Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=nlockman.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
March 26, 2026
Valid Until
June 24, 2026
55 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4F:51:A4:C9:AE:D1:00:BE:8E:C1:25:6C:C1:1B:1A:A9:DD:AD:2B:7B:9B:D2:8C:40:F0:0E:2F:C5:06:D6:1F:59
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
medicalimaging.in
*.medicalimaging.in
29780.co
*.29780.co
bbaing.com
*.bbaing.com
casamianhelopr.com
*.casamianhelopr.com
cfbbb.xyz
*.cfbbb.xyz
davidplayle.com
*.davidplayle.com
eliteclick942.shop
*.eliteclick942.shop
fdsklp.xyz
*.fdsklp.xyz
flora.finance
*.flora.finance
floridadroneshow.com
*.floridadroneshow.com
hostingsecure.pro
*.hostingsecure.pro
iygmym.gdn
*.iygmym.gdn
jtjibc.top
*.jtjibc.top
kingscrossministries.org
*.kingscrossministries.org
madorjewelrydz.com
*.madorjewelrydz.com
mental-test-ss-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1.sbs
*.mental-test-ss-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1.sbs
minervatrust.com
*.minervatrust.com
n1casinogr.org
*.n1casinogr.org
nashdisability.com
*.nashdisability.com
nativeamericanjewely.com
*.nativeamericanjewely.com
nlockman.com
*.nlockman.com
onlinealerts.help
*.onlinealerts.help
ontariocardealer.com
*.ontariocardealer.com
persian.in
*.persian.in
smyjz.pro
*.smyjz.pro
suffolkcountycpa.com
*.suffolkcountycpa.com
sunflowyoga.com
*.sunflowyoga.com
suoparye.com
*.suoparye.com
supalabs.xyz
*.supalabs.xyz
superinfoportalkz.live
*.superinfoportalkz.live
superrealm977.top
*.superrealm977.top
sy4ever.vacations
*.sy4ever.vacations
thegiftaura.com
*.thegiftaura.com
tradeterrificlive.com
*.tradeterrificlive.com
tradetrackmarketing.com
*.tradetrackmarketing.com
tryemovidapp.com
*.tryemovidapp.com
unlock-it.com
*.unlock-it.com
unsignedbrand.com
*.unsignedbrand.com
uocztg.gdn
*.uocztg.gdn
uoqaz.co
*.uoqaz.co
vgnbn.support
*.vgnbn.support
vzbli.gdn
*.vzbli.gdn
vzjqt.co
*.vzjqt.co
xiplj.pro
*.xiplj.pro
zgslv.town
*.zgslv.town
Other domains in certificate