Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=traveltodayhq.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 30, 2026
Valid Until
April 30, 2026
67 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A2:5F:5D:C9:E6:28:BB:08:7B:92:B3:8D:7F:15:45:FF:A5:1A:3B:88:66:12:78:D0:99:B7:BB:5C:AA:A5:B9:B2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
phonesells.com
*.phonesells.com
bankingdkb.de
*.bankingdkb.de
buywacom.com.au
*.buywacom.com.au
cddsy57.top
*.cddsy57.top
fidelityreporters.com
*.fidelityreporters.com
goldervistarealestate.com
*.goldervistarealestate.com
guardianstats.com
*.guardianstats.com
*.login.guardianstats.com
*.abc.marsaic.com
*.abhishek.marsaic.com
*.abroad.marsaic.com
*.aeroleaf.marsaic.com
*.api.marsaic.com
*.backup.marsaic.com
*.crud.marsaic.com
*.demo.marsaic.com
*.erp.marsaic.com
*.fiber.marsaic.com
*.fiberorganic.marsaic.com
*.hospitalmanagement.marsaic.com
*.hotel.marsaic.com
*.ims.marsaic.com
*.joy.marsaic.com
*.joystore.marsaic.com
*.leafaero.marsaic.com
*.lms.marsaic.com
*.manpower.marsaic.com
marsaic.com
*.marsaic.com
*.mgmt.marsaic.com
*.mis.marsaic.com
*.navajyoti.marsaic.com
*.njehss.marsaic.com
*.oliz.marsaic.com
*.organic.marsaic.com
*.organicfiber.marsaic.com
*.organicfibernyxistech.marsaic.com
*.rishi.marsaic.com
*.server.marsaic.com
*.surajkhadka.marsaic.com
*.surgical.marsaic.com
*.test.marsaic.com
*.2020.mask.com.au
*.adserver.mask.com.au
*.backup.mask.com.au
*.comune.mask.com.au
*.is.mask.com.au
*.mail.mask.com.au
mask.com.au
*.mask.com.au
*.movies.mask.com.au
*.mx.mask.com.au
*.mx7.mask.com.au
*.oftheedge.mask.com.au
*.origin.mask.com.au
*.pan.mask.com.au
*.posta.mask.com.au
*.random.mask.com.au
*.vip.mask.com.au
*.ww17.mask.com.au
meghresidency.com
*.meghresidency.com
nicereview.com
*.nicereview.com
sonisoftit.com
*.sonisoftit.com
sorawong.com
*.sorawong.com
*.ww25.sorawong.com
*.ww38.sorawong.com
*.api.swanskilltech.com
swanskilltech.com
*.swanskilltech.com
*.adfsp.temu.rs
*.assets.temu.rs
temu.rs
*.temu.rs
*.ww1.temu.rs
theporn245.cc
*.theporn245.cc
*.api.traveltodayhq.com
traveltodayhq.com
*.traveltodayhq.com
Other domains in certificate