76/100 SECURITY SCORE

Certificate Information

Subject
CN=cnbclive.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 12, 2026
Valid Until
September 10, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D1:EE:F5:1B:67:17:47:6B:EA:6E:D4:A9:8F:C1:8B:FB:61:31:A5:3A:FF:38:18:86:E2:AA:06:07:C4:92:DD:74
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
advancedmdd.com *.advancedmdd.com *.demo.advancedmdd.com *.kf.advancedmdd.com *.test.advancedmdd.com

Other domains in certificate

1xstavka.bet *.1xstavka.bet *.app.1xstavka.bet *.dashboard.1xstavka.bet *.rdycihr.1xstavka.bet *.test.1xstavka.bet *.v2.1xstavka.bet
*.16.4345.com *.42.4345.com 4345.com *.4345.com *.9.4345.com *.djeu.4345.com *.ee.4345.com *.vlu.4345.com *.ww.4345.com *.zm.4345.com
*.alpha.cheapcaribbean.co *.beta.cheapcaribbean.co *.booking.cheapcaribbean.co cheapcaribbean.co *.cheapcaribbean.co *.ci.cheapcaribbean.co *.comune.cheapcaribbean.co *.cruise.cheapcaribbean.co *.dev-jenkins.cheapcaribbean.co *.development.cheapcaribbean.co *.e.cheapcaribbean.co *.eml.cheapcaribbean.co *.jenkins.cheapcaribbean.co *.pipeline.cheapcaribbean.co *.random.cheapcaribbean.co *.sandbox.cheapcaribbean.co *.vmail.cheapcaribbean.co *.ww25.cheapcaribbean.co *.ww38.cheapcaribbean.co *.www.cheapcaribbean.co
*.admin.cnbclive.com cnbclive.com *.cnbclive.com
*.b54zj.hotok.xyz hotok.xyz *.hotok.xyz *.l7nqb.hotok.xyz *.members.hotok.xyz *.ques8.hotok.xyz *.ygndccxie3.hotok.xyz *.z3dl1.hotok.xyz
*.dashboards.joust.it *.dashs.joust.it *.hostmaster.joust.it joust.it *.joust.it *.stats.joust.it *.workmanatdailywages.joust.it
*.but.lotta.fish lotta.fish *.lotta.fish *.sitemaps.lotta.fish *.vpn.lotta.fish *.www.lotta.fish
*.admin.masciagoprimo.com masciagoprimo.com *.masciagoprimo.com
*.admin.saka.it *.backend.saka.it *.hostmaster.saka.it *.mx.saka.it saka.it *.saka.it *.status.saka.it *.superset.saka.it
*.bellaspa.semore.com *.campfosterpasspffice.semore.com *.ellethaitherapeutic.semore.com *.ghscarebooking.semore.com *.kiwichelledonails.semore.com *.naibywen.semore.com *.naturalrefine.semore.com *.recceu.semore.com semore.com *.semore.com
thestylinglounge.co.uk *.thestylinglounge.co.uk