Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=toroiki.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 11, 2026
Valid Until
August 09, 2026
53 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BE:73:B3:21:46:3B:40:A8:07:0D:3C:A7:0F:EF:72:13:FE:D3:92:DC:89:E9:13:0E:D7:BF:13:17:5F:58:2E:60
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
73 domains
reumenow.com
*.reumenow.com
brisbanefinacebrokers.com.au
*.brisbanefinacebrokers.com.au
copcams.com
*.copcams.com
csafchicago.org
*.csafchicago.org
customisable.com
*.customisable.com
erieelectionresults.com
*.erieelectionresults.com
estalem.store
*.estalem.store
*.www.estalem.store
eyvonne.com
*.eyvonne.com
findyourdealnow.com
*.findyourdealnow.com
godwddy.com
*.godwddy.com
handymantampa.pro
*.handymantampa.pro
herlnteractive.com
*.herlnteractive.com
infoslotgacor.bet
*.infoslotgacor.bet
instantprint.com.au
*.instantprint.com.au
jafa.live
*.jafa.live
maehroboter.de
*.maehroboter.de
maildream.de
*.maildream.de
*.www.maildream.de
marketmasters.net.au
*.marketmasters.net.au
newstabloids.com
*.newstabloids.com
onlineschool.xyz
*.onlineschool.xyz
pornlike.com
*.pornlike.com
regulatoryes.live
*.regulatoryes.live
reviews4adults.com
*.reviews4adults.com
serdi.pro
*.serdi.pro
speed-test.au
*.speed-test.au
spikedcompany.com.au
*.spikedcompany.com.au
stromboli.live
*.stromboli.live
tigerqueen.com
*.tigerqueen.com
*.random.toroiki.com
toroiki.com
*.toroiki.com
vapeshop.com.au
*.vapeshop.com.au
whyldass.com
*.whyldass.com
worryes.live
*.worryes.live
wpa2012.org
*.wpa2012.org
wwwuhc.com
*.wwwuhc.com
youvibe.com
*.youvibe.com
Other domains in certificate