Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=veteransjournal.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
87 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
20:2F:6B:CD:22:86:66:CB:9A:E5:C4:5E:DF:39:AF:9D:B5:08:FC:7B:AC:10:43:EF:ED:39:47:BA:37:15:67:92
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
neotropics.com
*.neotropics.com
*.api.neotropics.com
*.assets.neotropics.com
*.access.beeg.fan
*.ambari.beeg.fan
*.assets.beeg.fan
beeg.fan
*.beeg.fan
*.cci.beeg.fan
*.centos.beeg.fan
*.doh.beeg.fan
*.guardian.beeg.fan
*.ww25.beeg.fan
*.admin.kimchidiet.com
*.app.kimchidiet.com
*.assets.kimchidiet.com
kimchidiet.com
*.kimchidiet.com
*.ww16.kimchidiet.com
*.app.pitching.top
*.djqf.pitching.top
*.dnjn.pitching.top
*.gngj.pitching.top
*.hbuxtntsn.pitching.top
*.izse.pitching.top
*.mail.pitching.top
*.mngz.pitching.top
*.notexistswgjn.pitching.top
pitching.top
*.pitching.top
*.pshl.pitching.top
*.qcpq.pitching.top
*.tdgw.pitching.top
*.tnsf.pitching.top
*.wblj.pitching.top
*.yrtn.pitching.top
*.zwnb.pitching.top
*.anyconnect.sertlesme.com
*.apps.sertlesme.com
*.assets.sertlesme.com
*.gateway.sertlesme.com
*.m.sertlesme.com
sertlesme.com
*.sertlesme.com
*.vpn.sertlesme.com
*.access.tifus.com
*.aolydsitemap.tifus.com
*.api.tifus.com
*.apps.tifus.com
*.assets.tifus.com
*.dev.tifus.com
*.hostmaster.tifus.com
*.j.tifus.com
tifus.com
*.tifus.com
*.ww25.tifus.com
*.access.veteransjournal.com
*.anyconnect.veteransjournal.com
*.apps.veteransjournal.com
*.assets.veteransjournal.com
*.clientesvpn.veteransjournal.com
*.m.veteransjournal.com
*.staging.veteransjournal.com
veteransjournal.com
*.veteransjournal.com
*.vpn.veteransjournal.com
*.vpnssl.veteransjournal.com
*.apps.werthmann.com
*.assets.werthmann.com
*.comune.werthmann.com
*.gateway.werthmann.com
*.ts.werthmann.com
*.vdi.werthmann.com
werthmann.com
*.werthmann.com
*.ww11.werthmann.com
*.ww16.werthmann.com
*.anyconnect.yuuri.com
*.apps.yuuri.com
*.assets.yuuri.com
*.comune.yuuri.com
*.gateway.yuuri.com
*.ns.yuuri.com
*.portal.yuuri.com
*.ww1.yuuri.com
*.ww16.yuuri.com
yuuri.com
*.yuuri.com
Other domains in certificate