76/100 SECURITY SCORE

Certificate Information

Subject
CN=casacandles.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 13, 2026
Valid Until
August 11, 2026 66 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B7:CC:5A:70:33:E5:FB:FB:86:28:8F:58:54:0C:79:06:37:3A:E2:07:9A:12:0B:52:70:FF:88:58:4F:43:73:57
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ipmsolutionsafrica.com *.ipmsolutionsafrica.com *.com.ipmsolutionsafrica.com

Other domains in certificate

46384.mobi *.46384.mobi
4777b.club *.4777b.club
556688jj.cc *.556688jj.cc
aero-glit.pro *.aero-glit.pro
bassic.ca *.bassic.ca
beatthecourt.com *.beatthecourt.com *.yourprivategoldmine.beatthecourt.com
bgw5yrs.top *.bgw5yrs.top
bigplateng.com *.bigplateng.com
bilgicasa.info *.bilgicasa.info
bilgidepo.info *.bilgidepo.info
box-taping-machine-c93.click *.box-taping-machine-c93.click
casacandles.co.uk *.casacandles.co.uk *.cpcalendars.casacandles.co.uk
desgas.com *.desgas.com *.qa.desgas.com *.random.desgas.com *.remote.desgas.com *.rustore.desgas.com *.webmail.desgas.com *.ww1.desgas.com *.ww25.desgas.com *.ww38.desgas.com *.www.desgas.com
*.admin.designingthefrontier.com designingthefrontier.com *.designingthefrontier.com *.test.designingthefrontier.com
joyoo.live *.joyoo.live
loopnwt.com *.loopnwt.com *.ww38.loopnwt.com
lossaucescalafatehotel.com *.lossaucescalafatehotel.com *.teststable.lossaucescalafatehotel.com
manhxuongkhop.site *.manhxuongkhop.site *.www.manhxuongkhop.site
*.admin.ona-db.xyz *.ai.ona-db.xyz *.api.ona-db.xyz *.assets.ona-db.xyz *.c1kpafhzhkdxxo2r.ona-db.xyz *.cpanel.ona-db.xyz *.demo.ona-db.xyz *.dev.ona-db.xyz *.hostmaster.ona-db.xyz *.m.ona-db.xyz *.mail.ona-db.xyz *.mtepqcpanel.ona-db.xyz ona-db.xyz *.ona-db.xyz *.sitemap.ona-db.xyz *.test.ona-db.xyz *.webdisk.ona-db.xyz *.webmail.ona-db.xyz *.wildcard.ona-db.xyz *.ww1.ona-db.xyz *.ww16.ona-db.xyz *.ww2.ona-db.xyz *.ww3.ona-db.xyz *.ww38.ona-db.xyz *.ww6.ona-db.xyz
*.app.scalamobile.com *.hostmaster.scalamobile.com *.mail.scalamobile.com *.mail2.scalamobile.com scalamobile.com *.scalamobile.com
shoptiktok-shop.info *.shoptiktok-shop.info
slotfit.com *.slotfit.com