Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=homedecotop.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CD:BA:B0:D9:B7:F7:DB:8A:45:4D:C0:E9:4E:39:F7:F8:21:16:2B:D6:E9:AC:44:50:B3:07:4F:CB:64:1C:BD:16
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
humanizednet.com
*.humanizednet.com
home-warranty-br-8145.click
*.home-warranty-br-8145.click
homedecotop.com
*.homedecotop.com
homefunding.net
*.homefunding.net
horoscopo-2025.click
*.horoscopo-2025.click
hotpussy1.com
*.hotpussy1.com
housepaintingcompany101504.icu
*.housepaintingcompany101504.icu
hsyipos.com
*.hsyipos.com
hzbkedn.us
*.hzbkedn.us
i-taiji.cn
*.i-taiji.cn
icarrly.com
*.icarrly.com
icsdao.org
*.icsdao.org
idc188terang.xyz
*.idc188terang.xyz
idr77.rent
*.idr77.rent
ihmc759.pro
*.ihmc759.pro
imn.at
*.imn.at
indtous.com
*.indtous.com
industrialzone.it
*.industrialzone.it
indy4.info
*.indy4.info
inspireyourfitness.run
*.inspireyourfitness.run
insteptherapy.com
*.insteptherapy.com
inventory-management-services.click
*.inventory-management-services.click
rgp-x.com
*.rgp-x.com
rivoluzioneenergetica.it
*.rivoluzioneenergetica.it
romeanc.buzz
*.romeanc.buzz
sabq6p.click
*.sabq6p.click
sailshade-moon.one
*.sailshade-moon.one
seattleforddealer.com
*.seattleforddealer.com
shyla.it
*.shyla.it
spatialsnowboarder.com
*.spatialsnowboarder.com
squadraslot.com
*.squadraslot.com
suelo.it
*.suelo.it
thechicagodaily.com
*.thechicagodaily.com
theinfluenceroominformation.com
*.theinfluenceroominformation.com
tuik563.pro
*.tuik563.pro
vip1516kefuhuanyingninyouxiwandekaixin.vip
*.vip1516kefuhuanyingninyouxiwandekaixin.vip
voennikcc9.top
*.voennikcc9.top
weight-loss-injections117269.icu
*.weight-loss-injections117269.icu
xh939.com
*.xh939.com
xnjuq.com
*.xnjuq.com
xyjkp.tv
*.xyjkp.tv
yatirimnokkta.com
*.yatirimnokkta.com
yushan.org
*.yushan.org
ywdeipt558.vip
*.ywdeipt558.vip
yyoov.gdn
*.yyoov.gdn
Other domains in certificate