76/100 SECURITY SCORE

Certificate Information

Subject
CN=nursing.co.za
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 04, 2026
Valid Until
July 03, 2026 61 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9D:29:B7:D4:B3:7B:7A:E0:51:CF:29:16:88:28:F5:E9:41:11:AF:53:E2:70:81:00:46:B2:B5:89:F7:72:82:E6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
bilibilil.com *.bilibilil.com *.38.bilibilil.com *.account.bilibilil.com *.mail.bilibilil.com *.space.bilibilil.com *.ww38.bilibilil.com

Other domains in certificate

0004a.cc *.0004a.cc *.sitemaps.0004a.cc
aasiapower.co *.aasiapower.co
blogging.network *.blogging.network *.mail.blogging.network
*.div.ecityworks.com ecityworks.com *.ecityworks.com *.www.ecityworks.com
figural.org *.figural.org *.gold.figural.org *.tag.figural.org
*.com.fock.life fock.life *.fock.life *.gov.fock.life *.na.fock.life *.ww25.fock.life
focushealthnetbenifits.com *.focushealthnetbenifits.com *.pop.focushealthnetbenifits.com *.smtp.focushealthnetbenifits.com
*.9ca1dcda0d27.getmaildoso.org getmaildoso.org *.getmaildoso.org
greenleafmassagecenter.com *.greenleafmassagecenter.com *.monitor.greenleafmassagecenter.com *.sitemap.greenleafmassagecenter.com
heedejoawi.com *.heedejoawi.com *.ww38.heedejoawi.com *.yescms-stag.heedejoawi.com
*.api.investmentstrategyconsultant.pro investmentstrategyconsultant.pro *.investmentstrategyconsultant.pro *.mail.investmentstrategyconsultant.pro
jendoscope.eu *.jendoscope.eu
lonelyguy.com *.lonelyguy.com *.mail.lonelyguy.com *.sg.lonelyguy.com
moviesonhawaiinair.com *.moviesonhawaiinair.com
*.charisma.nursing.co.za nursing.co.za *.nursing.co.za *.unisa.nursing.co.za
preshares.top *.preshares.top
*.18.r3o.cc r3o.cc *.r3o.cc
*.cicd.signsoflungcancer.com *.noc.signsoflungcancer.com signsoflungcancer.com *.signsoflungcancer.com *.ww25.signsoflungcancer.com
sushi-junai.app *.sushi-junai.app *.ww38.sushi-junai.app
*.admin.termeitaly.com *.metrics.termeitaly.com *.redash.termeitaly.com *.staging.termeitaly.com termeitaly.com *.termeitaly.com
totallynotchess.com *.totallynotchess.com *.ww25.totallynotchess.com *.ww38.totallynotchess.com
*.bbbd0883-efd5-4076-a66c-38818931a25d.wukedou.com.cn wukedou.com.cn *.wukedou.com.cn *.www.wukedou.com.cn
ythifs.com *.ythifs.com