Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=massagezentop.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:E4:2B:0B:2F:EC:22:FC:0B:94:B4:49:06:3B:72:06:A8:49:3F:22:F9:BD:D7:42:26:8E:77:B8:B0:F8:34:2C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
mpas.it
*.mpas.it
sanctum.co.in
*.sanctum.co.in
massage-chairs-th.click
*.massage-chairs-th.click
massagezentop.com
*.massagezentop.com
masterwin44.org
*.masterwin44.org
mdsone.com
*.mdsone.com
medicalpro12.com
*.medicalpro12.com
mercadante.it
*.mercadante.it
mffrn.gdn
*.mffrn.gdn
moneyplanet.it
*.moneyplanet.it
mostbet-h9zm.xyz
*.mostbet-h9zm.xyz
nlife.co
*.nlife.co
nljqf.net
*.nljqf.net
nlm2hqzp6xoz5w2.top
*.nlm2hqzp6xoz5w2.top
nltio.pro
*.nltio.pro
nluut.tv
*.nluut.tv
nlwxe.net
*.nlwxe.net
pdfdownloader.org
*.pdfdownloader.org
phuoj.com
*.phuoj.com
pilarft.info
*.pilarft.info
play-phantom-fury.xyz
*.play-phantom-fury.xyz
play-zenith-ward.xyz
*.play-zenith-ward.xyz
promiselandproperties.com
*.promiselandproperties.com
qixfyze.com
*.qixfyze.com
readfundzone.com
*.readfundzone.com
rentabulldozer.com
*.rentabulldozer.com
rikhtt.com
*.rikhtt.com
safmasofalsf.com
*.safmasofalsf.com
scommessesportiveonline.it
*.scommessesportiveonline.it
seatoncapital.net
*.seatoncapital.net
shoes-shops.us
*.shoes-shops.us
shopifysupport.xyz
*.shopifysupport.xyz
sinkeey.com
*.sinkeey.com
skaaragnmonioasdatuphub.cyou
*.skaaragnmonioasdatuphub.cyou
skyvino.com
*.skyvino.com
smartbet.net
*.smartbet.net
sporter-x.co
*.sporter-x.co
thai99king.online
*.thai99king.online
thevirtualonlineassistant.com
*.thevirtualonlineassistant.com
thruebook.us
*.thruebook.us
tinyhouseplants.com
*.tinyhouseplants.com
trentpackltd.com
*.trentpackltd.com
troposphericwater.com
*.troposphericwater.com
tunein.me
*.tunein.me
v0rv1fe9mu.icu
*.v0rv1fe9mu.icu
Other domains in certificate