76/100 SECURITY SCORE

Certificate Information

Subject
CN=marya.net
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 15, 2026
Valid Until
April 15, 2026 58 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B0:A5:38:DC:AB:D2:42:F8:8A:1D:0E:4A:EB:59:49:D8:E3:C1:1B:D8:72:AB:2D:85:97:0C:02:52:78:89:CC:7A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
lonaci.net *.lonaci.net *.auth-ns.lonaci.net *.printer.lonaci.net *.random.lonaci.net *.teredo.lonaci.net *.ww25.lonaci.net

Other domains in certificate

acvgummies.website *.acvgummies.website
aeromodelismoeassim.com *.aeromodelismoeassim.com
dmealliance.com *.dmealliance.com *.m.dmealliance.com *.wap.dmealliance.com *.wap2.dmealliance.com *.wap3.dmealliance.com *.wts.dmealliance.com
dragonhatch2luck.xyz *.dragonhatch2luck.xyz *.ww25.dragonhatch2luck.xyz
dutchacrespups.com *.dutchacrespups.com
eehn.co.uk *.eehn.co.uk
local.pink *.local.pink
*.cit.marya.net *.dealers.marya.net marya.net *.marya.net
missionwelfare.co *.missionwelfare.co
*.acp.mrg.au *.anzctr.mrg.au *.bluecare.mrg.au mrg.au *.mrg.au *.pedro.mrg.au *.scitech.mrg.au *.vision.mrg.au *.wa.mrg.au
pranjalbirla.tech *.pranjalbirla.tech
*.app.printkro.xyz *.cpanel.printkro.xyz *.cpcalendars.printkro.xyz *.d.printkro.xyz *.mail.printkro.xyz printkro.xyz *.printkro.xyz *.webmail.printkro.xyz *.ww2.printkro.xyz *.ww25.printkro.xyz *.www.printkro.xyz
*.m.rhouseoyopers.info rhouseoyopers.info *.rhouseoyopers.info *.ww25.rhouseoyopers.info
sinuelo.co *.sinuelo.co
smilestk.com *.smilestk.com
*.r.splashinfashion.com splashinfashion.com *.splashinfashion.com *.ww38.splashinfashion.com
*.mail12.techupdated.us *.smtpseguro.techupdated.us techupdated.us *.techupdated.us *.ww25.techupdated.us
turnersautowrecking.com *.turnersautowrecking.com
*.random.usdtysook.com usdtysook.com *.usdtysook.com *.wildcard.usdtysook.com *.ww25.usdtysook.com *.ww38.usdtysook.com
wairfare.com *.wairfare.com *.ww.wairfare.com *.ww16.wairfare.com
xntv.cc *.xntv.cc
zipizy.site *.zipizy.site