Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=sonicmassage.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 07, 2026
Valid Until
September 05, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
40:02:C7:9F:DE:26:AB:13:8B:B3:E6:A9:1E:F3:97:49:3A:93:68:62:56:24:1F:DD:86:21:1F:A3:A0:80:FD:13
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
thea.bot
*.thea.bot
51909.my
*.51909.my
84653.my
*.84653.my
avantii.store
*.avantii.store
ayahamza.com
*.ayahamza.com
bayruncoffee.com
*.bayruncoffee.com
*.www.bayruncoffee.com
bb999p.quest
*.bb999p.quest
bibliotecadigitallusofona.org
*.bibliotecadigitallusofona.org
*.ingles.bibliotecadigitallusofona.org
*.ww25.bibliotecadigitallusofona.org
brushhealthy.org
*.brushhealthy.org
dorxataworld.com
*.dorxataworld.com
downeysfishandchips.co.uk
*.downeysfishandchips.co.uk
*.ww25.downeysfishandchips.co.uk
esgreport.com.au
*.esgreport.com.au
hj4f6.com
*.hj4f6.com
*.ww25.hj4f6.com
jdrne.town
*.jdrne.town
listnplan.com
*.listnplan.com
onlinecredithuman.com
*.onlinecredithuman.com
overton-security.org
*.overton-security.org
paxkd.town
*.paxkd.town
poohealthy.org
*.poohealthy.org
pskbj.town
*.pskbj.town
rcnmo.town
*.rcnmo.town
rfid.group
*.rfid.group
salthealthy.org
*.salthealthy.org
*.1.settei.com
*.art.settei.com
settei.com
*.settei.com
*.status.settei.com
*.sms.sonicmassage.com
sonicmassage.com
*.sonicmassage.com
strategiccareernavigator.qpon
*.strategiccareernavigator.qpon
taptoosl.io
*.taptoosl.io
taracure.com
*.taracure.com
travelingthephilippines.info
*.travelingthephilippines.info
uvaeh.town
*.uvaeh.town
v53mx.top
*.v53mx.top
valuegardeningnetwork.live
*.valuegardeningnetwork.live
*.competition.vodafonecomedycarnival.com
*.contact.vodafonecomedycarnival.com
*.previous.vodafonecomedycarnival.com
vodafonecomedycarnival.com
*.vodafonecomedycarnival.com
*.www.vodafonecomedycarnival.com
weddingcadence.beauty
*.weddingcadence.beauty
xdxhz.town
*.xdxhz.town
xn--sptzle-cua.info
*.xn--sptzle-cua.info
xyzaclks.xyz
*.xyzaclks.xyz
zxtnq.work
*.zxtnq.work
Other domains in certificate