Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=12793.my
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 04, 2026
Valid Until
August 02, 2026
53 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
63:F2:DD:2E:95:0F:52:F9:C2:81:B7:41:3B:1F:85:5A:E2:AE:1B:BF:B6:E1:BC:BC:70:7E:7F:97:73:6C:94:B2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
anhosting.top
*.anhosting.top
12793.my
*.12793.my
16912.my
*.16912.my
25269.qpon
*.25269.qpon
32696.my
*.32696.my
448323v.cc
*.448323v.cc
49sx.com
*.49sx.com
51cgz.fun
*.51cgz.fun
63908.one
*.63908.one
80eb.cc
*.80eb.cc
83378.lgbt
*.83378.lgbt
9001rf.xyz
*.9001rf.xyz
99339.my
*.99339.my
ahicn.com
*.ahicn.com
aismartmatic.com
*.aismartmatic.com
arntoyond.com
*.arntoyond.com
aryangrg.xyz
*.aryangrg.xyz
autoenginellc.com
*.autoenginellc.com
bluestarthailand.com
*.bluestarthailand.com
buzzbig.com
*.buzzbig.com
cedarskennewick.com
*.cedarskennewick.com
citi-bank.info
*.citi-bank.info
corporate-minds.com
*.corporate-minds.com
cryptocurrencygui.top
*.cryptocurrencygui.top
datsja.com
*.datsja.com
debet.tokyo
*.debet.tokyo
dqwzi39153.xyz
*.dqwzi39153.xyz
dxwy057.club
*.dxwy057.club
envie2e-49.fr
*.envie2e-49.fr
erectile-dysfunction-treatments-shares-019.sbs
*.erectile-dysfunction-treatments-shares-019.sbs
esepworld.com
*.esepworld.com
flexisoin.xyz
*.flexisoin.xyz
gamechanger4biz.com
*.gamechanger4biz.com
gapkey.com
*.gapkey.com
gqbuuzau3l.xyz
*.gqbuuzau3l.xyz
greatest.baby
*.greatest.baby
hockeystackbuild.com
*.hockeystackbuild.com
hockeystackdev.com
*.hockeystackdev.com
hushabye.baby
*.hushabye.baby
itsgalahad.co
*.itsgalahad.co
melqu.auction
*.melqu.auction
nhbnbnk.com
*.nhbnbnk.com
tehky.gdn
*.tehky.gdn
upsidedowninsideout.tech
*.upsidedowninsideout.tech
xiaoniao2.buzz
*.xiaoniao2.buzz
Other domains in certificate