Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=sayhold.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 15, 2026
Valid Until
August 13, 2026 66 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BD:00:6A:3E:31:04:FF:4F:F2:1A:ED:72:CA:3D:F2:E6:C2:EE:DD:81:17:C5:63:6D:80:CA:31:78:41:E9:BD:22
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
sayhold.com *.sayhold.com *.cloud.sayhold.com *.lime.sayhold.com *.rds.sayhold.com *.rdweb.sayhold.com *.remote.sayhold.com *.sitemap.sayhold.com

Other domains in certificate

76543.locker *.76543.locker *.barracuda.76543.locker *.beta.76543.locker *.blog.76543.locker *.intranet.76543.locker *.mail5.76543.locker *.mailserver.76543.locker *.members.76543.locker *.mx02.76543.locker *.srv.76543.locker *.support.76543.locker
*.backend.bandadimatti.com bandadimatti.com *.bandadimatti.com *.dashs.bandadimatti.com *.notexistsdev.bandadimatti.com *.reporting.bandadimatti.com
*.bi.caliejean.com.au caliejean.com.au *.caliejean.com.au *.ww25.caliejean.com.au
communityompage.com *.communityompage.com *.dp1usm.communityompage.com
*.bhuilms.ethioclassicjobs.com *.elearning.ethioclassicjobs.com ethioclassicjobs.com *.ethioclassicjobs.com *.learning.ethioclassicjobs.com
*.demo.holoauthority.com *.help.holoauthority.com holoauthority.com *.holoauthority.com *.m.holoauthority.com
*.com.lollie.com lollie.com *.lollie.com *.net.lollie.com *.pics.lollie.com *.ww1.lollie.com
monofix.club *.monofix.club *.ww25.monofix.club
*.cnlyj3jzzu.nuisdartistes.com nuisdartistes.com *.nuisdartistes.com
*.member.online24.bet online24.bet *.online24.bet
*.lc.rickydelrosariocoaching.com rickydelrosariocoaching.com *.rickydelrosariocoaching.com
*.0dcd3b38-b0ad-44ea-8018-56509c28670d.tibebe.art *.pzvh39.tibebe.art tibebe.art *.tibebe.art
wowkebabish.com *.wowkebabish.com
*.dqeif.xn--ehqa.com *.s3hyw.xn--ehqa.com *.secureaccess.xn--ehqa.com *.sitemap.xn--ehqa.com *.sitemaps.xn--ehqa.com *.wildcard.xn--ehqa.com *.www.xn--ehqa.com xn--ehqa.com *.xn--ehqa.com
*.aging.xventure.tech *.api.xventure.tech *.assets.xventure.tech *.backup.xventure.tech *.cure.xventure.tech *.dashboard.xventure.tech *.demo.xventure.tech *.eiztjv2.xventure.tech *.japnyaging.xventure.tech *.qirkotest.xventure.tech *.staging.xventure.tech xventure.tech *.xventure.tech *.ztjv2.xventure.tech