76/100 SECURITY SCORE

Certificate Information

Subject
CN=zhouyuaa29.top
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9A:8B:39:BD:6F:FB:49:01:6A:3D:A8:D0:88:69:95:11:B0:81:E5:3C:F2:0E:7A:A3:93:30:76:F6:E2:E4:18:DF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
paintfusionworks.com *.paintfusionworks.com

Other domains in certificate

jbktk1408.com *.jbktk1408.com
jcpenneycsale.com *.jcpenneycsale.com
jicuzi.com *.jicuzi.com
*.1yme1.kfcsayapgoreng.xyz kfcsayapgoreng.xyz *.kfcsayapgoreng.xyz
kj694.info *.kj694.info
klgu04h.com *.klgu04h.com
legisio.pro *.legisio.pro
linkbet200perakpgsoft.org *.linkbet200perakpgsoft.org *.pcn5d9.linkbet200perakpgsoft.org
lu-netra.com *.lu-netra.com
mariposalakes.com *.mariposalakes.com
market-gglplay.com *.market-gglplay.com
mefyra.com *.mefyra.com
minimalpopscapes.com *.minimalpopscapes.com
minimalstyleart.com *.minimalstyleart.com
minimalworksart.com *.minimalworksart.com
nbnbttllnb.com *.nbnbttllnb.com
nextgenfurnaceagp.com *.nextgenfurnaceagp.com
nordstromronline.com *.nordstromronline.com
oberhausenobex.com *.oberhausenobex.com
objectifupdirect.com *.objectifupdirect.com
offgridsolar.co *.offgridsolar.co
official-arbitrix.com *.official-arbitrix.com
oncinhathegame.com *.oncinhathegame.com
opengrowthstudioagency.com *.opengrowthstudioagency.com
orthodoxically.com *.orthodoxically.com
paint4social.com *.paint4social.com
*.nkyehb.paintingartworks.click paintingartworks.click *.paintingartworks.click
paintminimal.com *.paintminimal.com
painttechworld.com *.painttechworld.com
pcepd448.com *.pcepd448.com
pet-adoptions2025.click *.pet-adoptions2025.click
pntly.town *.pntly.town
promodoano.sbs *.promodoano.sbs
proquupalify.com *.proquupalify.com
psvlp6.shop *.psvlp6.shop
pudndqn608.vip *.pudndqn608.vip
q2008j.top *.q2008j.top
qjsfp.app *.qjsfp.app *.www.qjsfp.app
qlsmzm.cyou *.qlsmzm.cyou
qtyhhhueh.cc *.qtyhhhueh.cc
*.38.zhouyuaa29.top zhouyuaa29.top *.zhouyuaa29.top