Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=etovo.sbs
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 10, 2026
Valid Until
May 11, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:A2:0D:33:B6:B3:FB:48:6C:D8:26:B3:00:D7:74:FD:62:45:37:71:B3:8C:B6:54:BF:40:11:B6:96:A9:56:DD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
sjyoon.tech
*.sjyoon.tech
etovo.sbs
*.etovo.sbs
eufmxj.cc
*.eufmxj.cc
fhiewmf.vip
*.fhiewmf.vip
freshfood.love
*.freshfood.love
glicemiabaixa.fun
*.glicemiabaixa.fun
gtrsuite.net
*.gtrsuite.net
gzxinghe.com
*.gzxinghe.com
hkytuha594.vip
*.hkytuha594.vip
home-improvement-mtg-usa-0208.click
*.home-improvement-mtg-usa-0208.click
houduanappdtxiazaiyuming17.com
*.houduanappdtxiazaiyuming17.com
humanoidgene.com
*.humanoidgene.com
hyc97155.cc
*.hyc97155.cc
jindmall.com
*.jindmall.com
jkfdjn.mobi
*.jkfdjn.mobi
joinjudeluxe.business
*.joinjudeluxe.business
liking.work
*.liking.work
m345.my
*.m345.my
manutention.it
*.manutention.it
maranoticino.com
*.maranoticino.com
masnaghi.com
*.masnaghi.com
minenfts.com
*.minenfts.com
moorelife.com
*.moorelife.com
mpbff.gdn
*.mpbff.gdn
mutiara4d.fun
*.mutiara4d.fun
nenkarn.com
*.nenkarn.com
oksvip.app
*.oksvip.app
onlinesuperannuation.com
*.onlinesuperannuation.com
paragon-foundation.org
*.paragon-foundation.org
pbksgncx.xyz
*.pbksgncx.xyz
pdpxd.gdn
*.pdpxd.gdn
pjxuf.loan
*.pjxuf.loan
pwwcu.gdn
*.pwwcu.gdn
qewdf.me
*.qewdf.me
rehabilitation-center-th-0207.click
*.rehabilitation-center-th-0207.click
reteazienda.it
*.reteazienda.it
revitalizefitlife.run
*.revitalizefitlife.run
richmedia-server.com
*.richmedia-server.com
sdqqm.gdn
*.sdqqm.gdn
sf70018.cc
*.sf70018.cc
siddhimantra.online
*.siddhimantra.online
smilebrightly.online
*.smilebrightly.online
smilehouse2310.tokyo
*.smilehouse2310.tokyo
sourjealousyauto.com
*.sourjealousyauto.com
sport-vexor.com
*.sport-vexor.com
Other domains in certificate