76/100 SECURITY SCORE

Certificate Information

Subject
CN=iqlj.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 03, 2026
Valid Until
September 01, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
93:1C:08:27:E1:62:04:8D:69:FD:68:3B:B7:18:D0:04:80:4F:D1:25:8B:1F:C8:FC:B0:C5:A4:29:F9:59:B8:17
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

73 domains
tentuniversity.com *.tentuniversity.com *.random.tentuniversity.com *.test.tentuniversity.com *.ww25.tentuniversity.com

Other domains in certificate

arip27.com *.arip27.com *.cicd.arip27.com *.ww17.arip27.com *.ww38.arip27.com
beadedbracelets.com.au *.beadedbracelets.com.au *.ww25.beadedbracelets.com.au
brisbaneactivities.com.au *.brisbaneactivities.com.au *.emv1.brisbaneactivities.com.au *.ww25.brisbaneactivities.com.au *.ww38.brisbaneactivities.com.au
capable.au *.capable.au *.ete.capable.au *.marketplace.capable.au *.random.capable.au
centrecolombier.org *.centrecolombier.org
daria.org *.daria.org *.hrrjl.daria.org *.lacamisetasoli.daria.org
davideharrington.com *.davideharrington.com *.random.davideharrington.com
donatello.au *.donatello.au
hinerfeld-ward.com *.hinerfeld-ward.com *.mail.hinerfeld-ward.com *.mta-sts.hinerfeld-ward.com *.ww38.hinerfeld-ward.com *.www.hinerfeld-ward.com
*.hostmaster.insurescooter.com insurescooter.com *.insurescooter.com *.random.insurescooter.com
*.forums.iqlj.com iqlj.com *.iqlj.com *.sg.iqlj.com
magras.com.br *.magras.com.br *.ww25.magras.com.br *.ww38.magras.com.br
*.hostmaster.maibaumstueberl-ruhpolding.de maibaumstueberl-ruhpolding.de *.maibaumstueberl-ruhpolding.de
taffic-mondo.com *.taffic-mondo.com *.ww16.taffic-mondo.com *.ww25.taffic-mondo.com *.ww38.taffic-mondo.com
*.mx1.tubuz.net tubuz.net *.tubuz.net *.ww25.tubuz.net *.www.tubuz.net
*.ww25.ytx.au ytx.au *.ytx.au
*.hostmaster.yy489.com *.sitemap.yy489.com *.ww25.yy489.com yy489.com *.yy489.com