Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=lunoti.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 12, 2026
Valid Until
August 10, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
59:85:5D:A4:D4:06:39:B2:5E:7C:EE:01:D1:61:FB:0E:B3:83:E3:8E:84:36:0F:DC:20:C5:E0:AC:06:C2:31:E2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
lunoti.com
*.lunoti.com
*.access.lunoti.com
*.assets.lunoti.com
*.dev.lunoti.com
*.gateway.lunoti.com
*.mail.lunoti.com
*.rdp.lunoti.com
*.ts.lunoti.com
atma.live
*.atma.live
*.attsim.ciptakarya.com
ciptakarya.com
*.ciptakarya.com
*.simbg.ciptakarya.com
*.ww16.ciptakarya.com
*.www.ciptakarya.com
cloudis.club
*.cloudis.club
codebeach.co
*.codebeach.co
ecocups.com.au
*.ecocups.com.au
frtghyuj.club
*.frtghyuj.club
gestionjuridica.co
*.gestionjuridica.co
gymvault.co
*.gymvault.co
laytrix.icu
*.laytrix.icu
*.ww16.laytrix.icu
lklicktel.de
*.lklicktel.de
*.random.lklicktel.de
*.16jun.lordfilm-7.net
*.19dec.lordfilm-7.net
*.22apr.lordfilm-7.net
lordfilm-7.net
*.lordfilm-7.net
mamentournaments.club
*.mamentournaments.club
*.ww38.mamentournaments.club
*.admin.merlott.com
*.autodiscover.merlott.com
*.intranet.merlott.com
merlott.com
*.merlott.com
*.ww1.merlott.com
*.app.musicproductions.us
*.erinllyncdiscover.musicproductions.us
*.m.musicproductions.us
musicproductions.us
*.musicproductions.us
*.sitemaps.musicproductions.us
*.www.musicproductions.us
neowarrior11.shop
*.neowarrior11.shop
nobartv7.icu
*.nobartv7.icu
nsw.life
*.nsw.life
ohsanty.com
*.ohsanty.com
oktaxrda.com
*.oktaxrda.com
paqofy.com
*.paqofy.com
*.prod.shapeshift.space
shapeshift.space
*.shapeshift.space
*.superset.shapeshift.space
targetly.online
*.targetly.online
*.ww25.targetly.online
*.ww38.targetly.online
themachineguns.net
*.themachineguns.net
thenewvision.co.uk
*.thenewvision.co.uk
ubv23.icu
*.ubv23.icu
x58d.icu
*.x58d.icu
xawywuy.com
*.xawywuy.com
xn--0g3a53t.xyz
*.xn--0g3a53t.xyz
yourlifetimeinsurance.com
*.yourlifetimeinsurance.com
Other domains in certificate