Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=mega38play.online
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 24, 2026
Valid Until
September 22, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3D:E4:55:FA:1A:68:F7:74:1E:FC:EB:12:8E:F4:09:CA:1B:A7:B2:B5:C9:96:7C:5C:B2:7C:4C:3A:7D:62:94:DF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
rewardff.com *.rewardff.com *.link.rewardff.com *.test.rewardff.com *.www.rewardff.com

Other domains in certificate

07307.vip *.07307.vip *.wwww.07307.vip
*.adm.akemirankinegriffith.com akemirankinegriffith.com *.akemirankinegriffith.com *.assets.akemirankinegriffith.com *.m.akemirankinegriffith.com *.staging.akemirankinegriffith.com
*.admin.greenschoolethiopia.com greenschoolethiopia.com *.greenschoolethiopia.com
hidefwallpaper.org *.hidefwallpaper.org
*.cpanel.impalacongo.com *.cpcalendars.impalacongo.com *.imap.impalacongo.com impalacongo.com *.impalacongo.com *.m.impalacongo.com *.mail.impalacongo.com *.sitemaps.impalacongo.com *.smtp.impalacongo.com
*.025ed7e3-bd9e-483a-a41e-1a399db948e7.jjrbbav1.xyz *.insight.jjrbbav1.xyz jjrbbav1.xyz *.jjrbbav1.xyz *.wildcard.jjrbbav1.xyz *.ww1.jjrbbav1.xyz *.ww25.jjrbbav1.xyz *.ww38.jjrbbav1.xyz
krummrich.com *.krummrich.com
*.map.matrasyviolait.online matrasyviolait.online *.matrasyviolait.online *.ysghupxt.matrasyviolait.online
*.blog.mega38play.online *.demo.mega38play.online *.dev.mega38play.online mega38play.online *.mega38play.online *.test.mega38play.online
*.app.pixleyfuneral.com *.notexistsbackend.pixleyfuneral.com pixleyfuneral.com *.pixleyfuneral.com *.staging.pixleyfuneral.com
sdmimdjournal.in *.sdmimdjournal.in
sieudamtv.mobi *.sieudamtv.mobi *.test.sieudamtv.mobi *.ww25.sieudamtv.mobi *.ww38.sieudamtv.mobi
sinks.top *.sinks.top
*.admin.smmfaster.online *.airflow.smmfaster.online *.api.smmfaster.online *.random.smmfaster.online smmfaster.online *.smmfaster.online
*.random.storiesog.info storiesog.info *.storiesog.info
*.3ugcn.swiftplumedeck.cfd *.iovou.swiftplumedeck.cfd swiftplumedeck.cfd *.swiftplumedeck.cfd
tav2e0w.cc *.tav2e0w.cc
*.8cnplf.todayimatter.net *.app.todayimatter.net *.staging.todayimatter.net todayimatter.net *.todayimatter.net *.uat.todayimatter.net
*.random.wud.info wud.info *.wud.info
*.r2wg51.wxyy123.top wxyy123.top *.wxyy123.top