Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=pastfoward.tech
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 05, 2026
Valid Until
May 06, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
21:37:1F:54:8E:4E:D7:69:B8:73:57:4F:5D:8B:F0:EB:F2:CE:15:32:A0:50:25:91:64:B8:E2:A9:B6:ED:66:58
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
mechef.com
*.mechef.com
*.m.mechef.com
13859.academy
*.13859.academy
*.a1c06382-06bf-4ad4-b30d-fdf8c573af08.13859.academy
*.cc61600d-9dbc-4df8-80ae-40acd15c3d41.13859.academy
*.hostmaster.13859.academy
*.qa.13859.academy
*.secure.13859.academy
9hz5.shop
*.9hz5.shop
*.mail.9hz5.shop
*.y05fvnk.9hz5.shop
bassettfurniture.company
*.bassettfurniture.company
*.mail.bassettfurniture.company
*.ww38.bassettfurniture.company
betcup498.com
*.betcup498.com
bookdealer.com.au
*.bookdealer.com.au
*.ww16.bookdealer.com.au
*.ww25.bookdealer.com.au
*.ww38.bookdealer.com.au
*.archiv.brazzrrsnetwork.com
brazzrrsnetwork.com
*.brazzrrsnetwork.com
canans.com
*.canans.com
*.m.canans.com
cufa.info
*.cufa.info
*.m.cufa.info
dfyo75c6.top
*.dfyo75c6.top
dimabilan.com
*.dimabilan.com
divinify.net
*.divinify.net
*.client.jebran.com
*.connectvpn.jebran.com
jebran.com
*.jebran.com
*.office.jebran.com
*.remoteaccess.jebran.com
*.client.lineas.com
*.connectvpn.lineas.com
lineas.com
*.lineas.com
*.office.lineas.com
*.remoteaccess.lineas.com
*.vpn1.lineas.com
*.web.lineas.com
*.live.olahraga24.com
olahraga24.com
*.olahraga24.com
*.sv.olahraga24.com
*.2d0cf9f9-b8f8-47bc-9d25-d3ff415a5f15.pastfoward.tech
*.dash.pastfoward.tech
pastfoward.tech
*.pastfoward.tech
paybyplate.com
*.paybyplate.com
*.website.paybyplate.com
*.ww16.paybyplate.com
*.wwww.paybyplate.com
psgc.club
*.psgc.club
samanthakochis.info
*.samanthakochis.info
*.wildcard.samanthakochis.info
*.ww25.samanthakochis.info
*.www.samanthakochis.info
*.mail.sarmshop.eu
sarmshop.eu
*.sarmshop.eu
*.webmail.sarmshop.eu
*.mail.storminstruments.com
*.random.storminstruments.com
storminstruments.com
*.storminstruments.com
*.ww25.storminstruments.com
*.email.svperordinary.com
svperordinary.com
*.svperordinary.com
very79.xyz
*.very79.xyz
*.ww25.very79.xyz
*.ww38.very79.xyz
Other domains in certificate