76/100 SECURITY SCORE

Certificate Information

Subject
CN=osthaus.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C0:68:CD:5E:98:1D:02:E1:B8:C6:E9:2F:C2:69:D0:62:8B:A6:21:3F:95:55:EA:2D:80:4A:44:BB:55:1A:93:C0
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
sehmbi.com *.sehmbi.com *.sitemap.sehmbi.com

Other domains in certificate

*.app.escuelanacional.com *.backup.escuelanacional.com escuelanacional.com *.escuelanacional.com
goldi95.com *.goldi95.com *.www.goldi95.com
hjry.com *.hjry.com *.owa.hjry.com *.ww1.hjry.com *.ww38.hjry.com
*.css.konibetja.com konibetja.com *.konibetja.com
*.access.osthaus.com *.auth.osthaus.com osthaus.com *.osthaus.com
*.bokep.pusatmovie21.xyz *.cpcalendars.pusatmovie21.xyz *.hd.pusatmovie21.xyz *.jav.pusatmovie21.xyz *.klik.pusatmovie21.xyz *.pm.pusatmovie21.xyz *.ps.pusatmovie21.xyz pusatmovie21.xyz *.pusatmovie21.xyz *.random.pusatmovie21.xyz *.ww1.pusatmovie21.xyz *.ww2.pusatmovie21.xyz *.ww25.pusatmovie21.xyz *.ww3.pusatmovie21.xyz *.ww38.pusatmovie21.xyz *.ww4.pusatmovie21.xyz *.ww5.pusatmovie21.xyz *.ww6.pusatmovie21.xyz *.ww7.pusatmovie21.xyz *.ww8.pusatmovie21.xyz
seigioco.com *.seigioco.com *.superset.seigioco.com
ubriacarsi.com *.ubriacarsi.com
ueerj.bid *.ueerj.bid
ufficiomutui.com *.ufficiomutui.com
ufficioreclami.com *.ufficioreclami.com
uhdcq.pro *.uhdcq.pro
ulfqww.bid *.ulfqww.bid
ulglbc.pro *.ulglbc.pro
undeceivably.com *.undeceivably.com
undermeaning.com *.undermeaning.com
unitedhealthcare.net *.unitedhealthcare.net
unpiteousness.com *.unpiteousness.com
uuwyqt.top *.uuwyqt.top
vacationworks.com *.vacationworks.com
villalozano.com *.villalozano.com
vittoealloggio.com *.vittoealloggio.com
vx2.net *.vx2.net
wirelesssolarkeyboard.com *.wirelesssolarkeyboard.com
wizflex.blog *.wizflex.blog
xiancheng.cc *.xiancheng.cc
yatunink.com *.yatunink.com
yjyh6.yachts *.yjyh6.yachts
ziongpt.com *.ziongpt.com