Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=sabil.io
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 02, 2026
Valid Until
July 31, 2026 86 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
45:06:2E:5F:83:18:0D:8E:7A:B2:E8:01:E8:6A:E8:B9:BE:2B:75:B1:D5:1D:19:43:A7:90:25:57:DF:FB:B4:2F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
jefflebars.com *.jefflebars.com

Other domains in certificate

altieri.it *.altieri.it *.b.altieri.it *.bb.altieri.it *.giann.altieri.it *.gianni.altieri.it *.marc.altieri.it *.www.altieri.it
cryptoteacher.info *.cryptoteacher.info *.cryptoteacherxzy.cryptoteacher.info *.getgiftcard.cryptoteacher.info *.giftcards4fan.cryptoteacher.info
designsinwools.com *.designsinwools.com
*.09ad5cc5-3ee8-4a2d-bb5f-9a0782121e90.dodosan.info *.admin.dodosan.info *.dev.dodosan.info dodosan.info *.dodosan.info *.dqfxismtp.dodosan.info *.gnxvvapp.dodosan.info *.py0jax.dodosan.info
*.app.dtost.vip dtost.vip *.dtost.vip *.ww38.dtost.vip
*.api.elanthiaonline.tech *.backup.elanthiaonline.tech elanthiaonline.tech *.elanthiaonline.tech *.uat.elanthiaonline.tech
ilovehairextensions.co.uk *.ilovehairextensions.co.uk
ingoshealthylife.be *.ingoshealthylife.be
*.1.lord-novinki.online lord-novinki.online *.lord-novinki.online
*.7e4f5413-dddb-461d-9935-accd7a4775aa.manif3st.live *.admin.manif3st.live *.dev.manif3st.live *.hostmaster.manif3st.live *.hotfix.manif3st.live *.m.manif3st.live manif3st.live *.manif3st.live
*.map.mttqyoot.sbs mttqyoot.sbs *.mttqyoot.sbs *.tmvqs.mttqyoot.sbs *.xn--uv2au31a.mttqyoot.sbs *.xn--uvaua.mttqyoot.sbs
pijaneu.website *.pijaneu.website
*.checkout.sabil.io *.dashboard.sabil.io *.docs.sabil.io *.email.sabil.io sabil.io *.sabil.io *.ww.sabil.io
saints-gym.co.uk *.saints-gym.co.uk
*.banyuwangi.skck.online *.jatim.skck.online *.malang.skck.online *.polrespasuruan.skck.online *.polrespasuruankota.skck.online skck.online *.skck.online *.trenggalek.skck.online
strape.io *.strape.io
vuelos-encontrar.life *.vuelos-encontrar.life *.ww25.vuelos-encontrar.life
*.ebsgoldenharvest.windridgebooksofvt.com *.hostmaster.windridgebooksofvt.com windridgebooksofvt.com *.windridgebooksofvt.com *.ww38.windridgebooksofvt.com *.www.windridgebooksofvt.com
*.fm0vug.xn--knig-5qa.info *.gitlab.xn--knig-5qa.info *.wildcard.xn--knig-5qa.info xn--knig-5qa.info *.xn--knig-5qa.info