Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=hitobito.net
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 06, 2026
Valid Until
May 07, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BF:84:7C:A0:F6:96:F9:98:C5:29:CC:8C:E6:46:B4:80:7B:0F:D6:93:B8:2B:B8:8E:A9:5A:42:D2:9A:09:29:6A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
pusends.com
*.pusends.com
hitobito.net
*.hitobito.net
musculardystrophylatesttreatment844955.icu
*.musculardystrophylatesttreatment844955.icu
mybenefitwork.com
*.mybenefitwork.com
mycloudservers.net
*.mycloudservers.net
myharleybenifits.com
*.myharleybenifits.com
myhmc.com
*.myhmc.com
mzlxy.me
*.mzlxy.me
nedch5.click
*.nedch5.click
newpublicsphere.com
*.newpublicsphere.com
nightwear.cfd
*.nightwear.cfd
ninomo.com
*.ninomo.com
nmfec.bid
*.nmfec.bid
nofaceforvideopodcast.com
*.nofaceforvideopodcast.com
nursing-companies-mx-pablo.click
*.nursing-companies-mx-pablo.click
nusantara.properties
*.nusantara.properties
o9mvsj.my
*.o9mvsj.my
oakhollowvenue.com
*.oakhollowvenue.com
official-vulkan24.cfd
*.official-vulkan24.cfd
online-ads-ch-7315.buzz
*.online-ads-ch-7315.buzz
online-good.click
*.online-good.click
otnla.tv
*.otnla.tv
oyuvt.me
*.oyuvt.me
ozkqw.bid
*.ozkqw.bid
p70.co
*.p70.co
pdpjm.pro
*.pdpjm.pro
perchance.io
*.perchance.io
periovivevetmedteam.com
*.periovivevetmedteam.com
play-thunder-lab.xyz
*.play-thunder-lab.xyz
playgloryquest.com
*.playgloryquest.com
plumbers-alliston-482606821.click
*.plumbers-alliston-482606821.click
pretiumsociety.com
*.pretiumsociety.com
pricenet.it
*.pricenet.it
qauqn.gdn
*.qauqn.gdn
r1tm12u.cyou
*.r1tm12u.cyou
redstockbooks.com
*.redstockbooks.com
reliabletradenetwork.sbs
*.reliabletradenetwork.sbs
rnsadwq111333jdwjwd03jdw.vip
*.rnsadwq111333jdwjwd03jdw.vip
romaxxcnc.com
*.romaxxcnc.com
roofing-jobs-au4-dpclickclick.click
*.roofing-jobs-au4-dpclickclick.click
ruyalarvegayeler.online
*.ruyalarvegayeler.online
rwtsi.pro
*.rwtsi.pro
rxcdxj.me
*.rxcdxj.me
ryseadvance.com
*.ryseadvance.com
starleen.com
*.starleen.com
Other domains in certificate