76/100 SECURITY SCORE

Certificate Information

Subject
CN=paintwithsmell.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 18, 2026
Valid Until
August 16, 2026 86 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8A:E7:79:D5:7C:87:6F:08:C3:87:64:AA:B6:B7:F6:5E:8A:F5:81:37:6A:3E:DA:73:EE:F6:42:B3:9A:1C:FF:87
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
sonicknits.com *.sonicknits.com

Other domains in certificate

1149dmy301.top *.1149dmy301.top *.53c4a06762.1149dmy301.top *.542dad8ad7.1149dmy301.top *.e67b094518.1149dmy301.top
350ff.app *.350ff.app *.admin.350ff.app *.marketing.350ff.app *.qa.350ff.app
bloxflip.co *.bloxflip.co
brzesb.cyou *.brzesb.cyou
bytmart.co *.bytmart.co
c99u.cyou *.c99u.cyou
casinositeleri.bio *.casinositeleri.bio
cbot190.vip *.cbot190.vip
cieds.org *.cieds.org
coastalhockey.co *.coastalhockey.co
cqxfyy.cn *.cqxfyy.cn
expert-park.co *.expert-park.co
fapeoulette.co *.fapeoulette.co
flmxu.loan *.flmxu.loan
*.demo.forexvolumes.com forexvolumes.com *.forexvolumes.com *.test.forexvolumes.com *.ww2.forexvolumes.com
forogore.co *.forogore.co
gangnamgirls.co *.gangnamgirls.co
genesishealthcare.co *.genesishealthcare.co
getbiodance.co *.getbiodance.co
ghostportal.co *.ghostportal.co
gossipgrandiose.live *.gossipgrandiose.live
justromote.co *.justromote.co
karinapadilla.co *.karinapadilla.co
kawriverrustics.co *.kawriverrustics.co
kaylene.life *.kaylene.life
*.dev.lifedeathprizes.co lifedeathprizes.co *.lifedeathprizes.co
*.aowpq.meetbrightatlascore.xyz *.kwid9.meetbrightatlascore.xyz meetbrightatlascore.xyz *.meetbrightatlascore.xyz
*.fdb74.paintwithsmell.xyz *.l0r4m.paintwithsmell.xyz paintwithsmell.xyz *.paintwithsmell.xyz
sonomaessentials.co *.sonomaessentials.co
spacetrends.click *.spacetrends.click
spendnet.com *.spendnet.com
spingamewithdrawal.top *.spingamewithdrawal.top
stigstream.co *.stigstream.co
stjoobs.co *.stjoobs.co
streamblasters.co *.streamblasters.co
tgvos.cn *.tgvos.cn
theorytestpro.co *.theorytestpro.co