Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=agesspiegel.de
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 21, 2026
Valid Until
August 19, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
12:22:A3:7B:14:8F:26:3F:D0:6F:45:76:E7:C5:A5:BF:A2:B9:6C:0D:42:97:BF:97:61:03:E9:99:39:52:B6:F3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
maskedclick.com
*.maskedclick.com
agesspiegel.de
*.agesspiegel.de
district38.co
*.district38.co
dmpdccc.org
*.dmpdccc.org
dominakathryn.co
*.dominakathryn.co
dovizraporu.site
*.dovizraporu.site
easyfortificapitalsolutions.com
*.easyfortificapitalsolutions.com
enem-oficial.site
*.enem-oficial.site
erikol.store
*.erikol.store
evairengelsschlickmann.sbs
*.evairengelsschlickmann.sbs
fastpaybitcoin.icu
*.fastpaybitcoin.icu
fivestar125.cn
*.fivestar125.cn
flowcaps.com
*.flowcaps.com
fyaza.com
*.fyaza.com
gptintelligent.com
*.gptintelligent.com
gracefulweddingjourneys.beauty
*.gracefulweddingjourneys.beauty
hansipslot-016.cfd
*.hansipslot-016.cfd
heroslot1688.xyz
*.heroslot1688.xyz
hideproof.com
*.hideproof.com
khayt.ae
*.khayt.ae
kv95.cc
*.kv95.cc
lnuxyxsx.top
*.lnuxyxsx.top
logiamp.com
*.logiamp.com
logistudent.com
*.logistudent.com
lovesoccerplanet.xyz
*.lovesoccerplanet.xyz
lyqrmv.onl
*.lyqrmv.onl
m4up8.xyz
*.m4up8.xyz
m4upss.xyz
*.m4upss.xyz
m83g.icu
*.m83g.icu
maskedshopboost.com
*.maskedshopboost.com
pk789v2.xyz
*.pk789v2.xyz
publishingtime.info
*.publishingtime.info
push8888.xyz
*.push8888.xyz
q74q.cyou
*.q74q.cyou
rctd122.info
*.rctd122.info
regisprofox.com
*.regisprofox.com
renovation-comp-896844606.click
*.renovation-comp-896844606.click
renovation-company-678347144.click
*.renovation-company-678347144.click
shadowrace582.top
*.shadowrace582.top
socialexpress.org
*.socialexpress.org
tasity.gdn
*.tasity.gdn
timelesstraveloffers.live
*.timelesstraveloffers.live
viskaricks.cfd
*.viskaricks.cfd
vove.tv
*.vove.tv
vulkan-24-cazino.cfd
*.vulkan-24-cazino.cfd
Other domains in certificate