76/100 SECURITY SCORE

Certificate Information

Subject
CN=385972.one
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 21, 2026
Valid Until
August 19, 2026 60 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B6:EA:86:34:5C:9F:9C:6E:5E:3A:8D:D5:DD:F4:13:3F:55:D2:B9:5F:62:A4:92:C0:3A:5E:B4:4F:C6:6A:28:00
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
upsellpath.com *.upsellpath.com *.cloud.upsellpath.com

Other domains in certificate

385972.one *.385972.one
813598.xyz *.813598.xyz
acesmaster.xyz *.acesmaster.xyz
amadeusvanillastore.com *.amadeusvanillastore.com
beachfactors.xyz *.beachfactors.xyz
btcfastpay.xyz *.btcfastpay.xyz
btoulallou.co *.btoulallou.co
bydottedlinecomm.com *.bydottedlinecomm.com
cfharrisonburg.com *.cfharrisonburg.com
egfmy.cc *.egfmy.cc
*.dashboard.gcfusion.info gcfusion.info *.gcfusion.info
getcrates.com *.getcrates.com
goeozturklegal.sbs *.goeozturklegal.sbs
hifinicom.xyz *.hifinicom.xyz
kaceyblog.online *.kaceyblog.online *.kafka.kaceyblog.online
*.0m74xs.toyi.net.cn *.11270207.toyi.net.cn *.2ryc.toyi.net.cn *.37eam9.toyi.net.cn *.3ubed.toyi.net.cn *.3vqzs.toyi.net.cn *.4jj.toyi.net.cn *.59.toyi.net.cn *.5til.toyi.net.cn *.6w3l.toyi.net.cn *.baidu.toyi.net.cn *.bnsq.toyi.net.cn *.bw4c.toyi.net.cn *.c1m.toyi.net.cn *.cdn.toyi.net.cn *.cgdpxvqj.toyi.net.cn *.cn.toyi.net.cn *.cui.toyi.net.cn *.cyn.toyi.net.cn *.download.toyi.net.cn *.e8vmih.toyi.net.cn *.euw.toyi.net.cn *.f2d5g8.toyi.net.cn *.ffbr.toyi.net.cn *.fix7.toyi.net.cn *.fkb.toyi.net.cn *.flbb1.toyi.net.cn *.help.toyi.net.cn *.ikc.toyi.net.cn *.j5skxq.toyi.net.cn *.jwu.toyi.net.cn *.l070k.toyi.net.cn *.l647bi.toyi.net.cn *.mz.toyi.net.cn *.n2.toyi.net.cn *.nee.toyi.net.cn *.new.toyi.net.cn *.nuw.toyi.net.cn *.s4184442.toyi.net.cn *.s4185100.toyi.net.cn *.sa.toyi.net.cn *.server.toyi.net.cn *.support.toyi.net.cn toyi.net.cn *.toyi.net.cn *.uaj.toyi.net.cn *.ur3.toyi.net.cn *.whm.toyi.net.cn *.wso.toyi.net.cn *.xfi.toyi.net.cn *.y3bjbb.toyi.net.cn *.z2.toyi.net.cn *.zqdw.toyi.net.cn *.zz.toyi.net.cn