Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=yourtotalrewards.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 10, 2026
Valid Until
April 10, 2026
48 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:1F:CD:55:4E:12:32:32:31:F6:75:DE:5D:4D:F1:BD:F6:E2:C2:F6:2D:20:1C:8E:5B:08:59:60:9D:24:40:9E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
jipg.com
*.jipg.com
*.cdn.jipg.com
*.cooley-yeah.jipg.com
*.latinamerica.jipg.com
*.mx10.jipg.com
*.ng.jipg.com
*.pool.jipg.com
*.richardson-film.jipg.com
*.server22.jipg.com
*.soy.jipg.com
al-amana.net
*.al-amana.net
*.ns1.al-amana.net
*.ns2.al-amana.net
*.www.al-amana.net
booboobootique.com
*.booboobootique.com
*.stage.booboobootique.com
*.staging.booboobootique.com
expecity.com
*.expecity.com
*.ads.lasagra.com
*.beta.lasagra.com
*.blog.lasagra.com
*.board.lasagra.com
*.bugs.lasagra.com
*.dev.lasagra.com
*.insights.lasagra.com
lasagra.com
*.lasagra.com
*.mail.lasagra.com
*.random.lasagra.com
*.sms.lasagra.com
*.uat.lasagra.com
*.us.lasagra.com
*.vertoledo.lasagra.com
*.ww25.lasagra.com
*.ww38.lasagra.com
*.www.lasagra.com
*.anytning.mythilshape.top
*.asmxe.mythilshape.top
*.bmswa.mythilshape.top
*.brnok.mythilshape.top
*.e.mythilshape.top
*.gasma.mythilshape.top
*.gatxr.mythilshape.top
*.gfpio.mythilshape.top
*.lbrzp.mythilshape.top
*.lfenp.mythilshape.top
*.lloiz.mythilshape.top
mythilshape.top
*.mythilshape.top
*.nxejt.mythilshape.top
*.oqpcw.mythilshape.top
*.patak.mythilshape.top
*.qefmp.mythilshape.top
*.qwfuu.mythilshape.top
*.rhpin.mythilshape.top
*.rnmpi.mythilshape.top
*.tqnqt.mythilshape.top
*.ykrvt.mythilshape.top
ponographie.com
*.ponographie.com
*.random.ponographie.com
*.ww38.ponographie.com
*.hostmaster.radio-dukagjini.com
radio-dukagjini.com
*.radio-dukagjini.com
*.w.radio-dukagjini.com
*.ww16.radio-dukagjini.com
*.ww38.radio-dukagjini.com
*.www.radio-dukagjini.com
shs.au
*.shs.au
*.sn.shs.au
*.news.sportingsuperstore.com
*.random.sportingsuperstore.com
sportingsuperstore.com
*.sportingsuperstore.com
sweepstakes.au
*.sweepstakes.au
*.comww1.uouyube.com
*.random.uouyube.com
uouyube.com
*.uouyube.com
*.ww38.yourtotalrewards.co
yourtotalrewards.co
*.yourtotalrewards.co
Other domains in certificate