Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=xplor.app
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
May 28, 2026
Valid Until
August 26, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:78:5A:BF:D1:9D:6D:64:D3:D3:D8:EF:6B:9F:95:63:8E:E1:41:68:33:29:C6:3B:D3:7A:39:78:D4:9D:82:E4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
xplor.app
*.xplor.app
*.admin.xplor.app
*.app.xplor.app
*.backend.xplor.app
*.blog.xplor.app
*.com.xplor.app
*.demo.xplor.app
*.dev-analytic.xplor.app
*.m.xplor.app
*.mail.xplor.app
*.mailin1.xplor.app
*.mailrelay.xplor.app
*.members.xplor.app
*.mx.xplor.app
*.mx1.xplor.app
*.post.xplor.app
*.server.xplor.app
*.shop.xplor.app
*.smtp3.xplor.app
*.test.xplor.app
*.webmail.xplor.app
*.ww53.xplor.app
*.ww82.xplor.app
*.www.xplor.app
*.yueqamailin1.xplor.app
7box.us
*.7box.us
eey.au
*.eey.au
*.ww25.eey.au
exdomainer.com
*.exdomainer.com
grivot.com
*.grivot.com
helphotline.com
*.helphotline.com
*.random.helphotline.com
*.auth.kitchenremodeling.com.au
kitchenremodeling.com.au
*.kitchenremodeling.com.au
*.mailout.kitchenremodeling.com.au
*.ww25.kitchenremodeling.com.au
loko.net
*.loko.net
*.mail.loko.net
*.ww11.loko.net
*.ww17.loko.net
restauramar.org
*.restauramar.org
satellitehome.com
*.satellitehome.com
*.anyconnect.tahoe.luxe
*.api.tahoe.luxe
*.app.tahoe.luxe
*.apps.tahoe.luxe
*.backup.tahoe.luxe
*.connect.tahoe.luxe
*.dashboard.tahoe.luxe
*.dev.tahoe.luxe
*.gp.tahoe.luxe
*.jtrfjsslvpn.tahoe.luxe
*.mailer.tahoe.luxe
*.marketing.tahoe.luxe
*.rds.tahoe.luxe
*.remoteapp.tahoe.luxe
*.remoto.tahoe.luxe
*.sslvpn.tahoe.luxe
tahoe.luxe
*.tahoe.luxe
*.v1.tahoe.luxe
*.vpnssl.tahoe.luxe
*.webvpn.tahoe.luxe
*.1307.ys4.cc
*.1371.ys4.cc
*.1947.ys4.cc
*.1963.ys4.cc
*.32.ys4.cc
*.484.ys4.cc
*.53.ys4.cc
*.581.ys4.cc
*.742.ys4.cc
*.8brpe.ys4.cc
*.ptmdg.ys4.cc
*.r1kuu.ys4.cc
*.ww25.ys4.cc
*.www.ys4.cc
ys4.cc
*.ys4.cc
Other domains in certificate