76/100 SECURITY SCORE

Certificate Information

Subject
CN=mypuremist.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 02, 2026
Valid Until
July 31, 2026 52 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:69:91:63:1F:25:D1:19:94:A5:6A:89:89:CB:D3:7F:3C:3F:DC:4A:60:EC:01:0D:B7:C8:FE:7D:8C:16:5B:E6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
oulet.net *.oulet.net *.bbs.oulet.net *.ci-flow.oulet.net *.flowiseai.oulet.net *.ouletrepportal.oulet.net *.pohdelckhsov1.oulet.net *.pohdelckhsov3.oulet.net *.pohdelckhsov4.oulet.net *.pohdelckhsov7.oulet.net *.remote.oulet.net *.research.oulet.net *.superset.oulet.net *.ww20.oulet.net

Other domains in certificate

108631.xyz *.108631.xyz *.6.108631.xyz *.7.108631.xyz *.8.108631.xyz *.9.108631.xyz
*.accounts.carlsonsfloorcenterinc.com *.admin.carlsonsfloorcenterinc.com *.api.carlsonsfloorcenterinc.com *.app.carlsonsfloorcenterinc.com *.assets.carlsonsfloorcenterinc.com *.backup.carlsonsfloorcenterinc.com carlsonsfloorcenterinc.com *.carlsonsfloorcenterinc.com *.demo.carlsonsfloorcenterinc.com *.dev.carlsonsfloorcenterinc.com *.m.carlsonsfloorcenterinc.com *.mail.carlsonsfloorcenterinc.com *.mailer.carlsonsfloorcenterinc.com *.marketing.carlsonsfloorcenterinc.com *.mta-sts.carlsonsfloorcenterinc.com *.qa.carlsonsfloorcenterinc.com *.remote.carlsonsfloorcenterinc.com *.secure.carlsonsfloorcenterinc.com *.site1.carlsonsfloorcenterinc.com *.staging.carlsonsfloorcenterinc.com *.stg.carlsonsfloorcenterinc.com *.v2.carlsonsfloorcenterinc.com *.vpsvam.carlsonsfloorcenterinc.com *.web.carlsonsfloorcenterinc.com *.wildcard.carlsonsfloorcenterinc.com
*.biz.kpd34vip.com *.cc.kpd34vip.com *.cloud.kpd34vip.com *.club.kpd34vip.com *.com.kpd34vip.com *.commobcma.kpd34vip.com *.cu.kpd34vip.com kpd34vip.com *.kpd34vip.com *.me.kpd34vip.com *.movie.kpd34vip.com *.org.kpd34vip.com *.tv.kpd34vip.com *.vip.kpd34vip.com *.xxx.kpd34vip.com *.xyz.kpd34vip.com
*.ftp.mypuremist.com mypuremist.com *.mypuremist.com *.pay.mypuremist.com *.wildcard.mypuremist.com *.www.mypuremist.com
*.1a66a011-dcaf-4c69-9351-9576765333b1.swisscfd.org *.api.swisscfd.org *.assets.swisscfd.org *.backup.swisscfd.org *.cf56c0e1-a2d4-443c-ad28-5944b9dec7a9.swisscfd.org *.cpcontacts.swisscfd.org *.d50ffc65-c4f9-4b37-a5cd-2d236916d050.swisscfd.org *.dashboard.swisscfd.org *.gw.swisscfd.org *.home.swisscfd.org *.mail.swisscfd.org *.mailer.swisscfd.org *.mailgate.swisscfd.org *.marketing.swisscfd.org *.qa.swisscfd.org *.secure.swisscfd.org *.staging.swisscfd.org *.stg.swisscfd.org swisscfd.org *.swisscfd.org *.test.swisscfd.org *.ujrlqbck.swisscfd.org *.v1.swisscfd.org