Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=estrosalmi.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 28, 2026
Valid Until
August 26, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
99:41:22:11:46:EF:FA:93:94:99:7E:6D:4D:89:A6:D0:E9:0F:3A:DF:2A:7E:31:BA:5F:F6:CC:0E:01:D8:5E:B3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
refi.wtf
*.refi.wtf
*.m.refi.wtf
emitirpass.it.com
*.emitirpass.it.com
emitirpassdoc.com
*.emitirpassdoc.com
emitirpassdoc.dev
*.emitirpassdoc.dev
emitirpassdoc.org
*.emitirpassdoc.org
empreesesprymess.click
*.empreesesprymess.click
estrosalmi.com
*.estrosalmi.com
fggj369qwerasdfzxcv.com
*.fggj369qwerasdfzxcv.com
finsafelearn.com
*.finsafelearn.com
floridalogcabins.com
*.floridalogcabins.com
fruchtzone.win
*.fruchtzone.win
gamma-casinoz-online.sbs
*.gamma-casinoz-online.sbs
getrenaissancesite.com
*.getrenaissancesite.com
kk-7878.com
*.kk-7878.com
kljna.town
*.kljna.town
kryptolernen.com
*.kryptolernen.com
ks8k.cc
*.ks8k.cc
kzbcrt.com
*.kzbcrt.com
kzjdwf.com
*.kzjdwf.com
kzlwla.com
*.kzlwla.com
kzmbgy.com
*.kzmbgy.com
kzrirr.com
*.kzrirr.com
l3g0a7.cyou
*.l3g0a7.cyou
localexperiences.click
*.localexperiences.click
miserysignalstour2025.com
*.miserysignalstour2025.com
thunderarcade622.info
*.thunderarcade622.info
use-email-942722908.click
*.use-email-942722908.click
veggrow.xyz
*.veggrow.xyz
w79m.cyou
*.w79m.cyou
wapiyin.com
*.wapiyin.com
warehouse-jobs-3t5f1d0u2m2.sbs
*.warehouse-jobs-3t5f1d0u2m2.sbs
warehouse-jobs-4a6w3s4e8m9.sbs
*.warehouse-jobs-4a6w3s4e8m9.sbs
warehouse-jobs-9p8v7s7s5p6.sbs
*.warehouse-jobs-9p8v7s7s5p6.sbs
warehouse-sales-8y8d2f7n9k0.sbs
*.warehouse-sales-8y8d2f7n9k0.sbs
wassere.com
*.wassere.com
waste-mnagement-jobs-1v2i4c7j0j1.sbs
*.waste-mnagement-jobs-1v2i4c7j0j1.sbs
waste-mnagement-jobs-5q1e0x4n9p1.sbs
*.waste-mnagement-jobs-5q1e0x4n9p1.sbs
watchshipscience.info
*.watchshipscience.info
water-filter-383063637.click
*.water-filter-383063637.click
water-filters-systems-kc.click
*.water-filters-systems-kc.click
www93834.com
*.www93834.com
yourdectud.com
*.yourdectud.com
yzbpg.my
*.yzbpg.my
zhgc8pe7b.world
*.zhgc8pe7b.world
Other domains in certificate