Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=niedersachesen.de
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 13, 2026
Valid Until
May 14, 2026
83 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
01:D5:33:C9:01:B3:0B:D7:9B:62:B9:C3:66:24:7D:37:66:C5:D7:2E:21:E8:6F:E2:74:AD:C9:55:7D:4E:91:AB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
lunsar.com
*.lunsar.com
axtra.co
*.axtra.co
*.cpanel.axtra.co
*.webdisk.axtra.co
*.www.axtra.co
dailysports.org
*.dailysports.org
*.ns1.dailysports.org
*.www.dailysports.org
desertsaq-kr.shop
*.desertsaq-kr.shop
duloup.com
*.duloup.com
fateryh.com
*.fateryh.com
flutternavx.xyz
*.flutternavx.xyz
*.admin.goldshoes.it
goldshoes.it
*.goldshoes.it
gorilas.bet
*.gorilas.bet
*.ww25.gorilas.bet
*.ww38.gorilas.bet
harikabiryaklasim.online
*.harikabiryaklasim.online
*.com.hipertenso.online
hipertenso.online
*.hipertenso.online
imepita.jp
*.imepita.jp
istanbulyurt.com
*.istanbulyurt.com
krv690.org
*.krv690.org
*.coinbase.ksu.de
ksu.de
*.ksu.de
kudumbayogam.com
*.kudumbayogam.com
*.forum.leddio.com
leddio.com
*.leddio.com
*.ww25.leddio.com
*.ww38.leddio.com
*.crm.locked.studio
locked.studio
*.locked.studio
lqzj.xyz
*.lqzj.xyz
magalona.com
*.magalona.com
*.pay.magalona.com
*.remoteaccess.magalona.com
*.service.magalona.com
*.widget.magalona.com
materson.com
*.materson.com
maxandcosrbija.com
*.maxandcosrbija.com
*.ww25.maxandcosrbija.com
memebetting.com
*.memebetting.com
*.lstn.niedersachesen.de
*.navo.niedersachesen.de
niedersachesen.de
*.niedersachesen.de
*.polizei.niedersachesen.de
*.sip.niedersachesen.de
*.com.niliantattoo.com.br
niliantattoo.com.br
*.niliantattoo.com.br
*.ns2.niliantattoo.com.br
*.ns3.niliantattoo.com.br
*.2jqmhujvfz.susmtb.org
*.art.susmtb.org
*.full.susmtb.org
*.mail.susmtb.org
susmtb.org
*.susmtb.org
*.www.susmtb.org
*.sell.trendymert.com
trendymert.com
*.trendymert.com
*.mx.twiiit.co
twiiit.co
*.twiiit.co
Other domains in certificate