76/100 SECURITY SCORE

Certificate Information

Subject
CN=breeze-nova.buzz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 11, 2026
Valid Until
August 09, 2026 62 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
15:98:9C:CF:30:CE:7E:D3:73:13:50:61:73:D6:3B:1B:51:FF:CC:0B:B3:21:43:21:B4:11:96:1F:B0:85:18:67
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
kimacindustry.com *.kimacindustry.com *.39c3215c-ef89-46fc-bf6b-0fc24f122e42.kimacindustry.com *.66xrow.kimacindustry.com *.api.kimacindustry.com *.dashboard.kimacindustry.com *.mail.kimacindustry.com *.remote.kimacindustry.com *.ulrwv66xrow.kimacindustry.com *.webmail.kimacindustry.com

Other domains in certificate

breeze-nova.buzz *.breeze-nova.buzz
breeze-on-twin.city *.breeze-on-twin.city
cejygu.pro *.cejygu.pro
chamberscybersecurity.com *.chamberscybersecurity.com
ktjeip.app *.ktjeip.app
ledgerman.company *.ledgerman.company
lgoacespt.com *.lgoacespt.com
limebyte.rocks *.limebyte.rocks
*.31893d71-e649-4960-a082-87de3cf60129.lklotto.com *.admin.lklotto.com *.app.lklotto.com *.assets.lklotto.com *.dashboard.lklotto.com *.demo.lklotto.com lklotto.com *.lklotto.com *.m.lklotto.com *.mail.lklotto.com *.mailer.lklotto.com *.members.lklotto.com *.phrmuv1.lklotto.com *.v1.lklotto.com *.www.lklotto.com
medical-insurance7.click *.medical-insurance7.click
offerwelding-offers-welding-job-offer299.sbs *.offerwelding-offers-welding-job-offer299.sbs
oprng.cn *.oprng.cn
optuenin.com *.optuenin.com
oraaham.com *.oraaham.com
orbitleafsonic.world *.orbitleafsonic.world
overhaddoors.click *.overhaddoors.click
oyunyolcu.org *.oyunyolcu.org
paintrecharge.com *.paintrecharge.com
petstuffchicago.com *.petstuffchicago.com
pgaaag.love *.pgaaag.love
pgaaat.love *.pgaaat.love
pgyy.blog *.pgyy.blog
phdphdphd.phd *.phdphdphd.phd
piuts.ad *.piuts.ad
pk95r6.com *.pk95r6.com
play-gglmarket.org *.play-gglmarket.org
polyntelligence.com *.polyntelligence.com
presticappro.com *.presticappro.com
qsoptimizer.com *.qsoptimizer.com
superscatterzeus.net *.superscatterzeus.net
svxljcp.onl *.svxljcp.onl
terohi.pro *.terohi.pro
thelter.click *.thelter.click