Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=jaromer.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 15, 2026
Valid Until
July 14, 2026 50 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CA:24:13:37:9D:D7:E0:D7:E1:E6:E1:61:C7:98:C0:60:2A:7C:74:2B:C7:01:59:FD:E2:8F:B1:C0:30:89:18:2D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
kams.it *.kams.it *.random.kams.it *.remote.kams.it *.webmail.kams.it

Other domains in certificate

666tav.com *.666tav.com *.cm.666tav.com *.com.666tav.com *.ii.666tav.com *.space.666tav.com *.tv.666tav.com *.vip.666tav.com *.xyz.666tav.com *.youporn.666tav.com
areediservizio.com *.areediservizio.com *.backend.areediservizio.com *.dev.areediservizio.com *.mail.areediservizio.com *.notexistsbackend.areediservizio.com *.remote.areediservizio.com *.webmail.areediservizio.com
cameraanninh.com *.cameraanninh.com *.hostmaster.cameraanninh.com *.ww38.cameraanninh.com *.www.cameraanninh.com
coloringcombo.com *.coloringcombo.com *.dns.coloringcombo.com *.sitemaps.coloringcombo.com
*.0afmf.fdbdr.cfd *.1846m.fdbdr.cfd *.4qwa0.fdbdr.cfd *.8joac.fdbdr.cfd *.c6udy.fdbdr.cfd *.eu3rm.fdbdr.cfd *.fdb74.fdbdr.cfd fdbdr.cfd *.fdbdr.cfd *.feew6.fdbdr.cfd *.g89kw.fdbdr.cfd *.lbcp6.fdbdr.cfd *.qdiek.fdbdr.cfd *.rkuvx.fdbdr.cfd *.rnyzj.fdbdr.cfd *.x7pal.fdbdr.cfd *.z4gbs.fdbdr.cfd
*.asellae.govanfolkuniversity.org govanfolkuniversity.org *.govanfolkuniversity.org *.shop08002.govanfolkuniversity.org *.shop80002.govanfolkuniversity.org *.shop85003.govanfolkuniversity.org *.shop9504.govanfolkuniversity.org *.trsale.govanfolkuniversity.org
jaromer.com *.jaromer.com
kentucy.com *.kentucy.com *.wildcard.kentucy.com
moritzcompany.online *.moritzcompany.online *.ww38.moritzcompany.online
richsingles.com.au *.richsingles.com.au
*.a.sitesin.com *.admin.sitesin.com *.api.sitesin.com *.app.sitesin.com *.dashboard.sitesin.com *.demo.sitesin.com *.desktop.sitesin.com *.hostmaster.sitesin.com *.mailer.sitesin.com *.mta-sts.sitesin.com *.qa.sitesin.com *.qwdbmngi.sitesin.com *.secure.sitesin.com sitesin.com *.sitesin.com *.stg.sitesin.com *.v1.sitesin.com *.vpn.sitesin.com *.wap.sitesin.com
*.random.west.health west.health *.west.health