Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=bitcoin-win.vip
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 08, 2026
Valid Until
April 08, 2026 49 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B2:33:A8:E7:3D:93:17:00:B8:0F:16:1B:47:0F:05:B6:B4:C1:83:10:9B:A5:84:A2:D2:CA:1B:74:E2:42:78:2C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ii.au *.ii.au *.17.ii.au *.c.ii.au *.dki.ii.au *.i.ii.au *.ii.ii.au *.iii.ii.au *.iinet.ii.au *.k.ii.au *.kopiengebildetwerden.ii.au *.kwanamba.ii.au *.leo.ii.au *.lm.ii.au *.namba.ii.au *.nikusubi.ii.au *.no.ii.au *.o.ii.au *.y.ii.au

Other domains in certificate

*.16.aj1574.online *.admin.aj1574.online aj1574.online *.aj1574.online *.analytic.aj1574.online *.analytics.aj1574.online *.api.aj1574.online *.app.aj1574.online *.bi.aj1574.online *.bigdata.aj1574.online *.console.aj1574.online *.dash.aj1574.online *.dashboard.aj1574.online *.dashs.aj1574.online *.data.aj1574.online *.dev.aj1574.online *.intel.aj1574.online *.internal.aj1574.online *.redash.aj1574.online *.remote.aj1574.online *.report.aj1574.online *.reporting.aj1574.online *.reports.aj1574.online *.staging.aj1574.online *.stats.aj1574.online *.status.aj1574.online *.superset-sandbox.aj1574.online *.superset.aj1574.online *.ww16.aj1574.online
bitcoin-win.vip *.bitcoin-win.vip
cdto.tech *.cdto.tech *.clip.cdto.tech *.cloud.cdto.tech *.dnk-bz.cdto.tech *.edu-release.cdto.tech *.edu.cdto.tech *.learn-dev.cdto.tech *.learn.cdto.tech *.portal.cdto.tech *.random.cdto.tech *.test.cdto.tech
*.39ir6.dropglide.xyz *.arjsbreport-preview.dropglide.xyz *.bbtkbotfix.dropglide.xyz *.d.dropglide.xyz dropglide.xyz *.dropglide.xyz *.imap.dropglide.xyz *.insight-development.dropglide.xyz *.reporting-ci.dropglide.xyz *.visual.dropglide.xyz *.ww25.dropglide.xyz *.xcauikac0t.dropglide.xyz
gcreddy.info *.gcreddy.info *.hotfix.gcreddy.info
gudfilm-0.mom *.gudfilm-0.mom *.w-af.gudfilm-0.mom *.w-hk.gudfilm-0.mom *.w-wk.gudfilm-0.mom
*.cicd.tk66.xyz tk66.xyz *.tk66.xyz *.ww38.tk66.xyz
*.adminpod4.veersafpa.xyz *.sonar.veersafpa.xyz veersafpa.xyz *.veersafpa.xyz