76/100 SECURITY SCORE

Certificate Information

Subject
CN=ovgzufntaa.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 14, 2026
Valid Until
September 12, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2A:E5:E6:36:D1:1A:14:C7:7B:67:64:41:2B:67:63:80:02:58:10:BD:70:DF:B8:A8:CB:66:DA:16:0E:35:98:7E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
gourmetroast.com *.gourmetroast.com *.admin.gourmetroast.com *.analytics.gourmetroast.com *.backend.gourmetroast.com *.dev.gourmetroast.com *.flowise.gourmetroast.com *.intelligence.gourmetroast.com *.superset.gourmetroast.com *.visual.gourmetroast.com *.ww20.gourmetroast.com *.ww42.gourmetroast.com

Other domains in certificate

*.adrec-chatou.fr.au *.airwhitsunday.fr.au *.alloanglais.fr.au *.alpha-photo.fr.au *.amazon.fr.au *.amicaledesanciensducirad.fr.au *.antidox.fr.au *.asternet.fr.au *.bbox.fr.au *.bk-peinture.fr.au *.bluebella.fr.au *.catinaflat.fr.au *.cc-vire.fr.au *.cottontreetalk.fr.au *.debian.fr.au *.ebay.fr.au *.ecarteblue.fr.au *.ecbleue.fr.au *.envertetcontretous.fr.au *.epiloglaser.fr.au fr.au *.fr.au *.free.fr.au *.go-electrique.fr.au *.gouv.fr.au *.hotmail.fr.au *.lali.fr.au *.lefigaro.fr.au *.lelivrescolaire.fr.au *.leslibraires.fr.au *.live.fr.au *.liveramp.fr.au *.melnotte.fr.au *.nic.fr.au *.oa3sporta3.fr.au *.olightstore.fr.au *.orange.fr.au *.outlook.fr.au *.php.fr.au *.postgrid.fr.au *.protonmail.fr.au *.qip.fr.au *.readanybook.fr.au *.restaurant-le-k.fr.au *.roycecross.fr.au *.seafancy.fr.au *.sequem.fr.au *.service-eblue.fr.au *.signiflow.fr.au *.tajbatiment.fr.au *.tpg.fr.au *.velocitynet.fr.au *.wanadoo.fr.au *.web.fr.au *.weleda.fr.au *.westnet.fr.au *.ww25.fr.au *.yahoo.fr.au *.yardi.fr.au *.zip-clip.fr.au
*.dev.lkdomains.com *.hostmaster.lkdomains.com lkdomains.com *.lkdomains.com *.ww1.lkdomains.com *.ww25.lkdomains.com *.ww38.lkdomains.com *.ww5.lkdomains.com
ovgzufntaa.com *.ovgzufntaa.com
pub777.vip *.pub777.vip
randysautosales.com *.randysautosales.com
tacoselcreador.com *.tacoselcreador.com
traumatherapeuten.de *.traumatherapeuten.de