Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=thecontroltower.club
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 06, 2026
Valid Until
April 06, 2026
52 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BC:B1:C0:AB:77:11:80:98:CF:D2:1B:3B:DA:E5:7C:7E:21:61:28:AD:F4:E5:8C:60:6E:9B:9E:1E:C9:00:EE:EF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
68 domains
order-global.cc
*.order-global.cc
*.ccww25.order-global.cc
123allan.live
*.123allan.live
arcasiangrocer.store
*.arcasiangrocer.store
*.cpcalendars.arcasiangrocer.store
beautifiedclothing.world
*.beautifiedclothing.world
*.appliances.blogmyfriend.tech
blogmyfriend.tech
*.blogmyfriend.tech
*.news.blogmyfriend.tech
bolista.biz
*.bolista.biz
*.ww38.bolista.biz
*.com.earthanimalrights.org
earthanimalrights.org
*.earthanimalrights.org
*.webmail.earthanimalrights.org
hockeyweb.xyz
*.hockeyweb.xyz
*.hw.hockeyweb.xyz
*.hp.lamail.xyz
lamail.xyz
*.lamail.xyz
ligamansion2nhk.site
*.ligamansion2nhk.site
*.m.ligamansion2nhk.site
manhwahentai.site
*.manhwahentai.site
*.smtps.manhwahentai.site
*.lime.meetpowerheal.space
meetpowerheal.space
*.meetpowerheal.space
nmqdr.online
*.nmqdr.online
*.wwww.nmqdr.online
paunitescoalition.org
*.paunitescoalition.org
peliculasfi.co
*.peliculasfi.co
*.m.pendletvl.com
pendletvl.com
*.pendletvl.com
serverpk.online
*.serverpk.online
*.sindh-avls.serverpk.online
*.localhost.somaconamorbq.store
somaconamorbq.store
*.somaconamorbq.store
*.cpanel.thecontroltower.club
*.cpcalendars.thecontroltower.club
*.crm.thecontroltower.club
*.insurancebusiness.thecontroltower.club
*.mail.thecontroltower.club
thecontroltower.club
*.thecontroltower.club
*.webdisk.thecontroltower.club
*.webmail.thecontroltower.club
*.admin.vods.top
*.newsmarters.vods.top
vods.top
*.vods.top
*.ns1.waswc.org
waswc.org
*.waswc.org
Other domains in certificate