Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=mancity.academy
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 13, 2026
Valid Until
April 13, 2026
56 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:F9:51:E1:97:6C:EF:5D:E1:8A:8D:42:EC:61:8C:15:28:48:AD:00:BB:4F:F7:96:1F:A5:60:AE:21:16:4A:53
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
netblend.cfd
*.netblend.cfd
3rgpyh.cfd
*.3rgpyh.cfd
aglestari.co
*.aglestari.co
agnt.life
*.agnt.life
*.ww25.agnt.life
animelatinohd.co
*.animelatinohd.co
cadmiumquoit313.cfd
*.cadmiumquoit313.cfd
cassino.life
*.cassino.life
cryptonexa.live
*.cryptonexa.live
*.ww38.cryptonexa.live
digmizedeal.click
*.digmizedeal.click
*.aa.gf2sn8pw.com
*.ce25e10b-9a05-467e-851e-04896b3ad80d.gf2sn8pw.com
*.cloud.gf2sn8pw.com
gf2sn8pw.com
*.gf2sn8pw.com
*.htjolrd.gf2sn8pw.com
*.m.gf2sn8pw.com
*.rd.gf2sn8pw.com
*.rds.gf2sn8pw.com
*.rdweb.gf2sn8pw.com
*.remote.gf2sn8pw.com
*.wildcard.gf2sn8pw.com
inspire-deals.xyz
*.inspire-deals.xyz
ljlseo366.icu
*.ljlseo366.icu
mail-etan.fr
*.mail-etan.fr
*.blog.mancity.academy
mancity.academy
*.mancity.academy
*.old.mancity.academy
*.shop.mancity.academy
*.ww38.mancity.academy
*.calendly.manpowergroup.work
manpowergroup.work
*.manpowergroup.work
*.random.manpowergroup.work
*.ww38.manpowergroup.work
mimisenling.cfd
*.mimisenling.cfd
myinsider6.club
*.myinsider6.club
mymetroclim.com
*.mymetroclim.com
nexusbyte.cfd
*.nexusbyte.cfd
*.jiko.oject.co.uk
oject.co.uk
*.oject.co.uk
*.thelandpr.oject.co.uk
*.host.practicasinclusion.org
practicasinclusion.org
*.practicasinclusion.org
promotion-carte-avantages.com
*.promotion-carte-avantages.com
*.sncf.promotion-carte-avantages.com
roamans.club
*.roamans.club
rucira.io
*.rucira.io
sharktracks.co.uk
*.sharktracks.co.uk
*.synchroma.sharktracks.co.uk
*.vacuumscience.sharktracks.co.uk
shop-beyonce.co
*.shop-beyonce.co
sprucehub.co
*.sprucehub.co
stillmanvalleyhigh.org
*.stillmanvalleyhigh.org
*.ww38.stillmanvalleyhigh.org
swavekiqs.fr
*.swavekiqs.fr
vecrank.com
*.vecrank.com
worntv.net
*.worntv.net
zcxas.cfd
*.zcxas.cfd
Other domains in certificate