Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=346659.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 27, 2026
Valid Until
July 26, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
24:FC:2B:C0:D6:5A:F7:D2:3D:0A:D0:BD:A0:99:C8:78:CA:39:E5:84:DA:1E:BA:0A:48:C0:AD:CC:54:E5:A8:A5
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ktminvest.com
*.ktminvest.com
1stmagicai.info
*.1stmagicai.info
27650572.vip
*.27650572.vip
302tly00.com
*.302tly00.com
31362.co
*.31362.co
346659.com
*.346659.com
456fgfff.com
*.456fgfff.com
52526.one
*.52526.one
59293.loan
*.59293.loan
666ld3.shop
*.666ld3.shop
76013.pro
*.76013.pro
999g.xyz
*.999g.xyz
bc9.online
*.bc9.online
blm11.xyz
*.blm11.xyz
bolle-drinks.com
*.bolle-drinks.com
callwavesolutions.com
*.callwavesolutions.com
choiceexecmentor.com
*.choiceexecmentor.com
chung.autos
*.chung.autos
cluear.shop
*.cluear.shop
creaturespace.com
*.creaturespace.com
datafyxerclash.info
*.datafyxerclash.info
diambr.shop
*.diambr.shop
hookahcafe.ae
*.hookahcafe.ae
howtheplay.com
*.howtheplay.com
hpmpw.science
*.hpmpw.science
iaimagem.com
*.iaimagem.com
inscricaoescolar.site
*.inscricaoescolar.site
iq-nexora.com
*.iq-nexora.com
loreng88id.info
*.loreng88id.info
luxurybrooch.shop
*.luxurybrooch.shop
momentumelectronics.com
*.momentumelectronics.com
nuptialconclave.beauty
*.nuptialconclave.beauty
nuptialoptic.beauty
*.nuptialoptic.beauty
ovengenius.com
*.ovengenius.com
pasastesintagsrn.click
*.pasastesintagsrn.click
pc8yh.top
*.pc8yh.top
pcapa.org
*.pcapa.org
personal-loans-at-7078.sbs
*.personal-loans-at-7078.sbs
personal-loans-za-213.sbs
*.personal-loans-za-213.sbs
petmystify.com
*.petmystify.com
qsmash.info
*.qsmash.info
qsttuvw.xyz
*.qsttuvw.xyz
reply-coindesk.com
*.reply-coindesk.com
robothis.com
*.robothis.com
royal1127.buzz
*.royal1127.buzz
Other domains in certificate