Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=135105.my
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026
57 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6C:16:F0:45:62:95:0C:C7:2F:4B:34:6B:02:CD:3E:ED:AF:E3:9D:41:B6:1E:BC:07:E7:7E:28:C0:E6:BE:7A:67
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
marcellozuna.com
*.marcellozuna.com
10027.my
*.10027.my
10035.lgbt
*.10035.lgbt
135105.my
*.135105.my
32248.my
*.32248.my
332297.cc
*.332297.cc
33542.one
*.33542.one
343887.cc
*.343887.cc
344123.co
*.344123.co
39856.my
*.39856.my
406027.cc
*.406027.cc
509312.town
*.509312.town
53391.mobi
*.53391.mobi
54308143.top
*.54308143.top
68048.my
*.68048.my
81525.mobi
*.81525.mobi
absoluteweddingguide.beauty
*.absoluteweddingguide.beauty
ai-courses-ww-4151.sbs
*.ai-courses-ww-4151.sbs
altzw.blog
*.altzw.blog
axwnuzjfadfhu.cc
*.axwnuzjfadfhu.cc
creditrepairservices.sbs
*.creditrepairservices.sbs
dreamaction65.info
*.dreamaction65.info
expecks.com
*.expecks.com
*.4yac8k.feesaq.com
feesaq.com
*.feesaq.com
feministbooks.click
*.feministbooks.click
flagfinancelab.com
*.flagfinancelab.com
flare-jolt.rest
*.flare-jolt.rest
*.www.flare-jolt.rest
freebetbet365.biz
*.freebetbet365.biz
fusion-techmatrix.quest
*.fusion-techmatrix.quest
fwjy9f6bpy.top
*.fwjy9f6bpy.top
g27p76ewpe.top
*.g27p76ewpe.top
government-risk-compliance-57ljm.click
*.government-risk-compliance-57ljm.click
housecleanhelper-1qaa.click
*.housecleanhelper-1qaa.click
iajhgxcyqh.cc
*.iajhgxcyqh.cc
imgcoffee.biz
*.imgcoffee.biz
indiajnqs.my
*.indiajnqs.my
j9dyskubfho2bzd6fu.pro
*.j9dyskubfho2bzd6fu.pro
lawyerconsult.click
*.lawyerconsult.click
need-dental-implants-lhhsh6.click
*.need-dental-implants-lhhsh6.click
persian.com.au
*.persian.com.au
qilofa.pro
*.qilofa.pro
systemscybersecurity.com
*.systemscybersecurity.com
vanguardroot.co
*.vanguardroot.co
xbet1.info
*.xbet1.info
Other domains in certificate