76/100 SECURITY SCORE

Certificate Information

Subject
CN=ca5s8.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 23, 2026
Valid Until
September 21, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
27:0A:35:41:9F:01:AE:01:94:EC:FC:41:46:38:D9:27:38:21:D1:E5:81:C9:E8:C3:8A:87:C3:DB:91:29:9B:BB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
exercisede.com *.exercisede.com *.2e86871e-c2fa-4108-b7cd-a9adcbee4931.exercisede.com *.a58aa77f-f235-418a-841b-1f6d4f69d9c0.exercisede.com *.account.exercisede.com *.app.exercisede.com *.apps.exercisede.com *.backup.exercisede.com *.beta.exercisede.com *.blog.exercisede.com *.crm.exercisede.com *.dash.exercisede.com *.fdd8c56e-e488-4670-8919-92e4f1f3ef7e.exercisede.com *.forum.exercisede.com *.forums.exercisede.com *.help.exercisede.com *.m.exercisede.com *.mail.exercisede.com *.new.exercisede.com *.newsletter.exercisede.com *.shop.exercisede.com *.staging.exercisede.com *.supersets.exercisede.com *.temp.exercisede.com *.test.exercisede.com *.uat.exercisede.com *.v1.exercisede.com *.vpn.exercisede.com *.wiki.exercisede.com

Other domains in certificate

704dm.com *.704dm.com
arroa.com *.arroa.com *.cruz.arroa.com *.mail.arroa.com
atrapasuenos.online *.atrapasuenos.online *.dev.atrapasuenos.online *.webmail.atrapasuenos.online
bestvaporizerpen.com *.bestvaporizerpen.com
ca5s8.com *.ca5s8.com *.www.ca5s8.com
cprofsandiego.com *.cprofsandiego.com
*.assets.deconde.com *.blog.deconde.com deconde.com *.deconde.com *.hostmaster.deconde.com *.mail.deconde.com *.vpn.deconde.com *.ww1.deconde.com *.ww11.deconde.com *.ww16.deconde.com *.ww17.deconde.com *.ww38.deconde.com
frigitaire.com *.frigitaire.com
*.414technologies.jkbose.in *.csckashmir.jkbose.in *.globalcheckpro.jkbose.in jkbose.in *.jkbose.in *.williamcareyuniversity.jkbose.in
mininger.com *.mininger.com
qualitydecor.com *.qualitydecor.com
sevashram.com *.sevashram.com
swallowing.com.au *.swallowing.com.au
*.wildcard.xomvuive.com xomvuive.com *.xomvuive.com
*.blog.ypo.com.au *.cpanel.ypo.com.au *.ftp.ypo.com.au *.imap.ypo.com.au *.mail.ypo.com.au *.mx.ypo.com.au *.random.ypo.com.au *.smtp.ypo.com.au *.smtpauth.ypo.com.au *.webdisk.ypo.com.au *.wp.ypo.com.au ypo.com.au *.ypo.com.au