Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=za-factory-building-insurance-lpx.click
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 07, 2026
Valid Until
April 07, 2026 54 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:6F:57:1D:AE:0B:8C:57:76:4A:5F:D9:DB:B6:F0:A0:A7:55:68:E2:7B:DB:35:31:3C:29:8F:42:B7:76:7F:AF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
pcl.com.pl *.pcl.com.pl

Other domains in certificate

5gkacyh.com *.5gkacyh.com *.random.5gkacyh.com
5startstudents.com *.5startstudents.com
76k.bet *.76k.bet
adisued.de *.adisued.de
afl.de *.afl.de
agg.de *.agg.de
amisroutiers.com *.amisroutiers.com
colocaterreendirect.com *.colocaterreendirect.com
*.access.dekleijn.com *.app.dekleijn.com *.crm.dekleijn.com dekleijn.com *.dekleijn.com *.desktops1.dekleijn.com *.hostmaster.dekleijn.com *.mailrelay.dekleijn.com *.mta.dekleijn.com *.mx5.dekleijn.com *.portal.dekleijn.com *.virtualaccess.dekleijn.com *.virtualaccess1.dekleijn.com *.vpn2.dekleijn.com *.vpnssl.dekleijn.com *.webaccess.dekleijn.com *.www.dekleijn.com
evanwirt.com *.evanwirt.com
exiletracker.io *.exiletracker.io
*.anthem.experionidworks.com experionidworks.com *.experionidworks.com *.wildcard.experionidworks.com
f-g.de *.f-g.de
*.admin.fptjob.com *.airflow.fptjob.com *.api.fptjob.com *.argo.fptjob.com *.bi.fptjob.com *.demo.fptjob.com *.dev.fptjob.com fptjob.com *.fptjob.com *.home.fptjob.com *.hostmaster.fptjob.com *.jjz6hjqi2pe0jpev.fptjob.com *.m.fptjob.com *.mail.fptjob.com *.mobile.fptjob.com *.news.fptjob.com *.report.fptjob.com *.shop.fptjob.com *.superset.fptjob.com *.test.fptjob.com *.wap.fptjob.com *.web.fptjob.com *.ww1.fptjob.com *.wwww.fptjob.com
parsnip.com.au *.parsnip.com.au
*.random.retirementinvesting.com.au retirementinvesting.com.au *.retirementinvesting.com.au
*.mail.sellarpropertygroup.com *.random.sellarpropertygroup.com sellarpropertygroup.com *.sellarpropertygroup.com
sleevesurgery.net *.sleevesurgery.net
t-j.de *.t-j.de
*.admin.za-factory-building-insurance-lpx.click *.www.za-factory-building-insurance-lpx.click za-factory-building-insurance-lpx.click *.za-factory-building-insurance-lpx.click
zxs.de *.zxs.de