Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=monraz.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C4:4F:4A:16:33:FA:73:92:1F:96:E1:BD:B7:CF:37:8F:07:9F:80:69:51:81:66:B1:6E:63:B8:F9:DA:D1:7A:AE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
monraz.com
*.monraz.com
*.bqbzjstore.monraz.com
*.store.monraz.com
*.wiki.monraz.com
*.ww1.monraz.com
*.ww16.monraz.com
*.ww25.monraz.com
*.66a05721-7fee-495d-bf36-3a61a7b956b6.adyan.com
adyan.com
*.adyan.com
*.cs-test.adyan.com
*.duke.adyan.com
*.m.adyan.com
*.pinterset.adyan.com
*.ts.adyan.com
*.ww1.adyan.com
*.ww11.adyan.com
*.ww25.adyan.com
*.ww38.adyan.com
*.autodiscover.hyaty.com
*.hijaby.hyaty.com
*.hostmaster.hyaty.com
hyaty.com
*.hyaty.com
*.ww11.hyaty.com
*.ww25.hyaty.com
*.ww38.hyaty.com
*.acceptance.kinetic.bot
*.api.kinetic.bot
*.app.kinetic.bot
*.backup.kinetic.bot
*.bot.kinetic.bot
*.dev.kinetic.bot
*.hostmaster.kinetic.bot
kinetic.bot
*.kinetic.bot
*.localhost.kinetic.bot
*.m.kinetic.bot
*.nhdsiqa.kinetic.bot
*.oud.kinetic.bot
*.shop.kinetic.bot
*.test.kinetic.bot
*.v1.kinetic.bot
*.webmail.kinetic.bot
*.www.kinetic.bot
*.1cerp.mprom.com
*.api.mprom.com
*.asa.mprom.com
*.autoconfig.mprom.com
*.autodiscover.mprom.com
*.barracuda.mprom.com
*.beta.mprom.com
*.bioh.mprom.com
*.cloudgenaccess.mprom.com
*.co.mprom.com
*.dev.mprom.com
*.forticlient.mprom.com
*.gateway.mprom.com
*.globalprotect.mprom.com
*.hostmaster.mprom.com
*.icq.mprom.com
*.mail.mprom.com
*.mobileconnect.mprom.com
*.mprom-404-mail.mprom.com
*.mprom-404-mail1.mprom.com
mprom.com
*.mprom.com
*.p.mprom.com
*.rustore.mprom.com
*.sitemap.mprom.com
*.sslvpn.mprom.com
*.sso.mprom.com
*.vpn.mprom.com
*.vpn2.mprom.com
*.webmail.mprom.com
*.ww1.mprom.com
*.ww11.mprom.com
*.ww38.mprom.com
*.admin.weaothvaultpro.qpon
*.api.weaothvaultpro.qpon
*.dashboard.weaothvaultpro.qpon
*.mail.weaothvaultpro.qpon
*.mailer.weaothvaultpro.qpon
*.members.weaothvaultpro.qpon
*.stg.weaothvaultpro.qpon
weaothvaultpro.qpon
*.weaothvaultpro.qpon
zynva.xyz
*.zynva.xyz
Other domains in certificate