Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=blogcasalairfryer.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 30, 2026
Valid Until
July 29, 2026 77 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
69:24:82:CB:D7:7B:34:A0:25:D3:11:8C:51:C1:8C:27:21:F6:31:79:2F:BD:61:43:F8:E2:98:FE:06:D6:3D:55
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
lessontag.com *.lessontag.com *.sitemap.lessontag.com

Other domains in certificate

assisted-senior-living-friend-143.sbs *.assisted-senior-living-friend-143.sbs
australianstockexchanges.com.au *.australianstockexchanges.com.au
blogcasalairfryer.com *.blogcasalairfryer.com *.testing.blogcasalairfryer.com *.ww25.blogcasalairfryer.com *.ww38.blogcasalairfryer.com
*.app.brownfamilysc.info brownfamilysc.info *.brownfamilysc.info *.dev.brownfamilysc.info *.marketing.brownfamilysc.info *.stg.brownfamilysc.info *.umcngjof.brownfamilysc.info
*.a.chiacorps.com chiacorps.com *.chiacorps.com
emly.studio *.emly.studio *.ww38.emly.studio *.www.emly.studio
*.app.ferrarichat.club ferrarichat.club *.ferrarichat.club *.ww38.ferrarichat.club *.wwww.ferrarichat.club
gokken138.bet *.gokken138.bet
kascia.it *.kascia.it
khmer7hd.club *.khmer7hd.club *.www.khmer7hd.club
marge-trinational.eu *.marge-trinational.eu
*.cloudinary.meetadentist.com *.d09e0563-957f-4ecd-bf97-61f2ecfff12f.meetadentist.com meetadentist.com *.meetadentist.com
newvirginiahomes.com *.newvirginiahomes.com *.play.newvirginiahomes.com *.poczta.newvirginiahomes.com *.pool.newvirginiahomes.com
*.dev.obchodni.com *.nkxspssl.obchodni.com obchodni.com *.obchodni.com *.random.obchodni.com *.sitemap.obchodni.com *.tickets.obchodni.com *.users.obchodni.com *.ww16.obchodni.com
*.dev.rubies.it *.hostmaster.rubies.it rubies.it *.rubies.it *.staging.rubies.it *.superset.rubies.it
*.chart.wadagni.com *.viz.wadagni.com wadagni.com *.wadagni.com *.www.wadagni.com
*.20olo.wedonhisdhiltew.info *.dtxsp.wedonhisdhiltew.info *.eoggp.wedonhisdhiltew.info *.filzz.wedonhisdhiltew.info *.hlsic.wedonhisdhiltew.info *.hzhsk.wedonhisdhiltew.info *.iojex.wedonhisdhiltew.info *.nmppm.wedonhisdhiltew.info *.rqwxv.wedonhisdhiltew.info *.tqhnl.wedonhisdhiltew.info *.twiqv.wedonhisdhiltew.info *.uzdlp.wedonhisdhiltew.info *.vmffz.wedonhisdhiltew.info *.vnmsv.wedonhisdhiltew.info *.vvowj.wedonhisdhiltew.info wedonhisdhiltew.info *.wedonhisdhiltew.info *.xkuzm.wedonhisdhiltew.info *.youxt.wedonhisdhiltew.info *.zjxeq.wedonhisdhiltew.info