Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tenhi.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 02, 2026
Valid Until
July 01, 2026
49 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
36:17:36:C1:01:3A:F5:64:F0:D3:94:04:DA:1D:BA:7A:C8:93:8F:14:9C:82:B4:1F:B2:8D:12:90:69:50:E8:24
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
lgg2.it
*.lgg2.it
*.data.lgg2.it
0402-ljy-led-lights.sbs
*.0402-ljy-led-lights.sbs
41819.blog
*.41819.blog
49891.blog
*.49891.blog
acetofacegames.com
*.acetofacegames.com
agyxq.sx
*.agyxq.sx
amataexpress.com
*.amataexpress.com
collegemanoraptsal.com
*.collegemanoraptsal.com
construction-jobs-neaby.today
*.construction-jobs-neaby.today
*.25.cxema-ru.online
cxema-ru.online
*.cxema-ru.online
*.easycon.cxema-ru.online
*.flowise.cxema-ru.online
*.ww25.cxema-ru.online
duet.fund
*.duet.fund
gixty.com
*.gixty.com
icolour.in
*.icolour.in
ithiam.com
*.ithiam.com
kgyv10fy4.lol
*.kgyv10fy4.lol
lift-construction-job-cost.sbs
*.lift-construction-job-cost.sbs
mlxke.care
*.mlxke.care
moderngorunum.online
*.moderngorunum.online
motos-on-installment-ro1.sbs
*.motos-on-installment-ro1.sbs
newheightscalgary.ca
*.newheightscalgary.ca
njchj.loan
*.njchj.loan
ollbs.cc
*.ollbs.cc
ozyvk.co
*.ozyvk.co
postoffce.com
*.postoffce.com
powerupcontact.com
*.powerupcontact.com
professionalspeakers.in
*.professionalspeakers.in
r69p.icu
*.r69p.icu
strecher.com
*.strecher.com
surgicbot.com
*.surgicbot.com
switchingyourbank.sbs
*.switchingyourbank.sbs
sytwa.trade
*.sytwa.trade
tcodp.town
*.tcodp.town
telrouted.com
*.telrouted.com
tenhi.com
*.tenhi.com
*.ww25.tenhi.com
themrblinds.com
*.themrblinds.com
thestudyofstuff.com
*.thestudyofstuff.com
wildz9.io
*.wildz9.io
www143818.com
*.www143818.com
www939849.com
*.www939849.com
z72cyf5qm5.top
*.z72cyf5qm5.top
zlxku.co
*.zlxku.co
Other domains in certificate