SSL Verification Bypassed

The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.

Reason:

Hostname Mismatch - certificate is issued for *.70.cigers.com, *.77thb.com, *.abzahlungsrechner.de, *.airtalkwiress.com, *.aktfotografie.de, *.allstardriveronline.com, *.anglerbrille.de, *.charitygift.de, *.cigers.com, not for lb-212-228.above.com

73/100 SECURITY SCORE

Certificate Information

Subject
CN=epuli.de
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 29, 2026
Valid Until
April 29, 2026 29 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9A:91:6E:9E:61:38:8A:95:F9:50:C5:C2:64:4A:D5:45:1A:81:FD:BF:30:EC:56:E3:44:5D:EE:C6:22:7C:F0:41
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
77thb.com *.77thb.com
abzahlungsrechner.de *.abzahlungsrechner.de
airtalkwiress.com *.airtalkwiress.com
aktfotografie.de *.aktfotografie.de
allstardriveronline.com *.allstardriveronline.com
anglerbrille.de *.anglerbrille.de
charitygift.de *.charitygift.de
*.70.cigers.com cigers.com *.cigers.com *.kino.cigers.com
dankesbrief.de *.dankesbrief.de
dqs.eu *.dqs.eu
engelssprueche.de *.engelssprueche.de
enzympeeling.de *.enzympeeling.de
epuli.de *.epuli.de
fantasy-geschichten.de *.fantasy-geschichten.de
filmbearbeitungsprogramm.de *.filmbearbeitungsprogramm.de
iauction.de *.iauction.de
insolvenzbekanntnmachungen.de *.insolvenzbekanntnmachungen.de
kuechenrollenhalter.de *.kuechenrollenhalter.de
la-le-lu.de *.la-le-lu.de
pcgarage.au *.pcgarage.au
pcwhiz.au *.pcwhiz.au
prill.it *.prill.it
realmoneygambling.com.au *.realmoneygambling.com.au
schweinehackfleisch.de *.schweinehackfleisch.de
sergiotorres.com *.sergiotorres.com
videodrama.de *.videodrama.de
weihnachtsbaueme.de *.weihnachtsbaueme.de
weihnachtsdecke.de *.weihnachtsdecke.de
whichinsurer.com.au *.whichinsurer.com.au
winx-ausmalbilder.de *.winx-ausmalbilder.de
wwwtarif.de *.wwwtarif.de
xn--fensterflgel-llb.de *.xn--fensterflgel-llb.de
xn--fitnesspdagogik-7kb.de *.xn--fitnesspdagogik-7kb.de
xn--frerienhuser-ncb.de *.xn--frerienhuser-ncb.de
xn--hanfdnger-u9a.de *.xn--hanfdnger-u9a.de
xn--kunsthaarverlngerung-nzb.de *.xn--kunsthaarverlngerung-nzb.de
xn--rosenbrse-57a.de *.xn--rosenbrse-57a.de
xn--rotationsdit-qcb.de *.xn--rotationsdit-qcb.de
xn--rundbogentr-2hb.de *.xn--rundbogentr-2hb.de
xn--schildkrtengehege-6zb.de *.xn--schildkrtengehege-6zb.de
xn--schwippbgen-yfb.de *.xn--schwippbgen-yfb.de
xn--sdafrka-n2a.de *.xn--sdafrka-n2a.de
xn--suchrtsel-z2a.de *.xn--suchrtsel-z2a.de