Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=twokingdomsonethrone.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 06, 2025
Valid Until
March 06, 2026
34 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
89:8D:3E:92:95:51:36:28:45:3C:3D:9F:D5:2C:9E:E5:48:22:3A:72:26:A1:06:B9:71:5C:60:4C:97:24:9A:BA
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
cahloan.com
*.cahloan.com
*.ads.cahloan.com
*.download.cahloan.com
*.es.cahloan.com
*.law.cahloan.com
*.media.cahloan.com
*.random.cahloan.com
*.rss.cahloan.com
*.srv5.cahloan.com
*.users.cahloan.com
365parma.net
*.365parma.net
actualizarproceso.com
*.actualizarproceso.com
ccimchina.com
*.ccimchina.com
cipdhrcourses246088.icu
*.cipdhrcourses246088.icu
donadjtrump.com
*.donadjtrump.com
*.mail.donadjtrump.com
*.ww38.donadjtrump.com
*.cpcontacts.exportshebabd.com
exportshebabd.com
*.exportshebabd.com
*.546ca19f-48b1-4808-a96a-cf6e0d9842f6.foxledger.studio
*.blvck.foxledger.studio
foxledger.studio
*.foxledger.studio
*.metaplaypoker.foxledger.studio
freshmealpla.com
*.freshmealpla.com
*.random.freshmealpla.com
gayxxxpage.com
*.gayxxxpage.com
*.5cd7da10-7b0d-4a76-8efe-548a105ea8eb.happysoks.com
happysoks.com
*.happysoks.com
herbalformula41.com
*.herbalformula41.com
kltsi.cc
*.kltsi.cc
marcianosx.com
*.marcianosx.com
marianvip.com
*.marianvip.com
*.autodiscover.menssecrets.net
menssecrets.net
*.menssecrets.net
*.www.menssecrets.net
*.m.moviexk.cc
moviexk.cc
*.moviexk.cc
*.ac5fdsxevxq4s5y.novels80.com
*.adwhj77lcyoafdy.novels80.com
novels80.com
*.novels80.com
*.ww17.novels80.com
*.nt.nykaafashin.com
nykaafashin.com
*.nykaafashin.com
ourpreset.com
*.ourpreset.com
*.dns.pgatoursuperstor.com
pgatoursuperstor.com
*.pgatoursuperstor.com
*.sitemaps.pgatoursuperstor.com
senaigoioas.com.br
*.senaigoioas.com.br
*.app.superplugs.co
*.blog.superplugs.co
superplugs.co
*.superplugs.co
*.ww16.superplugs.co
teenpattiaa.com
*.teenpattiaa.com
tobecio.com
*.tobecio.com
twokingdomsonethrone.com
*.twokingdomsonethrone.com
*.backend.vivunt.com
*.dev.vivunt.com
*.mail.vivunt.com
*.tech.vivunt.com
vivunt.com
*.vivunt.com
*.webmail.vivunt.com
*.www.vivunt.com
Other domains in certificate