Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=phantom-mail.io
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026
72 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:D7:B4:3B:96:82:AA:DB:95:4E:8A:C2:5C:33:FF:81:12:7C:0E:88:0B:FE:3E:C3:EC:7E:DF:2F:0B:F6:A6:1C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
tccverify.com
*.tccverify.com
02044.one
*.02044.one
160x36.cc
*.160x36.cc
377202.xyz
*.377202.xyz
3833sh.cc
*.3833sh.cc
489600.vip
*.489600.vip
74777a.tv
*.74777a.tv
74777b.tv
*.74777b.tv
74777c.tv
*.74777c.tv
86a1.com
*.86a1.com
882601.my
*.882601.my
884873.cc
*.884873.cc
9hcfd62h6.world
*.9hcfd62h6.world
a399jys.top
*.a399jys.top
allenmiles.xyz
*.allenmiles.xyz
bee246c.top
*.bee246c.top
bejomen.lol
*.bejomen.lol
boldheartapp.cyou
*.boldheartapp.cyou
conduentconnectt.site
*.conduentconnectt.site
elephantmunchingcontest.site
*.elephantmunchingcontest.site
excwff.my
*.excwff.my
fs059568.cc
*.fs059568.cc
fullstopiq.com
*.fullstopiq.com
grandchasemobile.org
*.grandchasemobile.org
lordfilm-ss.site
*.lordfilm-ss.site
madreporarian.com
*.madreporarian.com
okfact.xyz
*.okfact.xyz
*.admin.phantom-mail.io
*.api.phantom-mail.io
*.beta.phantom-mail.io
*.comune.phantom-mail.io
*.dashboard.phantom-mail.io
*.mail.phantom-mail.io
*.mail1.phantom-mail.io
*.mailx.phantom-mail.io
*.net.phantom-mail.io
phantom-mail.io
*.phantom-mail.io
*.portal.phantom-mail.io
*.postmaster.phantom-mail.io
*.whm.phantom-mail.io
*.ww25.phantom-mail.io
*.ww38.phantom-mail.io
*.www.phantom-mail.io
pozsex.xyz
*.pozsex.xyz
prostatricum.bio
*.prostatricum.bio
*.ww38.prostatricum.bio
realfathers.org
*.realfathers.org
scoreseeker249.top
*.scoreseeker249.top
srp515h.top
*.srp515h.top
ymsbpy.cn
*.ymsbpy.cn
yracterdeet.xyz
*.yracterdeet.xyz
z6p3.cc
*.z6p3.cc
zzz3675.top
*.zzz3675.top
Other domains in certificate