Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=freshvandira.tech
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 05, 2026
Valid Until
May 06, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BB:E0:28:65:45:30:35:5E:5E:0E:0A:0B:D1:3B:71:B0:D3:83:88:69:1A:09:74:9E:50:B2:D9:59:9D:D4:55:58
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ideaboxmedia.com
*.ideaboxmedia.com
freshvandira.tech
*.freshvandira.tech
fukutoku-real-848151064.click
*.fukutoku-real-848151064.click
fullysold.com
*.fullysold.com
fundacjarai.pl
*.fundacjarai.pl
fxfc.com
*.fxfc.com
fzl168.com
*.fzl168.com
galaxyglow.world
*.galaxyglow.world
geniusenglish.in
*.geniusenglish.in
german-lebanese-ta-water.org
*.german-lebanese-ta-water.org
getaxelliant-tech.com
*.getaxelliant-tech.com
glavk.cc
*.glavk.cc
globalfamenetwork.com
*.globalfamenetwork.com
globalsealants.com
*.globalsealants.com
gloriouslove.com
*.gloriouslove.com
goalstyn.com
*.goalstyn.com
goldtexusa.com
*.goldtexusa.com
goodmorrowpictures.com
*.goodmorrowpictures.com
gossipcirclewhirl.live
*.gossipcirclewhirl.live
goxmyhgtesq.cc
*.goxmyhgtesq.cc
gptlion.com
*.gptlion.com
grapescarlet.com
*.grapescarlet.com
growthhub.rest
*.growthhub.rest
guitarvirtuosotop.com
*.guitarvirtuosotop.com
harass.net
*.harass.net
hf5fc.cc
*.hf5fc.cc
hillarywen.com
*.hillarywen.com
hiring-electrician.click
*.hiring-electrician.click
holistichealthfitness.run
*.holistichealthfitness.run
homes-prefab-xyz-kz.click
*.homes-prefab-xyz-kz.click
hoste.co
*.hoste.co
hotelborabora.it
*.hotelborabora.it
huamanzhu.com
*.huamanzhu.com
hurtmoney.com
*.hurtmoney.com
hw7b.mx
*.hw7b.mx
iancuttler.com
*.iancuttler.com
idqq88as.xyz
*.idqq88as.xyz
imiamihealth.org
*.imiamihealth.org
imijno.net
*.imijno.net
imkcp.academy
*.imkcp.academy
imkrgw.tv
*.imkrgw.tv
immagazzinamentoelettricita.it
*.immagazzinamentoelettricita.it
inattv833.xyz
*.inattv833.xyz
infinied.com
*.infinied.com
inflbank.buzz
*.inflbank.buzz
Other domains in certificate