Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=ykwa6z.cn
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 25, 2026
Valid Until
August 23, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A9:F8:B7:97:67:BB:59:10:14:EB:36:15:F7:3C:EE:73:A7:21:F1:7D:5D:D9:3B:3D:CA:43:46:09:E7:89:78:E3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
lexgroup.co *.lexgroup.co

Other domains in certificate

*.4e02809a-df5b-4b32-bc01-7c234d67866c.917878.vip 917878.vip *.917878.vip *.94f84a6a-2468-44f2-80cd-7a11a5c3a9f5.917878.vip *.api.917878.vip *.app.917878.vip *.assets.917878.vip *.dev.917878.vip *.docs.917878.vip *.g0eipa.917878.vip *.hr.917878.vip *.my.917878.vip *.vip.917878.vip
apenastorrent.net *.apenastorrent.net
bpm.it.com *.bpm.it.com *.www.bpm.it.com
brian.me *.brian.me *.call.brian.me *.cam.brian.me *.superset.brian.me
danauhoki88.one *.danauhoki88.one *.sharepoint.danauhoki88.one *.staging.danauhoki88.one *.test.danauhoki88.one
debet1.top *.debet1.top *.l1v3f.debet1.top
*.874890d5-a62f-48d9-9762-20afac8b69d4.emilyimagination.com emilyimagination.com *.emilyimagination.com
*.cc.huluopo.com huluopo.com *.huluopo.com
kugouxsw.com *.kugouxsw.com *.www.kugouxsw.com
mangago.info *.mangago.info *.mx7.mangago.info *.random.mangago.info *.ww25.mangago.info *.ww9.mangago.info
noleviptennis.info *.noleviptennis.info
*.hpzlhmailer.pdfhub.blog pdfhub.blog *.pdfhub.blog
quax.me *.quax.me
rongkangyy.com *.rongkangyy.com *.web-sitemap.rongkangyy.com
*.32.stoicism.live stoicism.live *.stoicism.live
*.admin.teapon.homes *.api.teapon.homes *.demo.teapon.homes *.fcrmsi.teapon.homes teapon.homes *.teapon.homes *.www.teapon.homes
*.android.uchio.com *.backbone.uchio.com *.go.uchio.com *.hostmaster.uchio.com *.img1-fg.uchio.com *.mp3.uchio.com *.soqvqpasgo.uchio.com *.tr.uchio.com uchio.com *.uchio.com *.ufa.uchio.com *.users.uchio.com *.ww11.uchio.com *.ww25.uchio.com
*.4adfe662-b7f0-435a-af1b-557de2146b9c.ykwa6z.cn *.m.ykwa6z.cn *.root.ykwa6z.cn ykwa6z.cn *.ykwa6z.cn
*.32.zamocwtuh.com zamocwtuh.com *.zamocwtuh.com