Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=kilate.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026 33 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:1B:F1:CF:E8:21:0B:12:49:B5:13:80:72:29:6B:08:48:31:83:2E:97:DC:5B:9A:34:9F:71:78:FB:D6:FE:BA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
renacer.com *.renacer.com *.ars.renacer.com *.bodega.renacer.com *.marykay.renacer.com *.shaiya.renacer.com *.uci.renacer.com

Other domains in certificate

*.autodiscover.brandincome.in brandincome.in *.brandincome.in *.mail.brandincome.in *.ns86.brandincome.in
catalogos.net *.catalogos.net *.ww16.catalogos.net *.ww25.catalogos.net
centrumjungle.cz *.centrumjungle.cz
chainfundcapital.com *.chainfundcapital.com *.ww25.chainfundcapital.com
demokrati.com *.demokrati.com
divaxcloset.com *.divaxcloset.com *.mx.divaxcloset.com *.ns2.divaxcloset.com *.users.divaxcloset.com *.ww31.divaxcloset.com
engworldwide.org *.engworldwide.org *.wildcard.engworldwide.org
*.account.firstcitizems.com firstcitizems.com *.firstcitizems.com *.propertypay.firstcitizems.com
golfspain.club *.golfspain.club *.preview.golfspain.club
*.analytics.gradi.com.au gradi.com.au *.gradi.com.au
groupe-allard.com *.groupe-allard.com *.ww25.groupe-allard.com
kensetu.com *.kensetu.com *.miyabi.kensetu.com *.takahasi.kensetu.com
*.anyconnect.kilate.com *.clientesvpn.kilate.com *.connect.kilate.com *.gateway.kilate.com *.hostmaster.kilate.com kilate.com *.kilate.com *.m.kilate.com *.mobileconnect.kilate.com *.officevpn.kilate.com *.portal.kilate.com *.rds.kilate.com *.rds1.kilate.com *.rdweb.kilate.com *.remote.kilate.com *.remoto.kilate.com *.secure.kilate.com *.ssl.kilate.com *.sslvpn.kilate.com *.studentsvpn.kilate.com *.vpn.kilate.com *.vpn2.kilate.com *.vpnssl.kilate.com *.wildcard.kilate.com *.ww11.kilate.com *.ww16.kilate.com *.ww17.kilate.com *.ww25.kilate.com *.ww38.kilate.com *.ww5.kilate.com
*.chongshengzhishouximonv.lewendushu.com *.jinyan.lewendushu.com lewendushu.com *.lewendushu.com
oldmanmu.net *.oldmanmu.net
prefabrications.com.au *.prefabrications.com.au
*.hostmaster.qizlet.live qizlet.live *.qizlet.live