Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=estrosalmi.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 28, 2026
Valid Until
August 26, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
99:41:22:11:46:EF:FA:93:94:99:7E:6D:4D:89:A6:D0:E9:0F:3A:DF:2A:7E:31:BA:5F:F6:CC:0E:01:D8:5E:B3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
refi.wtf *.refi.wtf *.m.refi.wtf

Other domains in certificate

emitirpass.it.com *.emitirpass.it.com
emitirpassdoc.com *.emitirpassdoc.com
emitirpassdoc.dev *.emitirpassdoc.dev
emitirpassdoc.org *.emitirpassdoc.org
empreesesprymess.click *.empreesesprymess.click
estrosalmi.com *.estrosalmi.com
fggj369qwerasdfzxcv.com *.fggj369qwerasdfzxcv.com
finsafelearn.com *.finsafelearn.com
floridalogcabins.com *.floridalogcabins.com
fruchtzone.win *.fruchtzone.win
gamma-casinoz-online.sbs *.gamma-casinoz-online.sbs
getrenaissancesite.com *.getrenaissancesite.com
kk-7878.com *.kk-7878.com
kljna.town *.kljna.town
kryptolernen.com *.kryptolernen.com
ks8k.cc *.ks8k.cc
kzbcrt.com *.kzbcrt.com
kzjdwf.com *.kzjdwf.com
kzlwla.com *.kzlwla.com
kzmbgy.com *.kzmbgy.com
kzrirr.com *.kzrirr.com
l3g0a7.cyou *.l3g0a7.cyou
localexperiences.click *.localexperiences.click
miserysignalstour2025.com *.miserysignalstour2025.com
thunderarcade622.info *.thunderarcade622.info
use-email-942722908.click *.use-email-942722908.click
veggrow.xyz *.veggrow.xyz
w79m.cyou *.w79m.cyou
wapiyin.com *.wapiyin.com
warehouse-jobs-3t5f1d0u2m2.sbs *.warehouse-jobs-3t5f1d0u2m2.sbs
warehouse-jobs-4a6w3s4e8m9.sbs *.warehouse-jobs-4a6w3s4e8m9.sbs
warehouse-jobs-9p8v7s7s5p6.sbs *.warehouse-jobs-9p8v7s7s5p6.sbs
warehouse-sales-8y8d2f7n9k0.sbs *.warehouse-sales-8y8d2f7n9k0.sbs
wassere.com *.wassere.com
waste-mnagement-jobs-1v2i4c7j0j1.sbs *.waste-mnagement-jobs-1v2i4c7j0j1.sbs
waste-mnagement-jobs-5q1e0x4n9p1.sbs *.waste-mnagement-jobs-5q1e0x4n9p1.sbs
watchshipscience.info *.watchshipscience.info
water-filter-383063637.click *.water-filter-383063637.click
water-filters-systems-kc.click *.water-filters-systems-kc.click
www93834.com *.www93834.com
yourdectud.com *.yourdectud.com
yzbpg.my *.yzbpg.my
zhgc8pe7b.world *.zhgc8pe7b.world