Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=lzihome.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 01, 2026
Valid Until
July 30, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
20:4C:44:3B:EB:73:87:C5:27:78:EF:85:55:30:A4:6C:1B:7A:0F:98:56:04:36:64:B2:3A:83:60:09:58:C3:46
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
lifesimplify.store *.lifesimplify.store *.com.lifesimplify.store

Other domains in certificate

228738.loan *.228738.loan *.loan.228738.loan
47isufaenztmi.xyz *.47isufaenztmi.xyz *.ww25.47isufaenztmi.xyz
*.2dbks.5137lls.top 5137lls.top *.5137lls.top *.5vs9r.5137lls.top *.bnbod.5137lls.top
btchacking.com *.btchacking.com
*.98c480cf-5adb-4a27-83eb-768346258d06.btwlogin.com *.a0f3db9d-5f92-4b41-81db-d29b9ba7f99c.btwlogin.com *.admin.btwlogin.com *.alaotapp.btwlogin.com *.api.btwlogin.com *.app.btwlogin.com btwlogin.com *.btwlogin.com *.f043ea12-d4f9-4d52-b947-e123956b0837.btwlogin.com *.fvgfoapp.btwlogin.com *.staging.btwlogin.com *.testing.btwlogin.com *.vpn.btwlogin.com
deker.org *.deker.org *.forum.deker.org *.rdweb.deker.org *.remoto.deker.org *.sites.deker.org *.tsfweb.deker.org
directsolar.co.uk *.directsolar.co.uk
etecribeiraopreto.com.br *.etecribeiraopreto.com.br
hostelsandcrib.com *.hostelsandcrib.com *.temp.hostelsandcrib.com
lzihome.com *.lzihome.com *.rdweb.lzihome.com
nicefduerygood.world *.nicefduerygood.world *.ux2rmv.nicefduerygood.world
*.autodiscover.projerseys.org projerseys.org *.projerseys.org
*.mail.pumpenplus.de pumpenplus.de *.pumpenplus.de
*.199926.senhuansiwang.cn *.64.senhuansiwang.cn *.69.senhuansiwang.cn *.6a.senhuansiwang.cn senhuansiwang.cn *.senhuansiwang.cn
skidome.com *.skidome.com *.store.skidome.com
*.alzkt.spider.pw spider.pw *.spider.pw
*.m.sukutoto.bet sukutoto.bet *.sukutoto.bet
*.co.tradertop.net tradertop.net *.tradertop.net *.vn.tradertop.net
*.random.valoshop.pro *.staging.valoshop.pro valoshop.pro *.valoshop.pro
*.cfapi.xdapiym5297.com *.cfcdn.xdapiym5297.com *.cfstatic.xdapiym5297.com *.dapiab.xdapiym5297.com *.matchgress-api.xdapiym5297.com *.matchgress.xdapiym5297.com *.newsapi.xdapiym5297.com *.sbscfstatic.xdapiym5297.com *.sportsoss.xdapiym5297.com *.sportsvideoapi.xdapiym5297.com xdapiym5297.com *.xdapiym5297.com