Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tinkerbox.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 24, 2026
Valid Until
August 22, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9D:47:DF:1F:B0:73:51:7A:FA:EE:8E:37:CC:CD:87:6C:22:EC:DD:CB:77:09:13:CC:DA:C2:F8:F2:E3:C5:6B:FD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
pg0002.my
*.pg0002.my
115533jj.cc
*.115533jj.cc
117755jj.cc
*.117755jj.cc
18263301xl01.top
*.18263301xl01.top
2t87768.com
*.2t87768.com
410370.lol
*.410370.lol
42204.blog
*.42204.blog
42583.my
*.42583.my
503367.lol
*.503367.lol
504397.lol
*.504397.lol
516173.lol
*.516173.lol
66734.town
*.66734.town
715003.lol
*.715003.lol
719006.my
*.719006.my
8wy64p.cc
*.8wy64p.cc
932wy.top
*.932wy.top
*.annelise-co.annelise.co
annelise.co
*.annelise.co
*.annelisew-training.annelise.co
*.annelisewoitulewicz.annelise.co
*.awcoaching-co.annelise.co
atrnos.me
*.atrnos.me
*.ayush773.atrnos.me
*.bettasmp.atrnos.me
*.felixistdumm.atrnos.me
*.hellosmpxwni.atrnos.me
*.kashimo9.atrnos.me
*.random.atrnos.me
*.saq6.atrnos.me
*.tjbe.atrnos.me
*.vcgkihellosmpxwni.atrnos.me
*.ww38.atrnos.me
ayy37.com
*.ayy37.com
b4il39.cyou
*.b4il39.cyou
backupwatcher.com
*.backupwatcher.com
bonaventure.pro
*.bonaventure.pro
*.ww38.bonaventure.pro
bustun.com
*.bustun.com
egg-don-es-ww-e3243.sbs
*.egg-don-es-ww-e3243.sbs
freshwa.com
*.freshwa.com
haspur.com
*.haspur.com
nociter.top
*.nociter.top
onlinecasinosthatpayrealmoney.top
*.onlinecasinosthatpayrealmoney.top
reliablegreenculture.xyz
*.reliablegreenculture.xyz
tinkerbox.co
*.tinkerbox.co
*.www.tinkerbox.co
wdlay.vip
*.wdlay.vip
webuyhouseshonoluluhi.online
*.webuyhouseshonoluluhi.online
xn--wusp30j.org
*.xn--wusp30j.org
yortan.com
*.yortan.com
zamowienie-56m21xqv2dgf0znb46ryp1.onl
*.zamowienie-56m21xqv2dgf0znb46ryp1.onl
zesza.cc
*.zesza.cc
Other domains in certificate