Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=aazz.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 31, 2026
Valid Until
May 01, 2026
80 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
59:50:5E:66:21:71:48:1D:D6:78:87:0C:1F:14:33:BA:39:69:6A:92:7C:E4:BC:80:24:A2:1B:96:62:AE:D9:9A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
jebran.com
*.jebran.com
*.client.jebran.com
2raw.com
*.2raw.com
*.rdp.2raw.com
*.rdweb.2raw.com
aazz.xyz
*.aazz.xyz
*.ns1.aazz.xyz
*.ww25.aazz.xyz
afraz.com
*.afraz.com
*.web.afraz.com
batholith.com
*.batholith.com
*.hostmaster.batholith.com
*.anadearmas.celebzone.net
*.ashleygraham.celebzone.net
*.awesome.celebzone.net
*.billieeilish.celebzone.net
*.cardib.celebzone.net
celebzone.net
*.celebzone.net
*.charming.celebzone.net
*.emmawatson.celebzone.net
*.jennaortega.celebzone.net
*.jenniferlawrence.celebzone.net
*.kaleycuoco.celebzone.net
*.kateupton.celebzone.net
*.kendalljenner.celebzone.net
*.kink.celebzone.net
*.mileycyrus.celebzone.net
*.milliebobbybrown.celebzone.net
*.sex.celebzone.net
*.sharp.celebzone.net
*.sydneysweeney.celebzone.net
*.upskirt.celebzone.net
*.willaholland.celebzone.net
vivektutorials.co.in
*.vivektutorials.co.in
*.www.zbk.com.pl
zbk.com.pl
*.zbk.com.pl
digitalabida.com
*.digitalabida.com
fb88.gdn
*.fb88.gdn
*.www.fb88.gdn
genemprendedor.lat
*.genemprendedor.lat
holymusic.in
*.holymusic.in
hwangsik1.com
*.hwangsik1.com
*.ww38.hwangsik1.com
iidservice.net
*.iidservice.net
ledgerliveupdates.com
*.ledgerliveupdates.com
mareen.net
*.mareen.net
*.exchange.mehmetali.com
mehmetali.com
*.mehmetali.com
*.beta.meimberg.com
meimberg.com
*.meimberg.com
*.cc.pgbb.bid
pgbb.bid
*.pgbb.bid
quickcredi.com
*.quickcredi.com
ramjienterprises.in
*.ramjienterprises.in
roestvrij.com
*.roestvrij.com
*.webvpn.roestvrij.com
rojewski.com
*.rojewski.com
*.sitemap.rojewski.com
*.ssl.rojewski.com
*.portal.rotular.com
rotular.com
*.rotular.com
sinar777.org
*.sinar777.org
*.sitemap.sinar777.org
upperroombd.com
*.upperroombd.com
Other domains in certificate