Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=kipa.world
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6E:0D:D5:98:11:BB:2D:4D:CA:21:D3:21:6D:92:27:92:6A:5D:CA:DA:3A:CC:81:C9:DF:09:C7:A3:FD:67:5A:F5
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

84 domains
minar.net *.minar.net *.app.minar.net *.ssl.minar.net *.vpn1.minar.net

Other domains in certificate

alldaydiscounts.xyz *.alldaydiscounts.xyz *.ww25.alldaydiscounts.xyz
australianfashionlabels.com.au *.australianfashionlabels.com.au
*.app.brekkie.life *.autodiscover.brekkie.life brekkie.life *.brekkie.life *.checkout.brekkie.life *.cpcalendars.brekkie.life *.cpcontacts.brekkie.life *.mail.brekkie.life *.sitemap.brekkie.life *.sitemaps.brekkie.life *.smtp.brekkie.life *.whm.brekkie.life *.wildcard.brekkie.life *.ww16.brekkie.life *.www.brekkie.life
chicago.gifts *.chicago.gifts *.goood.chicago.gifts *.mx.chicago.gifts
gautamanand.com *.gautamanand.com *.ww16.gautamanand.com
idiyi.cc *.idiyi.cc *.random.idiyi.cc *.ww25.idiyi.cc
kipa.world *.kipa.world
*.773d1ecd-0060-4a7b-94ae-2ed13bc6dc63.miamigiants.com *.admin.miamigiants.com *.backend.miamigiants.com miamigiants.com *.miamigiants.com *.rds.miamigiants.com
newlungcancertreatment097909.icu *.newlungcancertreatment097909.icu
*.8bfc2dff-8527-4316-8499-39dfa97393eb.roseandfox.pet roseandfox.pet *.roseandfox.pet
*.drvpn.sturms.com *.ftp.sturms.com sturms.com *.sturms.com *.ww1.sturms.com
*.h5.vsvtba.com *.portal.vsvtba.com vsvtba.com *.vsvtba.com *.wildcard.vsvtba.com
*.wildcard.wyndhamvacatonresorts.com *.ww38.wyndhamvacatonresorts.com wyndhamvacatonresorts.com *.wyndhamvacatonresorts.com
*.38.xn--ok0bv9hm4dy6wd0o.site *.api.xn--ok0bv9hm4dy6wd0o.site *.dev.xn--ok0bv9hm4dy6wd0o.site *.eb.xn--ok0bv9hm4dy6wd0o.site *.ir40yw80fy9eqtc3.xn--ok0bv9hm4dy6wd0o.site *.m.xn--ok0bv9hm4dy6wd0o.site *.wildcard.xn--ok0bv9hm4dy6wd0o.site *.ww25.xn--ok0bv9hm4dy6wd0o.site *.ww38.xn--ok0bv9hm4dy6wd0o.site xn--ok0bv9hm4dy6wd0o.site *.xn--ok0bv9hm4dy6wd0o.site
*.66kigu9.yoomaker.net *.fv1qdd.yoomaker.net *.wpujmz7.yoomaker.net *.ww25.yoomaker.net *.y0kc4q.yoomaker.net yoomaker.net *.yoomaker.net
*.ww25.yp007.tv yp007.tv *.yp007.tv