Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=cafepaioficial.online
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 30, 2026
Valid Until
April 30, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D6:12:7B:66:35:EA:7D:45:72:D6:F7:A0:45:FE:08:12:55:92:43:DF:84:7F:12:F5:76:FB:7A:38:E2:D6:AF:5A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
bellroy.online
*.bellroy.online
*.d2f650hvjk5s73d2lovg.bellroy.online
*.mjcsjww25.bellroy.online
*.root.bellroy.online
aeropress.online
*.aeropress.online
*.random.aeropress.online
ammosquitonetservices.com
*.ammosquitonetservices.com
armelrosa.store
*.armelrosa.store
*.ww25.armelrosa.store
atag.pro
*.atag.pro
*.mail.atag.pro
cafepaioficial.online
*.cafepaioficial.online
*.ww25.cafepaioficial.online
carbonbaits.co.uk
*.carbonbaits.co.uk
*.ww25.carbonbaits.co.uk
firmwaretechnology.com
*.firmwaretechnology.com
fitness-freak.store
*.fitness-freak.store
*.smartr.fitness-freak.store
frugalmcdougall2024.com
*.frugalmcdougall2024.com
*.pay.frugalmcdougall2024.com
gerain.store
*.gerain.store
*.ww25.gerain.store
hellrazroutdoorcooking.com
*.hellrazroutdoorcooking.com
*.random.hellrazroutdoorcooking.com
*.www.hellrazroutdoorcooking.com
*.79.heretic.online
heretic.online
*.heretic.online
hosting-guru.ru
*.hosting-guru.ru
iluminate.digital
*.iluminate.digital
kartubet88.vip
*.kartubet88.vip
*.mail.kartubet88.vip
*.www.kartubet88.vip
*.d.leadershop.xyz
*.dash.leadershop.xyz
*.dashs.leadershop.xyz
*.hs2.leadershop.xyz
leadershop.xyz
*.leadershop.xyz
*.m.leadershop.xyz
*.root.leadershop.xyz
*.webmail.leadershop.xyz
*.wildcard.leadershop.xyz
m-u.bet
*.m-u.bet
mbay.online
*.mbay.online
*.ww25.mbay.online
nguoivietoi.com
*.nguoivietoi.com
*.cpanel.peaceinnovationsworld.org
*.cpcontacts.peaceinnovationsworld.org
peaceinnovationsworld.org
*.peaceinnovationsworld.org
*.staging.peaceinnovationsworld.org
*.pop.shaheed4u.club
shaheed4u.club
*.shaheed4u.club
*.sitemap.shaheed4u.club
*.www.shaheed4u.club
skmesdix.pl
*.skmesdix.pl
*.ww25.skmesdix.pl
toeictestapp.com
*.toeictestapp.com
*.www.toeictestapp.com
ultracabs.co.uk
*.ultracabs.co.uk
workimgadvantage.com
*.workimgadvantage.com
*.quiz.xxjoa36.com
*.rdweb.xxjoa36.com
xxjoa36.com
*.xxjoa36.com
Other domains in certificate