Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=tunbu.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 09, 2026
Valid Until
May 10, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:8A:FE:5D:13:B4:83:13:90:0F:89:03:1F:36:D5:A0:B6:61:CF:8E:D7:FE:F1:26:EA:61:9C:53:17:BF:C4:5B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
sazaz.com *.sazaz.com *.cpanel.sazaz.com *.jira.sazaz.com *.mail.sazaz.com *.mx2.sazaz.com *.pop3.sazaz.com *.random.sazaz.com *.sitemap.sazaz.com *.webdisk.sazaz.com *.webmail.sazaz.com *.ww17.sazaz.com

Other domains in certificate

*.43tf.cavero.com *.api.cavero.com *.blog.cavero.com cavero.com *.cavero.com *.dev.cavero.com *.ebay.cavero.com *.mail.cavero.com *.test.cavero.com *.ww17.cavero.com *.ww25.cavero.com
*.acceso.lasierra.com *.app.lasierra.com *.apps.lasierra.com *.assets.lasierra.com *.autodiscover.lasierra.com *.citrix.lasierra.com *.cloud.lasierra.com *.cloudapp.lasierra.com *.connect.lasierra.com *.desktop.lasierra.com *.desktopstudent.lasierra.com *.gitlab.lasierra.com *.globalprotect.lasierra.com *.incoming.lasierra.com *.intra.lasierra.com *.labvirtual.lasierra.com lasierra.com *.lasierra.com *.mail.lasierra.com *.online.lasierra.com *.portal.lasierra.com *.prelogon.lasierra.com *.receiver.lasierra.com *.remoto.lasierra.com *.secureaccess.lasierra.com *.stream.lasierra.com *.vdi.lasierra.com *.virtualstudent.lasierra.com *.vpn.lasierra.com *.vpnssl.lasierra.com *.webvpn.lasierra.com *.workspace.lasierra.com *.ww25.lasierra.com *.yhiaydesktop.lasierra.com
mangahosted.org *.mangahosted.org *.rustore.mangahosted.org *.sitemaps.mangahosted.org
*.cloud.soaprano.com *.mail.soaprano.com soaprano.com *.soaprano.com
*.admin.tunbu.com *.cpcontacts.tunbu.com *.data-sandbox.tunbu.com *.dev.tunbu.com *.exchange.tunbu.com *.gateway.tunbu.com *.id-metrics.tunbu.com *.imap.tunbu.com *.m.tunbu.com *.mail.tunbu.com *.ml.tunbu.com *.portal.tunbu.com *.sitemaps.tunbu.com *.smtp.tunbu.com *.ssl.tunbu.com *.sslvpn.tunbu.com *.test.tunbu.com tunbu.com *.tunbu.com *.vpn.tunbu.com *.webmail.tunbu.com *.ww1.tunbu.com *.ww16.tunbu.com *.ww38.tunbu.com