Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=bestforcatsanddogs.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 25, 2026
Valid Until
September 23, 2026
89 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1E:B0:0E:79:8E:AE:A1:31:38:21:2B:32:82:2C:5D:1C:A9:B2:4D:B6:81:F3:F7:7A:F8:4F:2F:98:27:A0:76:40
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
runforgood.it
*.runforgood.it
*.admin.runforgood.it
*.analytic.runforgood.it
*.app.runforgood.it
*.dev.runforgood.it
*.mail.runforgood.it
*.www.runforgood.it
5280homepros.com
*.5280homepros.com
*.backup.5280homepros.com
bestforcatsanddogs.com
*.bestforcatsanddogs.com
*.cpcalendars.bestforcatsanddogs.com
captchtyperz.com
*.captchtyperz.com
*.ww1.captchtyperz.com
*.ww12.captchtyperz.com
*.ww2.captchtyperz.com
*.ww7.captchtyperz.com
*.www.captchtyperz.com
essswissport.com
*.essswissport.com
*.mail.essswissport.com
*.owa.essswissport.com
*.random.essswissport.com
*.ww16.essswissport.com
*.ww25.essswissport.com
*.ww38.essswissport.com
*.www.essswissport.com
*.admin.govareviewscontented.co
*.api.govareviewscontented.co
*.app.govareviewscontented.co
*.demo.govareviewscontented.co
govareviewscontented.co
*.govareviewscontented.co
*.lmsufapi.govareviewscontented.co
*.www.govareviewscontented.co
*.7qgb25.klug.lol
*.api.klug.lol
*.backup.klug.lol
*.demo.klug.lol
klug.lol
*.klug.lol
*.1.lanous.com
*.131412.lanous.com
*.access.lanous.com
*.app.lanous.com
*.bitrix.lanous.com
*.connect.lanous.com
*.dev.lanous.com
*.gp.lanous.com
lanous.com
*.lanous.com
*.pan.lanous.com
*.rd.lanous.com
*.shirosakimio.lanous.com
*.skzww.lanous.com
*.sslvpn.lanous.com
*.vpn2.lanous.com
*.ww.lanous.com
*.ww12.lanous.com
*.ww7.lanous.com
*.ww99.lanous.com
*.wwmr.lanous.com
*.wwue.lanous.com
*.wwuj.lanous.com
*.www.lanous.com
*.wwwn.lanous.com
*.wwxe.lanous.com
*.wwzf.lanous.com
*.xxx.lanous.com
*.014w8.lmnnopqr.xyz
lmnnopqr.xyz
*.lmnnopqr.xyz
*.business.paymentwallet.net
*.com.paymentwallet.net
paymentwallet.net
*.paymentwallet.net
*.test.paymentwallet.net
*.zonpayadmin.paymentwallet.net
*.5jsd7.pupdroid.xyz
*.cnfr9.pupdroid.xyz
pupdroid.xyz
*.pupdroid.xyz
*.zl1z8.pupdroid.xyz
*.alphaofficesysmta-sts.stomerij.eu
stomerij.eu
*.stomerij.eu
Other domains in certificate