Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=k590223.cc
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BA:6D:FE:5C:6A:62:1F:6E:9A:81:07:C1:65:77:F9:B1:F1:B7:71:E0:53:82:B5:C0:C8:DB:9B:83:1E:E5:B8:8B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
jskim.com
*.jskim.com
jantungsuster123.com
*.jantungsuster123.com
jazzcollective.net
*.jazzcollective.net
jeminigraycoaching.com
*.jeminigraycoaching.com
jianphone.com
*.jianphone.com
jrav313.com
*.jrav313.com
justicetransportation.com
*.justicetransportation.com
justore.in
*.justore.in
jyinero.click
*.jyinero.click
jzsjkj.com
*.jzsjkj.com
k590223.cc
*.k590223.cc
kaki4d-won.lol
*.kaki4d-won.lol
kakkokaritranslations.com
*.kakkokaritranslations.com
kaluteraathenview.com
*.kaluteraathenview.com
kgler1ubz.buzz
*.kgler1ubz.buzz
khtsghijohyvdjenkhqh.com
*.khtsghijohyvdjenkhqh.com
kidsrun.it
*.kidsrun.it
kliklink-iklan4d.cyou
*.kliklink-iklan4d.cyou
klinkenbergcoffee.com
*.klinkenbergcoffee.com
km3.xyz
*.km3.xyz
koinsilver.vip
*.koinsilver.vip
kpmwa.loan
*.kpmwa.loan
kubet36.vip
*.kubet36.vip
kungfoot.com
*.kungfoot.com
kvji2k.top
*.kvji2k.top
l52rub.com
*.l52rub.com
laskar99.blog
*.laskar99.blog
leonbets-h217.xyz
*.leonbets-h217.xyz
libsay.in
*.libsay.in
lifejuggler.com
*.lifejuggler.com
likecooking.it
*.likecooking.it
livebingo.in
*.livebingo.in
locationmobile.it
*.locationmobile.it
loeilduveilleur.com
*.loeilduveilleur.com
whenwework.xyz
*.whenwework.xyz
windsurfers.it
*.windsurfers.it
wmg-postyfast-5x.top
*.wmg-postyfast-5x.top
workplacehealthservices.com
*.workplacehealthservices.com
wuxiaadccplus.com
*.wuxiaadccplus.com
www4675.top
*.www4675.top
www886z.top
*.www886z.top
x-cited.com
*.x-cited.com
xn--cet23t.com
*.xn--cet23t.com
xn--ekr552fyihdrw.com
*.xn--ekr552fyihdrw.com
xn--uira987a.com
*.xn--uira987a.com
Other domains in certificate