Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=nordsdrom.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AE:2E:E7:44:A4:E1:C4:82:6F:84:11:4B:43:90:02:85:7D:B2:1D:A8:39:52:3F:74:4E:11:48:50:0A:4E:62:77
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
htmlnerd.net *.htmlnerd.net

Other domains in certificate

09612.co *.09612.co
360304.vip *.360304.vip
5208414978.cfd *.5208414978.cfd
b813dq.cyou *.b813dq.cyou
beeteam.co *.beeteam.co
bombsslot.vip *.bombsslot.vip
brightrally.co *.brightrally.co
brushartworks.click *.brushartworks.click
brushcolor.digital *.brushcolor.digital *.tl8g1v.brushcolor.digital
bvxj71ox.cc *.bvxj71ox.cc
*.ca.canadalpg.com canadalpg.com *.canadalpg.com *.support.canadalpg.com
casino-champion-online-mirror.pw *.casino-champion-online-mirror.pw
formbase.co *.formbase.co
hosanna-garments.com *.hosanna-garments.com
hotcoupons.top *.hotcoupons.top
jadkirchhengineering.com *.jadkirchhengineering.com
kvt0g.vip *.kvt0g.vip
nepalidarpan.com *.nepalidarpan.com
netfx-pay.com *.netfx-pay.com
*.joliette.nexion.biz nexion.biz *.nexion.biz *.web3.nexion.biz
nicecat.xyz *.nicecat.xyz
nordsdrom.com *.nordsdrom.com *.ww1.nordsdrom.com
novelriverwalk.com *.novelriverwalk.com
nuvexa.club *.nuvexa.club
online-loans-3r8z4z5n7q3.sbs *.online-loans-3r8z4z5n7q3.sbs
pewgjka1072.vip *.pewgjka1072.vip
phna2k.sbs *.phna2k.sbs
precisionboards.com *.precisionboards.com
prestigeoro.com *.prestigeoro.com
*.poborg.prideofbaltimorechorus.com prideofbaltimorechorus.com *.prideofbaltimorechorus.com *.www.prideofbaltimorechorus.com
*.img1-fg.rsong.com rsong.com *.rsong.com *.secure.rsong.com
thinkmoscreative.biz *.thinkmoscreative.biz
tjoay.gdn *.tjoay.gdn
topexpedientstudio.co *.topexpedientstudio.co
utopie.co *.utopie.co
wealthwave.trade *.wealthwave.trade
wikiglobalcourier.com *.wikiglobalcourier.com
wilhelminacharisma.net *.wilhelminacharisma.net
winwinbusinesssolutions.com *.winwinbusinesssolutions.com