Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=olivenza.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 17, 2026
Valid Until
May 18, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F2:59:46:0C:9E:79:DF:83:32:42:03:68:1F:7B:CC:8E:34:86:C3:45:BE:4B:C5:3B:1C:D4:63:2A:A0:3E:9A:26
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
nopalina.site *.nopalina.site

Other domains in certificate

bluechoicesc.co *.bluechoicesc.co *.ftp.bluechoicesc.co
*.blueice.bofanfuliao.com bofanfuliao.com *.bofanfuliao.com *.gae.bofanfuliao.com *.qresolve.bofanfuliao.com *.rwg.bofanfuliao.com *.sadpc.bofanfuliao.com *.wildcard.bofanfuliao.com
customizedhandbags.com *.customizedhandbags.com *.ww16.customizedhandbags.com *.ww25.customizedhandbags.com
cyberforum.space *.cyberforum.space
doujins.it *.doujins.it
*.m.mothherless.com mothherless.com *.mothherless.com *.ww25.mothherless.com *.ww38.mothherless.com
*.demo.nativeceramics.com *.kpr6wfo5bo.nativeceramics.com nativeceramics.com *.nativeceramics.com *.sitemap.nativeceramics.com *.wildcard.nativeceramics.com
newroadbookstore.com *.newroadbookstore.com
olivenza.com *.olivenza.com *.sitemap.olivenza.com *.store.olivenza.com *.wiki.olivenza.com *.ww11.olivenza.com *.ww17.olivenza.com
*.hostmaster.overskirt.com *.m.overskirt.com overskirt.com *.overskirt.com *.store.overskirt.com *.wiki.overskirt.com *.ww25.overskirt.com
pcbmarketplace.com *.pcbmarketplace.com *.vpn.pcbmarketplace.com *.wildcard.pcbmarketplace.com
phoenixvillebeerwinefestival.com *.phoenixvillebeerwinefestival.com
project-id.com *.project-id.com *.random.project-id.com *.wildcard.project-id.com *.www.project-id.com
*.autodiscover.rakuen.com *.bal.rakuen.com *.budo.rakuen.com *.global.rakuen.com *.m.rakuen.com *.mx02.rakuen.com *.op.rakuen.com rakuen.com *.rakuen.com *.ww16.rakuen.com *.ww17.rakuen.com *.ww25.rakuen.com
rigbycattlecompany.com *.rigbycattlecompany.com
simperdakom.com *.simperdakom.com
staking2.com *.staking2.com
*.hostmaster.thetruechurch.com thetruechurch.com *.thetruechurch.com *.ww1.thetruechurch.com *.ww25.thetruechurch.com
*.hls.tvday.me tvday.me *.tvday.me *.us.tvday.me
*.wildcard.yttbuy.com yttbuy.com *.yttbuy.com