76/100 SECURITY SCORE

Certificate Information

Subject
CN=darkwaterenviro.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CA:0D:97:B4:EC:CA:28:D6:94:42:3F:78:9A:13:52:D6:E7:07:0A:3C:59:76:89:DE:5F:D1:81:19:33:43:BA:66
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
incomeflywheel.com *.incomeflywheel.com

Other domains in certificate

darkwaterenviro.com *.darkwaterenviro.com
datup.cc *.datup.cc
day4you.com *.day4you.com
dckeji.com *.dckeji.com
ddjmf.cc *.ddjmf.cc
decoded.it *.decoded.it
digitaldevice.it *.digitaldevice.it
dnzgh.pro *.dnzgh.pro
downloadtorrent.it *.downloadtorrent.it
duyvj.pro *.duyvj.pro
e2004d01d270a31e.com *.e2004d01d270a31e.com
easyday.it *.easyday.it
echoicbonsaicrystal.com *.echoicbonsaicrystal.com
ecosostenbest.com *.ecosostenbest.com
efficaciabest.com *.efficaciabest.com
elegantbridedreams.beauty *.elegantbridedreams.beauty
epitomeglobaltrade.com *.epitomeglobaltrade.com
evanrealestate.com *.evanrealestate.com
eventzticketingplatform.net *.eventzticketingplatform.net
experienced-drunk-468500415.click *.experienced-drunk-468500415.click
fitnessspiritrise.club *.fitnessspiritrise.club
forevermarriagevows.beauty *.forevermarriagevows.beauty
fragrance.it *.fragrance.it
freedomhouse.it *.freedomhouse.it
frieze.it *.frieze.it
futurefinhub.xyz *.futurefinhub.xyz
gacor1.sbs *.gacor1.sbs
gfa57ci.cyou *.gfa57ci.cyou
gfjkk.me *.gfjkk.me
gimjk.shop *.gimjk.shop
globalwavenews.cyou *.globalwavenews.cyou
greatplaces.it *.greatplaces.it
gtuql.pro *.gtuql.pro
hamofenji.com *.hamofenji.com
handsmade.it *.handsmade.it
hempflower.it *.hempflower.it
highvalue.xyz *.highvalue.xyz
huakaimat.com *.huakaimat.com
ikasa.co *.ikasa.co
implantdentist.co *.implantdentist.co
insuranceprovider.it *.insuranceprovider.it
intelligentfinancing.it *.intelligentfinancing.it
indosultan88asli.it.com *.indosultan88asli.it.com
j0gn.my *.j0gn.my