76/100 SECURITY SCORE

Certificate Information

Subject
CN=clunch.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 11, 2026
Valid Until
July 10, 2026 54 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
65:A3:33:4C:0F:06:76:E0:64:70:A9:C2:02:5B:41:E0:4C:81:23:60:F7:88:A8:41:E5:7F:CD:8C:C2:41:F2:0A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
maxdesigning.com *.maxdesigning.com

Other domains in certificate

237865.blog *.237865.blog
53401.pro *.53401.pro
92761.locker *.92761.locker
adexamethasone.com *.adexamethasone.com
appsd892kn389dsj8923jk-dshj4.top *.appsd892kn389dsj8923jk-dshj4.top
bathtubs.co.uk *.bathtubs.co.uk
chestnutwoodsman.co.uk *.chestnutwoodsman.co.uk
clunch.co.uk *.clunch.co.uk *.ww16.clunch.co.uk
dszjx896.com *.dszjx896.com
eutt635.top *.eutt635.top
h18107.cc *.h18107.cc
iamamandasteed.com *.iamamandasteed.com
instantlysolutionsfinding.co *.instantlysolutionsfinding.co
irwincasino5.lol *.irwincasino5.lol
j58e6e5gfz.world *.j58e6e5gfz.world
jansk.games *.jansk.games
jeremylesleyband.com *.jeremylesleyband.com
keywest-bedandbreakfasts.com *.keywest-bedandbreakfasts.com
liveskool.com *.liveskool.com
lomondhills.co.uk *.lomondhills.co.uk
lux77th.blog *.lux77th.blog
m2fj5gp7qd.top *.m2fj5gp7qd.top
mafeai.com *.mafeai.com
masterpluspro.co.uk *.masterpluspro.co.uk
mcagentic.com *.mcagentic.com
mcxvr1350.com *.mcxvr1350.com
milebiclub.com *.milebiclub.com
serkino.net *.serkino.net
sifcargo.com *.sifcargo.com
sniffledom.com *.sniffledom.com
snocobiz.org *.snocobiz.org
studyinkorea.sbs *.studyinkorea.sbs
successdrivepath.co *.successdrivepath.co
t2hosted.co *.t2hosted.co
telefondasohbethatti.xyz *.telefondasohbethatti.xyz
tuomasphoto.com *.tuomasphoto.com
vip-dip.online *.vip-dip.online
wastetrackhire-nab.sbs *.wastetrackhire-nab.sbs
yarnspinner.top *.yarnspinner.top
yogic.top *.yogic.top
youthquake.top *.youthquake.top
z9mhf859e9.world *.z9mhf859e9.world
zviavey990.vip *.zviavey990.vip