Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=paypaol.de
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 08, 2026
Valid Until
April 08, 2026 57 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D1:7F:DA:DE:FB:66:F4:ED:D4:FF:57:9B:D8:2F:BA:A2:85:D6:21:63:B9:83:D1:68:F5:37:29:CF:EA:6D:6E:CC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

71 domains
ossil.com *.ossil.com *.hnna.ossil.com *.m.ossil.com *.ww16.ossil.com *.ww17.ossil.com

Other domains in certificate

ayrshire-roots.co.uk *.ayrshire-roots.co.uk *.www.ayrshire-roots.co.uk
brasilvigente.online *.brasilvigente.online *.hkrcxqvqup.brasilvigente.online *.postmaster.brasilvigente.online
cripto-money.space *.cripto-money.space
discountinfraredsaunasop.space *.discountinfraredsaunasop.space *.report.discountinfraredsaunasop.space
helocrates.xyz *.helocrates.xyz *.ww25.helocrates.xyz
kubacraftleather.com *.kubacraftleather.com *.www.kubacraftleather.com
*.admin.lampubagus38.click *.api.lampubagus38.click *.app.lampubagus38.click *.cpanel.lampubagus38.click *.cpcontacts.lampubagus38.click *.demo.lampubagus38.click *.dev.lampubagus38.click *.ftp.lampubagus38.click lampubagus38.click *.lampubagus38.click *.mail.lampubagus38.click *.test.lampubagus38.click *.webdisk.lampubagus38.click *.webmail.lampubagus38.click *.whm.lampubagus38.click
luoli345.info *.luoli345.info *.random.luoli345.info
*.cmajors.mycmg.org *.hhanson.mycmg.org *.jdalton.mycmg.org mycmg.org *.mycmg.org *.portal.mycmg.org *.vdalton.mycmg.org *.web.mycmg.org *.ww25.mycmg.org *.ww38.mycmg.org
paypaol.de *.paypaol.de
*.musicas.playviciorp.com playviciorp.com *.playviciorp.com *.teste.playviciorp.com
reuby.de *.reuby.de
*.random.wohnmobilmagazin.de wohnmobilmagazin.de *.wohnmobilmagazin.de
worldofdavidwilliams.com *.worldofdavidwilliams.com
wwwsheetz.com *.wwwsheetz.com
x-hampster.com *.x-hampster.com
xn--getrnkerechner-8hb.de *.xn--getrnkerechner-8hb.de