Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=bitcoin-win.vip
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 08, 2026
Valid Until
April 08, 2026
49 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B2:33:A8:E7:3D:93:17:00:B8:0F:16:1B:47:0F:05:B6:B4:C1:83:10:9B:A5:84:A2:D2:CA:1B:74:E2:42:78:2C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ii.au
*.ii.au
*.17.ii.au
*.c.ii.au
*.dki.ii.au
*.i.ii.au
*.ii.ii.au
*.iii.ii.au
*.iinet.ii.au
*.k.ii.au
*.kopiengebildetwerden.ii.au
*.kwanamba.ii.au
*.leo.ii.au
*.lm.ii.au
*.namba.ii.au
*.nikusubi.ii.au
*.no.ii.au
*.o.ii.au
*.y.ii.au
*.16.aj1574.online
*.admin.aj1574.online
aj1574.online
*.aj1574.online
*.analytic.aj1574.online
*.analytics.aj1574.online
*.api.aj1574.online
*.app.aj1574.online
*.bi.aj1574.online
*.bigdata.aj1574.online
*.console.aj1574.online
*.dash.aj1574.online
*.dashboard.aj1574.online
*.dashs.aj1574.online
*.data.aj1574.online
*.dev.aj1574.online
*.intel.aj1574.online
*.internal.aj1574.online
*.redash.aj1574.online
*.remote.aj1574.online
*.report.aj1574.online
*.reporting.aj1574.online
*.reports.aj1574.online
*.staging.aj1574.online
*.stats.aj1574.online
*.status.aj1574.online
*.superset-sandbox.aj1574.online
*.superset.aj1574.online
*.ww16.aj1574.online
bitcoin-win.vip
*.bitcoin-win.vip
cdto.tech
*.cdto.tech
*.clip.cdto.tech
*.cloud.cdto.tech
*.dnk-bz.cdto.tech
*.edu-release.cdto.tech
*.edu.cdto.tech
*.learn-dev.cdto.tech
*.learn.cdto.tech
*.portal.cdto.tech
*.random.cdto.tech
*.test.cdto.tech
*.39ir6.dropglide.xyz
*.arjsbreport-preview.dropglide.xyz
*.bbtkbotfix.dropglide.xyz
*.d.dropglide.xyz
dropglide.xyz
*.dropglide.xyz
*.imap.dropglide.xyz
*.insight-development.dropglide.xyz
*.reporting-ci.dropglide.xyz
*.visual.dropglide.xyz
*.ww25.dropglide.xyz
*.xcauikac0t.dropglide.xyz
gcreddy.info
*.gcreddy.info
*.hotfix.gcreddy.info
gudfilm-0.mom
*.gudfilm-0.mom
*.w-af.gudfilm-0.mom
*.w-hk.gudfilm-0.mom
*.w-wk.gudfilm-0.mom
*.cicd.tk66.xyz
tk66.xyz
*.tk66.xyz
*.ww38.tk66.xyz
*.adminpod4.veersafpa.xyz
*.sonar.veersafpa.xyz
veersafpa.xyz
*.veersafpa.xyz
Other domains in certificate