Open
Cached
·
just now
79/100
SECURITY SCORE
Certificate Information
Subject
CN=gekos-ks.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 30, 2026
Valid Until
April 30, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E2:14:5D:65:71:8D:AC:E2:5D:B8:77:2D:74:63:8F:43:3A:6E:89:4D:29:E3:4F:C7:EE:AA:EA:17:9A:0E:5A:43
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
optimumswap.com
*.optimumswap.com
1923.cam
*.1923.cam
*.www.1923.cam
dyorpay.com
*.dyorpay.com
*.www.dyorpay.com
enkorea.com
*.enkorea.com
*.staging.enkorea.com
gekos-ks.com
*.gekos-ks.com
hbo87q2h.top
*.hbo87q2h.top
hni.cc
*.hni.cc
holycrownsilchar.in
*.holycrownsilchar.in
hookingupagain.com
*.hookingupagain.com
izzicasinovip25.com
*.izzicasinovip25.com
jackpotorium.com
*.jackpotorium.com
juegoblackjack.mx
*.juegoblackjack.mx
k7playtv.sbs
*.k7playtv.sbs
*.1.kat.es
*.evang.kat.es
kat.es
*.kat.es
macbeehoney.com
*.macbeehoney.com
masterseoexpert.com
*.masterseoexpert.com
*.uat.masterseoexpert.com
masum.cc
*.masum.cc
matchfashion.org
*.matchfashion.org
mb6606.com
*.mb6606.com
mono-ai.com
*.mono-ai.com
myungminkim.com
*.myungminkim.com
neotec.blog
*.neotec.blog
nhandinhkeo.vip
*.nhandinhkeo.vip
onlineshopx.com
*.onlineshopx.com
p1ecetwb.top
*.p1ecetwb.top
pelletskaufen.com
*.pelletskaufen.com
pipayshop.com
*.pipayshop.com
qyhjwn.shop
*.qyhjwn.shop
qz1b2j26.top
*.qz1b2j26.top
raiseswap.com
*.raiseswap.com
sotrove.com
*.sotrove.com
starinfo.xyz
*.starinfo.xyz
thehrcg.com
*.thehrcg.com
theinnerwell.com
*.theinnerwell.com
xfylc.com
*.xfylc.com
*.stage.xn--ppr.com
xn--ppr.com
*.xn--ppr.com
xrico.com
*.xrico.com
yg8q8p7.top
*.yg8q8p7.top
yh9e2e3.top
*.yh9e2e3.top
yjqo9mjg.top
*.yjqo9mjg.top
yx1f8w3.top
*.yx1f8w3.top
Other domains in certificate