Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=theof.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 12, 2026
Valid Until
August 10, 2026
68 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
26:08:FC:E8:21:B3:27:E7:51:4B:79:1B:0A:B3:A8:1F:C6:95:CD:BC:9B:BE:AE:D6:A6:A8:1E:F0:68:CB:1F:65
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
peacefull.io
*.peacefull.io
*.www.peacefull.io
bailuqing2.com
*.bailuqing2.com
chihauhau.com
*.chihauhau.com
*.ebay.chihauhau.com
cnp-la.org
*.cnp-la.org
*.mail.cnp-la.org
evercrestfinance.com
*.evercrestfinance.com
*.ww38.evercrestfinance.com
*.admin.exitfrom.it
*.app.exitfrom.it
*.backend.exitfrom.it
*.bi.exitfrom.it
*.dashboards.exitfrom.it
*.demo.exitfrom.it
*.dev.exitfrom.it
exitfrom.it
*.exitfrom.it
*.reports.exitfrom.it
*.staging.exitfrom.it
*.superset-integration.exitfrom.it
*.superset.exitfrom.it
gamerspitstop.store
*.gamerspitstop.store
heartrealestate.org
*.heartrealestate.org
*.www.heartrealestate.org
history-of-call.org
*.history-of-call.org
*.ww25.history-of-call.org
*.www.history-of-call.org
*.co.kink.net
kink.net
*.kink.net
*.mobile.kink.net
*.rene.kink.net
*.img1-fg.nsdme.com
nsdme.com
*.nsdme.com
*.server.nsdme.com
*.server1.nsdme.com
*.worldofcpcalendars.nsdme.com
*.ww38.nsdme.com
pelvisscan.com
*.pelvisscan.com
*.ww25.pelvisscan.com
*.hostmaster.promozionale.com
promozionale.com
*.promozionale.com
*.wildcard.promozionale.com
*.ww16.promozionale.com
*.ww17.promozionale.com
*.ww25.promozionale.com
*.ww38.promozionale.com
racik-198-sedap.pro
*.racik-198-sedap.pro
*.sitemap.racik-198-sedap.pro
*.ww38.racik-198-sedap.pro
*.la.raz.es
*.mail.raz.es
raz.es
*.raz.es
*.ww38.raz.es
slovoppasana.online
*.slovoppasana.online
succeedatwork.com
*.succeedatwork.com
*.www.succeedatwork.com
*.admin.theof.com
*.hotels.theof.com
*.s1.theof.com
theof.com
*.theof.com
*.ww25.theof.com
*.stage.togobaby.site
togobaby.site
*.togobaby.site
*.bg.wikipura.com
*.com.wikipura.com
*.hi.wikipura.com
*.tutor.wikipura.com
wikipura.com
*.wikipura.com
women-artists.org
*.women-artists.org
Other domains in certificate