91/100 SECURITY SCORE

Certificate Information

Subject
CN=bazar.tools
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 23, 2026
Valid Until
June 21, 2026 39 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0F:8D:F2:F0:6C:E2:DE:EF:4A:D7:A8:5C:62:2E:84:EF:FD:17:5F:C3:1D:27:D2:A4:1F:F6:69:19:2E:83:2C:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin
Permissions-Policy
Present
geolocation=(), midi=(), sync-xhr=(); +6 more
Recommendations
  • Add Content-Security-Policy header to prevent XSS attacks

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
readreality-quest.com *.readreality-quest.com

Other domains in certificate

168756.cc *.168756.cc
6000a.org *.6000a.org
7xqz3xyz.com *.7xqz3xyz.com
aboagyeclan.estate *.aboagyeclan.estate
bao56.com *.bao56.com
bareskinnshop.com *.bareskinnshop.com
bazar.tools *.bazar.tools
cashreviewsnow.com *.cashreviewsnow.com
cialisahc.com *.cialisahc.com
comunikadosweb.us *.comunikadosweb.us
crusiedeckplans.com *.crusiedeckplans.com
digigr8media.com *.digigr8media.com
easy-mp3.com *.easy-mp3.com
editingcode.com *.editingcode.com
elysmode.com *.elysmode.com
hanman.sbs *.hanman.sbs
huiwenedn.com *.huiwenedn.com
iconicdiz.llc *.iconicdiz.llc
jrzhi.gdn *.jrzhi.gdn
kitchencreationhub.com *.kitchencreationhub.com
lenticexport.com *.lenticexport.com
limeblue.co *.limeblue.co
mbitspctools.live *.mbitspctools.live
mtb.tools *.mtb.tools
mystuff2.com *.mystuff2.com
partyrentalselpaso.com *.partyrentalselpaso.com
pp-fonder.com *.pp-fonder.com
proboapkdownload.com *.proboapkdownload.com
removeit.app *.removeit.app
rescheck.com *.rescheck.com
rjbkc.com *.rjbkc.com
rnlhue.gdn *.rnlhue.gdn
rockermortgage.com *.rockermortgage.com
rolitron.com *.rolitron.com
rootsmankitchen.site *.rootsmankitchen.site
shaarwindsor.org *.shaarwindsor.org
telagahikmah.org *.telagahikmah.org
thecagemadrid.com *.thecagemadrid.com
toystarwrestling.com *.toystarwrestling.com
updatemycareer.com *.updatemycareer.com
*.random.whatavacation.com whatavacation.com *.whatavacation.com
winzoapkdownload.com *.winzoapkdownload.com
xingyun1685555.cc *.xingyun1685555.cc