Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=golfironsuk.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 10, 2026
Valid Until
April 10, 2026
45 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
ED:02:88:35:E5:CA:C0:C1:DC:D7:0C:74:00:07:FB:97:50:2E:AB:4D:F2:63:B1:E2:62:9B:AE:87:17:64:31:47
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
shutterstok.com
*.shutterstok.com
*.contributif.shutterstok.com
*.random.shutterstok.com
*.samit.shutterstok.com
*.submit.shutterstok.com
*.ww.shutterstok.com
*.ww6.shutterstok.com
128jogo.com
*.128jogo.com
2pureb2b.co.uk
*.2pureb2b.co.uk
*.elastic.2pureb2b.co.uk
*.hostmaster.2pureb2b.co.uk
4ktvonline.site
*.4ktvonline.site
adventuresfromearth.com
*.adventuresfromearth.com
aliadas-wings.com
*.aliadas-wings.com
allbrandpros.com
*.allbrandpros.com
allo-urist.com
*.allo-urist.com
*.admin.applyhere.club
applyhere.club
*.applyhere.club
barlight.info
*.barlight.info
codenerds.com.au
*.codenerds.com.au
*.hikhqww25.codenerds.com.au
gbr.com.pl
*.gbr.com.pl
compaas.online
*.compaas.online
culinaryclasses191964.icu
*.culinaryclasses191964.icu
destekyetkiliservis.com
*.destekyetkiliservis.com
ed908998.icu
*.ed908998.icu
femtb.site
*.femtb.site
garagedoorrepair418825.icu
*.garagedoorrepair418825.icu
goldencorralmenu.us
*.goldencorralmenu.us
golfironsuk.co.uk
*.golfironsuk.co.uk
jewelerrings.us
*.jewelerrings.us
*.kay.jewelerrings.us
*.kayi.jewelerrings.us
*.ww25.jewelerrings.us
kkb8.net
*.kkb8.net
madomicialiation.fr
*.madomicialiation.fr
*.lanshan.myezsalesmobile.com
myezsalesmobile.com
*.myezsalesmobile.com
*.random.myezsalesmobile.com
*.ww25.myezsalesmobile.com
*.ww38.myezsalesmobile.com
paidbipolartrials807422.icu
*.paidbipolartrials807422.icu
pulso-shop.com
*.pulso-shop.com
*.betaalverzoek.raboabnk.nl
raboabnk.nl
*.raboabnk.nl
*.rn.raboabnk.nl
*.tilburg.raboabnk.nl
*.weert.raboabnk.nl
sextoydiscounts.club
*.sextoydiscounts.club
*.emails.socialrebel.app
*.hello.socialrebel.app
*.notify.socialrebel.app
*.share.socialrebel.app
socialrebel.app
*.socialrebel.app
tamstreasures.co.uk
*.tamstreasures.co.uk
theimprovementunion.com.au
*.theimprovementunion.com.au
*.wwww.yagi.live
yagi.live
*.yagi.live
Other domains in certificate