76/100 SECURITY SCORE

Certificate Information

Subject
CN=ecrypt.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 23, 2026
Valid Until
June 21, 2026 41 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C1:C2:D6:69:8F:DB:F8:78:DA:6A:AB:60:4D:76:FC:39:53:1C:91:7A:38:2B:8F:C1:1C:A7:AF:E4:1D:1A:E4:CB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
nationalgrigus.com *.nationalgrigus.com *.dns.nationalgrigus.com *.hostmaster.nationalgrigus.com *.mx7.nationalgrigus.com

Other domains in certificate

blackholeslabs.com *.blackholeslabs.com *.random.blackholeslabs.com *.zzrdsadmin.blackholeslabs.com
dapitta.com *.dapitta.com *.wildcard.dapitta.com
ecrypt.co.uk *.ecrypt.co.uk
*.app.hyred.eu hyred.eu *.hyred.eu
*.analytics2.internationaliving.com *.data.internationaliving.com *.dev.internationaliving.com internationaliving.com *.internationaliving.com *.metrics.internationaliving.com *.pro.internationaliving.com *.sset.internationaliving.com *.visualizations.internationaliving.com *.wildcard.internationaliving.com *.ww38.internationaliving.com
*.comune.lafabula.com lafabula.com *.lafabula.com *.ww.lafabula.com *.www.lafabula.com
*.dl.ltsstore.net ltsstore.net *.ltsstore.net *.random.ltsstore.net
*.dev.lucidatori.com lucidatori.com *.lucidatori.com *.remote.lucidatori.com
nusrath.com *.nusrath.com *.ubu.nusrath.com
nycyerhousing.co.uk *.nycyerhousing.co.uk
portia.au *.portia.au *.wildcard.portia.au *.ww38.portia.au
speedteset.de *.speedteset.de
*.hostmaster.sportbalance.it sportbalance.it *.sportbalance.it
*.admin.strapondomme.com *.hostmaster.strapondomme.com *.mail.strapondomme.com *.mail2.strapondomme.com strapondomme.com *.strapondomme.com *.ww25.strapondomme.com *.ww38.strapondomme.com *.www.strapondomme.com
suitsupply.co *.suitsupply.co
*.cpanel.thecottier.com thecottier.com *.thecottier.com
*.9ots.travisscoot.com travisscoot.com *.travisscoot.com *.ww25.travisscoot.com
*.ww38.xn--hppe-0ra.com xn--hppe-0ra.com *.xn--hppe-0ra.com
*.video.xn--mannfrmann-eeb.com *.ww16.xn--mannfrmann-eeb.com xn--mannfrmann-eeb.com *.xn--mannfrmann-eeb.com
*.ftp.yalbots.com *.qa.yalbots.com *.ww38.yalbots.com yalbots.com *.yalbots.com
*.cl.zhe.de *.ww25.zhe.de zhe.de *.zhe.de