Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=big-fit.live
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 02, 2026
Valid Until
July 31, 2026 84 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E1:9F:33:85:2F:E0:82:42:3E:F1:F6:1E:80:03:D0:02:55:C4:50:64:6E:CC:34:B1:6D:3D:59:2A:44:69:B8:AB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
r925.com *.r925.com *.mcloud.r925.com

Other domains in certificate

africanrights.org *.africanrights.org *.clwww.africanrights.org
big-fit.live *.big-fit.live *.ww25.big-fit.live *.www.big-fit.live
centralmail.org *.centralmail.org *.deliver.centralmail.org *.dispatch.centralmail.org *.em.centralmail.org *.global.centralmail.org *.greenspade5.centralmail.org *.greenspade6.centralmail.org *.metro.centralmail.org *.msg.centralmail.org *.paulo.centralmail.org *.post.centralmail.org *.prime.centralmail.org *.send.centralmail.org *.share.centralmail.org *.yshua1.centralmail.org *.yshua10.centralmail.org *.yshua12.centralmail.org *.yshua4.centralmail.org *.yshua6.centralmail.org *.yshua8.centralmail.org
*.351.cqmiliputao.com *.7rlnt7.cqmiliputao.com *.9nlzz9.cqmiliputao.com *.blog.cqmiliputao.com cqmiliputao.com *.cqmiliputao.com *.fnn6pp.cqmiliputao.com *.guanggao.cqmiliputao.com *.huicui.cqmiliputao.com *.j7rlzp.cqmiliputao.com *.n8fzdb.cqmiliputao.com *.par.cqmiliputao.com *.ptrd2r.cqmiliputao.com
*.admin.creativecharles.art *.api.creativecharles.art creativecharles.art *.creativecharles.art *.dev.creativecharles.art *.ji9jwz.creativecharles.art *.ozhtuji9jwz.creativecharles.art *.test.creativecharles.art *.www.creativecharles.art
*.api.labdiets.info *.dev.labdiets.info labdiets.info *.labdiets.info *.mail.labdiets.info *.mailer.labdiets.info *.marketing.labdiets.info *.uat.labdiets.info
*.04a9062e-1f92-49c6-9b6f-a5659f219fc9.physicalai.quest *.15f51ec7-f62b-4ecb-9453-91129c5aa4f0.physicalai.quest *.6592cda5-1db2-4590-a594-0cf22f008def.physicalai.quest *.admin.physicalai.quest *.aiptkmembers.physicalai.quest *.api.physicalai.quest *.app.physicalai.quest *.assets.physicalai.quest *.blkvxtest.physicalai.quest *.c69fee88-d716-491e-b9a2-21f2123c54ab.physicalai.quest *.demo.physicalai.quest *.dev.physicalai.quest *.hostmaster.physicalai.quest *.mail.physicalai.quest *.members.physicalai.quest physicalai.quest *.physicalai.quest *.rustore.physicalai.quest *.test.physicalai.quest *.yjnfjapp.physicalai.quest
*.random.skoonat.com skoonat.com *.skoonat.com
*.m.soservice.com *.riso.soservice.com soservice.com *.soservice.com
wanshulou.la *.wanshulou.la