Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=sakura-cat1.club
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 25, 2025
Valid Until
March 25, 2026
33 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0C:EC:16:A6:EC:78:34:23:29:6F:B1:C3:36:BD:85:E4:70:1F:38:24:3B:98:5C:10:ED:0F:10:73:18:44:B5:7A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
myfreshwork.com
*.myfreshwork.com
*.bharatpe5.myfreshwork.com
*.globalfederalreservebank.myfreshwork.com
*.rmgrupofeducation.myfreshwork.com
*.sharafdg-uae.myfreshwork.com
*.sundirect-606378453475310199.myfreshwork.com
*.tadg.myfreshwork.com
*.ttst-support.myfreshwork.com
*.xxx.myfreshwork.com
bidencrimes.org
*.bidencrimes.org
bitconemine.cc
*.bitconemine.cc
christianbest.com
*.christianbest.com
*.ww38.christianbest.com
culturesinterface.com
*.culturesinterface.com
*.apps.ecomotic.com
ecomotic.com
*.ecomotic.com
*.portal.ecomotic.com
*.spb.ecomotic.com
*.ww25.ecomotic.com
gotowalmart.com
*.gotowalmart.com
*.ww38.gotowalmart.com
hcr.us
*.hcr.us
httpsbit.ly
*.httpsbit.ly
*.vn.httpsbit.ly
*.ww16.httpsbit.ly
*.ww25.httpsbit.ly
*.ww38.httpsbit.ly
imanakaoiwi.com
*.imanakaoiwi.com
*.comune.lincolnleisurevehicles.co.uk
lincolnleisurevehicles.co.uk
*.lincolnleisurevehicles.co.uk
*.mail.lincolnleisurevehicles.co.uk
*.ww25.lincolnleisurevehicles.co.uk
maze.com.au
*.maze.com.au
medicare-br-3576.click
*.medicare-br-3576.click
nimalzkidz.com
*.nimalzkidz.com
*.ww25.nimalzkidz.com
ohiohcbscoalition.org
*.ohiohcbscoalition.org
*.app.polelette.shop
*.bigboss.polelette.shop
*.boss.polelette.shop
*.dev.polelette.shop
*.home.polelette.shop
*.m.polelette.shop
*.mobile.polelette.shop
*.news.polelette.shop
polelette.shop
*.polelette.shop
*.random.polelette.shop
*.sitemap.polelette.shop
*.wap.polelette.shop
*.web.polelette.shop
*.ww25.polelette.shop
*.ww38.polelette.shop
*.www.polelette.shop
pricacy.com.br
*.pricacy.com.br
*.docs.sakura-cat1.club
sakura-cat1.club
*.sakura-cat1.club
sfk.au
*.sfk.au
tdrrsqvkcb.top
*.tdrrsqvkcb.top
techno-gamers.com
*.techno-gamers.com
*.ww38.techno-gamers.com
toursrider.com
*.toursrider.com
twoseelife.com
*.twoseelife.com
xgtxdsjncb.top
*.xgtxdsjncb.top
ywqnhhrucb.top
*.ywqnhhrucb.top
Other domains in certificate