Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=mcdatfred.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 03, 2026
Valid Until
August 01, 2026 36 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
19:D8:72:85:A1:7F:38:6F:63:A5:AB:44:0D:19:28:9A:0C:95:0B:13:C0:32:A0:10:93:84:53:F4:7E:98:B0:81
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
pontotony.com *.pontotony.com *.abc.pontotony.com *.ca.pontotony.com *.forms.pontotony.com *.kino.pontotony.com *.tour.pontotony.com *.v3.pontotony.com *.ww25.pontotony.com

Other domains in certificate

9dtheater.com *.9dtheater.com *.dan.9dtheater.com *.hostmaster.9dtheater.com *.mx.9dtheater.com
*.4729521.apktik.xyz apktik.xyz *.apktik.xyz *.ww38.apktik.xyz
deduce.it *.deduce.it *.hostmaster.deduce.it *.staging.deduce.it
*.admin.familytribe.it *.api.familytribe.it *.app.familytribe.it *.backend.familytribe.it familytribe.it *.familytribe.it *.hostmaster.familytribe.it *.staging.familytribe.it
funsquirrel.com *.funsquirrel.com *.m.funsquirrel.com *.random.funsquirrel.com
*.0a8hf0wl.hami-wake.buzz *.7pwmi.hami-wake.buzz *.ezi9i.hami-wake.buzz *.fksbh.hami-wake.buzz hami-wake.buzz *.hami-wake.buzz *.ihawz.hami-wake.buzz *.kkfz3.hami-wake.buzz
*.avdwznew.japanwoman.xyz japanwoman.xyz *.japanwoman.xyz *.test.japanwoman.xyz *.tmzscm.japanwoman.xyz
*.beta.mcdatfred.com *.bi.mcdatfred.com *.by.mcdatfred.com *.charge.mcdatfred.com mcdatfred.com *.mcdatfred.com *.mobile.mcdatfred.com *.staging.mcdatfred.com *.tienda.mcdatfred.com *.users.mcdatfred.com *.videos.mcdatfred.com *.windows.mcdatfred.com *.ww38.mcdatfred.com
*.mail.thebabyshop.xyz thebabyshop.xyz *.thebabyshop.xyz *.wildcard.thebabyshop.xyz *.www.thebabyshop.xyz
*.api.upretirement.com *.cumfmm.upretirement.com *.intranet.upretirement.com *.m.upretirement.com *.remote.upretirement.com *.sitemaps.upretirement.com *.staging.upretirement.com upretirement.com *.upretirement.com *.webmail.upretirement.com
*.11.waterfordcove.com *.m.waterfordcove.com *.sitemap.waterfordcove.com waterfordcove.com *.waterfordcove.com *.ww.waterfordcove.com *.ww1.waterfordcove.com *.ww11.waterfordcove.com *.ww16.waterfordcove.com *.ww17.waterfordcove.com *.ww25.waterfordcove.com *.ww38.waterfordcove.com
*.demo.xn--istanbuliekgnder-jpbb20a.com xn--istanbuliekgnder-jpbb20a.com *.xn--istanbuliekgnder-jpbb20a.com