SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Hostname Mismatch - certificate is issued for *.253a.myswap.vip, *.3a.myswap.vip, *.a.awais.studio, *.admin.happyam.online, *.aguapotable.online, *.apiclassroom.cloudlabs.site, *.app.happyam.online, *.auth.schoolplus.store, *.awais.studio, not for lb-182-252.above.com
Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=cyuu.space
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
November 23, 2025
Valid Until
February 21, 2026
30 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
21:37:DC:2C:81:DC:81:DC:7F:7E:AD:03:55:0C:CA:E3:00:91:1D:EE:E9:C2:CB:32:CC:13:F7:FB:85:F5:C7:B0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
aguapotable.online
*.aguapotable.online
*.hm.aguapotable.online
*.mail.aguapotable.online
*.sitemap.aguapotable.online
*.webmail.aguapotable.online
*.a.awais.studio
awais.studio
*.awais.studio
*.clients.awais.studio
*.editor.awais.studio
*.plugins.awais.studio
*.apiclassroom.cloudlabs.site
cloudlabs.site
*.cloudlabs.site
*.lti-service.cloudlabs.site
*.menu.cloudlabs.site
*.renewal.cloudlabs.site
cyuu.space
*.cyuu.space
*.gs.cyuu.space
*.zi.cyuu.space
desimovies.live
*.desimovies.live
*.ww38.desimovies.live
educo.au
*.educo.au
*.uts.educo.au
*.ww17.educo.au
*.ww38.educo.au
*.admin.happyam.online
*.app.happyam.online
*.c.happyam.online
happyam.online
*.happyam.online
*.i.happyam.online
*.j.happyam.online
*.m.happyam.online
*.maps.happyam.online
*.ranet.happyam.online
*.sitemaps.happyam.online
landmetzgerei-froehlich.de
*.landmetzgerei-froehlich.de
*.shop.landmetzgerei-froehlich.de
*.hcaptcha.leonbet-zerkalo10.xyz
leonbet-zerkalo10.xyz
*.leonbet-zerkalo10.xyz
*.m.leonbet-zerkalo10.xyz
*.c6qbi.lolcorp.online
lolcorp.online
*.lolcorp.online
mahavastushruti.com
*.mahavastushruti.com
*.ww25.mahavastushruti.com
*.dev.mercilessgaming.xyz
mercilessgaming.xyz
*.mercilessgaming.xyz
*.website.mercilessgaming.xyz
*.ww25.mercilessgaming.xyz
*.253a.myswap.vip
*.3a.myswap.vip
*.docs.myswap.vip
myswap.vip
*.myswap.vip
*.ww.myswap.vip
*.auth.schoolplus.store
*.courses.schoolplus.store
schoolplus.store
*.schoolplus.store
*.pat.statefees.online
statefees.online
*.statefees.online
taosewu.site
*.taosewu.site
*.ww12.taosewu.site
*.owa.theoldhousehotel.co.uk
theoldhousehotel.co.uk
*.theoldhousehotel.co.uk
*.m.tiktokincome.online
tiktokincome.online
*.tiktokincome.online
turtle.academy
*.turtle.academy
*.ww38.turtle.academy
vidtower.io
*.vidtower.io
*.ww25.vidtower.io
*.ww38.vidtower.io
waterheaterrepair442150.icu
*.waterheaterrepair442150.icu