Open
Cached
·
just now
79/100
SECURITY SCORE
Certificate Information
Subject
CN=montrekbrasil.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 29, 2026
Valid Until
April 29, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EE:82:2B:24:53:B2:9E:D6:B9:60:33:89:5E:FF:75:B2:D3:48:2D:89:CC:01:66:8B:6E:55:73:3D:90:C9:32:9C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
namesofangels.com
*.namesofangels.com
boostaro.pro
*.boostaro.pro
gototmeeting.com
*.gototmeeting.com
hangtags.cc
*.hangtags.cc
ibuzzusa.com
*.ibuzzusa.com
idolaasik.com
*.idolaasik.com
import-autoworks.com
*.import-autoworks.com
ineedtopaymybills.com
*.ineedtopaymybills.com
inpresspni.com
*.inpresspni.com
jaxcrawford.com
*.jaxcrawford.com
jettohire.com
*.jettohire.com
jpmgpt.com
*.jpmgpt.com
katuzen.com
*.katuzen.com
kervansaraybeach.com
*.kervansaraybeach.com
leadsessentialteam.com
*.leadsessentialteam.com
lgolivebl.com
*.lgolivebl.com
link268always.com
*.link268always.com
liztravel.com
*.liztravel.com
lmwinternational.com
*.lmwinternational.com
mailshard.com
*.mailshard.com
mailtalker.com
*.mailtalker.com
melbetfinder.com
*.melbetfinder.com
*.bjudyblackmore.montrekbrasil.com
*.correo.montrekbrasil.com
*.email.montrekbrasil.com
*.ex02.montrekbrasil.com
*.exchange.montrekbrasil.com
*.mail.montrekbrasil.com
*.mail3.montrekbrasil.com
montrekbrasil.com
*.montrekbrasil.com
*.mymail.montrekbrasil.com
*.outlook.montrekbrasil.com
*.owa.montrekbrasil.com
*.portal.montrekbrasil.com
*.remote.montrekbrasil.com
*.remote2.montrekbrasil.com
*.sslvpn.montrekbrasil.com
*.sslvpn2.montrekbrasil.com
*.sslvpn3.montrekbrasil.com
*.vpn.montrekbrasil.com
*.vpn2.montrekbrasil.com
*.vpn3.montrekbrasil.com
*.webmail.montrekbrasil.com
*.ww25.montrekbrasil.com
mpo08vibes.com
*.mpo08vibes.com
mysterymejaslot.com
*.mysterymejaslot.com
myvideogametruck.com
*.myvideogametruck.com
nec-igo.com
*.nec-igo.com
ngmacplayer.com
*.ngmacplayer.com
ngomonghung.gallery
*.ngomonghung.gallery
openretellaiapp.com
*.openretellaiapp.com
orrhotherapy.com
*.orrhotherapy.com
*.ha.tansunion.ca
*.ocs.tansunion.ca
*.ocs3.tansunion.ca
tansunion.ca
*.tansunion.ca
yayoins.com
*.yayoins.com
Other domains in certificate