76/100 SECURITY SCORE

Certificate Information

Subject
CN=shivtr.blue
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FC:E2:1B:3F:2C:14:B0:75:08:80:60:DC:CE:27:27:B5:4E:B9:93:36:76:67:F2:DF:F5:FB:C8:DE:32:05:AC:2C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
millerresourcegroup.com *.millerresourcegroup.com *.inst.millerresourcegroup.com

Other domains in certificate

abcdefg1.com *.abcdefg1.com
alparslan.com *.alparslan.com *.com.alparslan.com *.m.alparslan.com *.ww35.alparslan.com *.www.alparslan.com
baby-spende.de *.baby-spende.de
*.5jsd7.botuna55b.top *.8joac.botuna55b.top botuna55b.top *.botuna55b.top *.d.botuna55b.top *.fp99n5.botuna55b.top *.jxc88.botuna55b.top *.kwid9.botuna55b.top *.l2aa8.botuna55b.top *.nan1j.botuna55b.top *.qk6fu.botuna55b.top *.rnyzj.botuna55b.top *.tzygd.botuna55b.top *.vwwsifp99n5.botuna55b.top
*.bk.citizenmeds.co citizenmeds.co *.citizenmeds.co
daluumngqosvhfg.cc *.daluumngqosvhfg.cc
e-bikes-night-551.sbs *.e-bikes-night-551.sbs
envoler.com *.envoler.com *.forum.envoler.com
foundationrepaircali.de *.foundationrepaircali.de
fullware.io *.fullware.io *.mail.fullware.io *.www.fullware.io
gourmetdetective.com *.gourmetdetective.com
*.app.harrahscash.buzz harrahscash.buzz *.harrahscash.buzz *.m.harrahscash.buzz
kasinatechnology.com *.kasinatechnology.com
kbp67.icu *.kbp67.icu
leisurelymicrophone.com *.leisurelymicrophone.com *.random.leisurelymicrophone.com
mckaytablepads.com *.mckaytablepads.com
ohmyflirts.life *.ohmyflirts.life *.ww1.ohmyflirts.life
*.access.onpointconsultants.com *.beta.onpointconsultants.com *.m.onpointconsultants.com onpointconsultants.com *.onpointconsultants.com *.rdp.onpointconsultants.com *.rlrombackup.onpointconsultants.com *.sitemap.onpointconsultants.com
pqd29.icu *.pqd29.icu
profetaanamaldonado.org *.profetaanamaldonado.org
*.ad-astra.shivtr.blue *.eternity.shivtr.blue shivtr.blue *.shivtr.blue
*.comune.slopegame-online.io slopegame-online.io *.slopegame-online.io
thgwdmqejzh.cc *.thgwdmqejzh.cc
tr-pinup.online *.tr-pinup.online *.ww38.tr-pinup.online
usdtdailyminer.com *.usdtdailyminer.com *.ww38.usdtdailyminer.com
whitemountainrentals.com *.whitemountainrentals.com