.exconmobil.accountinline.com *.exonmobil.accountinline.com *.exxonmobil.accountinline.com *.goodyear.accountinline.com *.homedepotconsumer.accountinline.com *.insights.accountinline.com *.macys.accountinline.com *.meijer.accountinline.com *.meijers.accountinline.com *.officedepotcards.accountinline.com *.prod.accountinline.com *.reporting.accountinline.com *.servicecentral.accountinline.com *.shell.accountinline.com *.sho.accountinline.com *.staplesbusiness.accountinline.com *.sunoco.accountinline.com *.syw.accountinline.com *.tires.accountinline.com *.tscard.accountinline.com *.tsccard.accountinline.com *.wafair.accountinline.com *.wawa.accountinline.com *.wayfair.accountinline.com
berkmans.com *.berkmans.com *.ww38.berkmans.com
*.asa.brinza.com *.autoconfig.brinza.com brinza.com *.brinza.com *.cpanel.brinza.com
*.app.consenttopleasure.com consenttopleasure.com *.consenttopleasure.com *.demo.consenttopleasure.com *.dev.consenttopleasure.com *.kumsthostmaster.consenttopleasure.com *.rd.consenttopleasure.com *.rds.consenttopleasure.com *.rdweb.consenttopleasure.com *.staging.consenttopleasure.com *.www.consenttopleasure.com
*.api.consultaestadomigratorio.com *.app.consultaestadomigratorio.com consultaestadomigratorio.com *.consultaestadomigratorio.com *.notexistsapi.consultaestadomigratorio.com *.nrgiiwildcard.consultaestadomigratorio.com *.owa.consultaestadomigratorio.com *.rd.consultaestadomigratorio.com *.sitemaps.consultaestadomigratorio.com *.wildcard.consultaestadomigratorio.com *.wwww.consultaestadomigratorio.com
*.b1c74373-7046-4e3d-9239-5533a434beb3.deepetf.xyz deepetf.xyz *.deepetf.xyz
*.bat.musikantiga.com *.blog.musikantiga.com musikantiga.com *.musikantiga.com *.office.musikantiga.com *.painel.musikantiga.com *.ww25.musikantiga.com
*.4f59c66a-a881-43a5-8031-8ff43620a3d9.snaplinea.com snaplinea.com *.snaplinea.com
*.intranet.somtam.cafe somtam.cafe *.somtam.cafe