Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=08708.my
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 23, 2026
Valid Until
July 22, 2026
48 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
22:EE:24:CD:59:7D:E6:CF:FF:D0:94:42:BE:2A:82:8B:1D:33:5B:D6:7E:46:E3:F9:19:AE:DB:82:E5:55:AD:62
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
otoauto.net
*.otoauto.net
08708.my
*.08708.my
253.sx
*.253.sx
256.gg
*.256.gg
27173.co
*.27173.co
293844.co
*.293844.co
41554.my
*.41554.my
721i.cc
*.721i.cc
759361.one
*.759361.one
79321.one
*.79321.one
88848.one
*.88848.one
89488.one
*.89488.one
90788.one
*.90788.one
94168.toys
*.94168.toys
964496.com
*.964496.com
aviatargame.com
*.aviatargame.com
aviatarplay.com
*.aviatarplay.com
capitaofilmes.net
*.capitaofilmes.net
citieschange.click
*.citieschange.click
citylifeimpact.click
*.citylifeimpact.click
clade.my
*.clade.my
clarityfitnessinsight.run
*.clarityfitnessinsight.run
dingli-zhuangpiyouyou.top
*.dingli-zhuangpiyouyou.top
gold-jllr.today
*.gold-jllr.today
gourmetbelief.food
*.gourmetbelief.food
goyns.co
*.goyns.co
hdrezka-ag.com
*.hdrezka-ag.com
itiexamhelp.com
*.itiexamhelp.com
jibonjuddho.com
*.jibonjuddho.com
karsanicvedisticaret.com
*.karsanicvedisticaret.com
lakhashoes.com
*.lakhashoes.com
lihbih.com
*.lihbih.com
millsfreight.com
*.millsfreight.com
netmirrors.net
*.netmirrors.net
p3bjdtk.cc
*.p3bjdtk.cc
retirement-planning-online.sbs
*.retirement-planning-online.sbs
srnwin.net
*.srnwin.net
surveysforu.com
*.surveysforu.com
the123movies.com
*.the123movies.com
urlink.net
*.urlink.net
veryfastmovie.com
*.veryfastmovie.com
w13721206.com
*.w13721206.com
w13729792.com
*.w13729792.com
webpetfamily.com
*.webpetfamily.com
zksztp.top
*.zksztp.top
Other domains in certificate