76/100 SECURITY SCORE

Certificate Information

Subject
CN=outdoorlighting.au
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 18, 2026
Valid Until
July 17, 2026 64 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8A:EE:75:9E:80:8F:C1:D9:FC:E6:9E:91:1F:FE:00:D9:98:58:9C:DF:5F:F4:DE:A4:B4:EE:B0:39:60:93:0E:55
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
puffinmodels.com *.puffinmodels.com *.api.puffinmodels.com *.branches.puffinmodels.com *.gwsparts.puffinmodels.com *.home.puffinmodels.com *.mail.puffinmodels.com *.mobile.puffinmodels.com *.random.puffinmodels.com *.remote.puffinmodels.com *.smtp.puffinmodels.com *.webmail.puffinmodels.com

Other domains in certificate

*.40f98c0c-f1c4-4e23-a115-a0e7ce4816b0.appsai.bot *.app.appsai.bot appsai.bot *.appsai.bot *.demo.appsai.bot *.forums.appsai.bot *.img.appsai.bot *.mbox.appsai.bot *.sip.appsai.bot *.www2.appsai.bot
*.argo.bahisnow.info bahisnow.info *.bahisnow.info *.brucegreymarketinshop.bahisnow.info *.cms.bahisnow.info *.de.bahisnow.info *.el.bahisnow.info *.elop.bahisnow.info *.erp.bahisnow.info *.forum.bahisnow.info *.forums.bahisnow.info *.invoice.bahisnow.info *.l.bahisnow.info *.m.bahisnow.info *.magencrm.bahisnow.info *.manage.bahisnow.info *.marketplace.bahisnow.info *.mobile.bahisnow.info *.ns1.bahisnow.info *.pc.bahisnow.info *.pos.bahisnow.info *.sandbox.bahisnow.info *.shalomconfeccom.bahisnow.info *.shop.bahisnow.info *.signup.bahisnow.info *.sitemaps.bahisnow.info *.smtp.bahisnow.info *.ss.bahisnow.info *.tkboard.bahisnow.info *.tor-corporatssl.bahisnow.info *.v.bahisnow.info *.wa.bahisnow.info *.webmail.bahisnow.info *.wwwplst.bahisnow.info
*.a.euphogummies.com *.api.euphogummies.com euphogummies.com *.euphogummies.com *.mailer.euphogummies.com *.stg.euphogummies.com *.v2.euphogummies.com
*.29751392-5a26-4b0f-be91-c92f7d4da772.milletproperty.com *.67beebeb-d082-44ff-aaa2-d8f37f386b52.milletproperty.com *.admin.milletproperty.com *.app.milletproperty.com *.assets.milletproperty.com *.autodiscover.milletproperty.com *.demo.milletproperty.com *.dev.milletproperty.com *.exchange.milletproperty.com *.haqycadmin.milletproperty.com *.homologacao.milletproperty.com *.hostmaster.milletproperty.com *.landings.milletproperty.com *.login.milletproperty.com *.mail.milletproperty.com *.mailserver.milletproperty.com milletproperty.com *.milletproperty.com *.portal.milletproperty.com *.remote.milletproperty.com *.rnepha.milletproperty.com *.sitemap.milletproperty.com *.webmail.milletproperty.com *.www.milletproperty.com
outdoorlighting.au *.outdoorlighting.au