76/100 SECURITY SCORE

Certificate Information

Subject
CN=nsdlpancard.site
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 16, 2026
Valid Until
August 14, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FE:F0:4E:BC:80:AC:34:A1:2B:49:9D:CB:7C:ED:F0:8C:F7:F6:90:93:CC:CB:F9:EE:1A:1B:AD:CE:F1:78:92:38
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
envidia.it *.envidia.it *.dashboard.envidia.it *.data.envidia.it *.dev.envidia.it *.email.envidia.it *.imap.envidia.it *.mail.envidia.it *.mx.envidia.it *.mymail.envidia.it *.notexistsapi.envidia.it *.officevpn.envidia.it *.rdweb.envidia.it *.report.envidia.it *.smtp.envidia.it *.superset.envidia.it *.webmail.envidia.it

Other domains in certificate

665358a.buzz *.665358a.buzz *.665358com-k3ir5.665358a.buzz
*.0.aea.org *.0mnh4.aea.org aea.org *.aea.org *.aeevt.aea.org *.arizona.aea.org *.cuwab20.aea.org *.siscom.aea.org *.top-offers.aea.org *.tp.aea.org *.training.aea.org *.ww.aea.org
camaraprivada.com *.camaraprivada.com *.sasporn.camaraprivada.com *.thepornlinks.camaraprivada.com
*.analyze.cybermonday-deals.site *.bi.cybermonday-deals.site cybermonday-deals.site *.cybermonday-deals.site *.demo.cybermonday-deals.site *.development.cybermonday-deals.site *.fw.cybermonday-deals.site *.insight-test.cybermonday-deals.site *.integration.cybermonday-deals.site *.qa.cybermonday-deals.site *.staging-viz.cybermonday-deals.site *.staging.cybermonday-deals.site *.superset-demo.cybermonday-deals.site *.uat.cybermonday-deals.site *.ww38.cybermonday-deals.site *.www.cybermonday-deals.site
domainassessments.com *.domainassessments.com *.random.domainassessments.com
*.dhl.espbenefit.com espbenefit.com *.espbenefit.com *.olx-uz.espbenefit.com *.proxy.espbenefit.com *.sberbank.espbenefit.com
*.com.hans-joachim-kuehn.de *.de.hans-joachim-kuehn.de hans-joachim-kuehn.de *.hans-joachim-kuehn.de *.nl.hans-joachim-kuehn.de *.online.hans-joachim-kuehn.de *.pl.hans-joachim-kuehn.de
hilltopassets.com *.hilltopassets.com *.test.hilltopassets.com
*.id.nsdlpancard.site nsdlpancard.site *.nsdlpancard.site *.plan.nsdlpancard.site *.resume.nsdlpancard.site *.site.nsdlpancard.site *.wa.nsdlpancard.site *.ww25.nsdlpancard.site
*.lhigwfkv.thoughtfulai.co *.random.thoughtfulai.co *.sitemap.thoughtfulai.co thoughtfulai.co *.thoughtfulai.co
*.kwid9.ufabet168bet.top ufabet168bet.top *.ufabet168bet.top
*.kwid9.vm9bet.top vm9bet.top *.vm9bet.top