76/100 SECURITY SCORE

Certificate Information

Subject
CN=cleverbridg.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E1:6E:EE:E0:8A:8A:59:75:BE:13:A9:0A:8F:29:23:48:99:26:A2:67:84:E1:7D:A8:2C:50:B8:E5:B5:79:7A:07
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
goldcard.it *.goldcard.it *.admin.goldcard.it *.autoconfig.goldcard.it *.dev.goldcard.it *.rdweb.goldcard.it *.remote.goldcard.it *.sslvpn.goldcard.it

Other domains in certificate

78165.org *.78165.org
87xx.cc *.87xx.cc
899cash.bid *.899cash.bid
90570.my *.90570.my
92742.my *.92742.my
95656.mobi *.95656.mobi
98744.loan *.98744.loan
accessvoiceformhq.info *.accessvoiceformhq.info
biheibo.pro *.biheibo.pro
boxofdolls.com *.boxofdolls.com
buy-mystery-box.com *.buy-mystery-box.com
*.api.capitalsherpafund.biz capitalsherpafund.biz *.capitalsherpafund.biz *.demo.capitalsherpafund.biz *.test.capitalsherpafund.biz *.vr22qt.capitalsherpafund.biz *.www.capitalsherpafund.biz
capitalsherpaguide.biz *.capitalsherpaguide.biz *.ogd7gu.capitalsherpaguide.biz
capitalsherpatrust.biz *.capitalsherpatrust.biz *.emiuhczb.capitalsherpatrust.biz *.testing.capitalsherpatrust.biz
*.backup.capitalsherpavault.biz capitalsherpavault.biz *.capitalsherpavault.biz
cashresources.com.au *.cashresources.com.au *.mail.cashresources.com.au *.smtp.cashresources.com.au *.vexchange.cashresources.com.au *.ww25.cashresources.com.au
cleverbridg.com *.cleverbridg.com *.dgw.cleverbridg.com *.dns.cleverbridg.com *.hostmaster.cleverbridg.com *.mx7.cleverbridg.com *.random.cleverbridg.com *.w.cleverbridg.com *.ww38.cleverbridg.com *.xn--ww7-hn0a.cleverbridg.com
*.0288854c-389c-40e3-882f-235488b6e59b.cuocbongda.net *.62f269b4-0a24-49ef-9386-2de899bbb8f2.cuocbongda.net *.admin.cuocbongda.net *.app.cuocbongda.net *.blog.cuocbongda.net *.chrupm.cuocbongda.net cuocbongda.net *.cuocbongda.net *.dashboard.cuocbongda.net *.ebmail.cuocbongda.net *.hostmaster.cuocbongda.net *.m.cuocbongda.net *.mailer.cuocbongda.net *.marketing.cuocbongda.net *.mqcjduat.cuocbongda.net *.remote.cuocbongda.net *.secure.cuocbongda.net *.staging.cuocbongda.net *.v2.cuocbongda.net *.waoebwebmail.cuocbongda.net *.web.cuocbongda.net *.webmail.cuocbongda.net *.wildcard.cuocbongda.net
northlakes.studio *.northlakes.studio
omnimetaphoria.com *.omnimetaphoria.com