76/100 SECURITY SCORE

Certificate Information

Subject
CN=dorothypetshop.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 26, 2026
Valid Until
July 25, 2026 38 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0E:E0:82:9A:0C:E2:BF:18:52:D5:B4:2F:E1:BC:52:D2:63:10:25:2F:EB:5A:54:8C:AF:00:8C:0B:22:C5:FD:FC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
atttower.com *.atttower.com *.random.atttower.com

Other domains in certificate

acs-racing.net *.acs-racing.net *.shop.acs-racing.net *.ww25.acs-racing.net
*.admin.blackfridaysuv.com *.backend.blackfridaysuv.com blackfridaysuv.com *.blackfridaysuv.com
brightwhite.co *.brightwhite.co *.mx.brightwhite.co *.www.brightwhite.co
dorothypetshop.com *.dorothypetshop.com *.ww25.dorothypetshop.com
*.05994b5f-043d-430e-8f95-2542a83e2c91.ek-5-5-5.site *.51c272e0-8ecb-4063-97c7-ab0b016a49ee.ek-5-5-5.site *.admin.ek-5-5-5.site *.aging.ek-5-5-5.site *.app.ek-5-5-5.site *.assets.ek-5-5-5.site *.atendimento.ek-5-5-5.site *.bqtzxapi.ek-5-5-5.site *.demo.ek-5-5-5.site ek-5-5-5.site *.ek-5-5-5.site *.g.ek-5-5-5.site *.hostmaster.ek-5-5-5.site *.staging.ek-5-5-5.site *.test.ek-5-5-5.site *.w.ek-5-5-5.site
entirely.au *.entirely.au *.ww25.entirely.au
igbtig.com *.igbtig.com *.postmaster.igbtig.com *.ww25.igbtig.com *.www.igbtig.com
*.blog.immediatematrixcanada.com immediatematrixcanada.com *.immediatematrixcanada.com
jiuse9017.xyz *.jiuse9017.xyz
pricemonitors.com.au *.pricemonitors.com.au *.ww25.pricemonitors.com.au *.ww38.pricemonitors.com.au
*.citrix.public.com.au *.galano.public.com.au *.intelema.public.com.au *.itsm-assessment.public.com.au *.mailserver.public.com.au *.ntp.public.com.au *.pop.public.com.au public.com.au *.public.com.au *.random.public.com.au *.remotemail.public.com.au *.sa-east-6.public.com.au *.superset.public.com.au *.tools.public.com.au *.tst.public.com.au *.up.public.com.au *.us-east-25.public.com.au *.web.public.com.au *.ww25.public.com.au *.zoho.public.com.au
pucrt.town *.pucrt.town
redditforcorporationsproject.com *.redditforcorporationsproject.com
redditpartnersteams.com *.redditpartnersteams.com
renaissancegpt.com *.renaissancegpt.com
s-h-i-g-o.com *.s-h-i-g-o.com *.ww25.s-h-i-g-o.com
serenade.au *.serenade.au
sonntagsspiele.de *.sonntagsspiele.de
ts10029.cc *.ts10029.cc