Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=aiviptourguide.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 20, 2026
Valid Until
August 18, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D8:83:58:04:84:60:A9:67:21:AB:75:41:FC:D9:93:9C:8C:FC:48:1F:BB:C4:CC:66:0B:4B:B3:F5:72:2C:50:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
saaswriting.com *.saaswriting.com *.hostmaster.saaswriting.com *.www.saaswriting.com

Other domains in certificate

*.3f4dd7ee-baf2-4f7d-8a90-2df8f5477496.aiviptourguide.com *.9324b81f-26e0-4af3-b174-af154cafb394.aiviptourguide.com *.adm.aiviptourguide.com aiviptourguide.com *.aiviptourguide.com *.assets.aiviptourguide.com *.autoconfig.aiviptourguide.com *.autodiscover.aiviptourguide.com *.backend.aiviptourguide.com *.c019f7ee-d6ab-48db-b941-308343191c25.aiviptourguide.com *.chat.aiviptourguide.com *.fascbassets.aiviptourguide.com *.hosting.aiviptourguide.com *.ipv6.aiviptourguide.com *.new.aiviptourguide.com *.vpn.aiviptourguide.com
amanullah.com *.amanullah.com *.www.amanullah.com
annasarchive.gl *.annasarchive.gl *.ww17.annasarchive.gl
aspirehairsalons.co.uk *.aspirehairsalons.co.uk
border.watch *.border.watch *.m.border.watch *.www.border.watch
burbowl.com *.burbowl.com *.m.burbowl.com
*.assets.clara.onl clara.onl *.clara.onl *.test.clara.onl
componentvideo.it *.componentvideo.it *.mail.componentvideo.it *.www.componentvideo.it
dekor.live *.dekor.live
elitetalentconsultants.org *.elitetalentconsultants.org
furiabet.site *.furiabet.site
goophone.net *.goophone.net *.mta-sts.goophone.net *.news.goophone.net
*.admin.hanyide.cn *.api.hanyide.cn *.app.hanyide.cn hanyide.cn *.hanyide.cn
megaspace267.top *.megaspace267.top
mohnberg-gmbh.de *.mohnberg-gmbh.de
*.hostmaster.newmedia1.it newmedia1.it *.newmedia1.it *.remote.newmedia1.it
*.pay.prestige-aura.shop prestige-aura.shop *.prestige-aura.shop
readmyexclusivetowerguide.online *.readmyexclusivetowerguide.online *.www.readmyexclusivetowerguide.online
*.sfp.teaye.cn teaye.cn *.teaye.cn *.wap.teaye.cn *.www.teaye.cn
*.staging.telephoneconsultant.it telephoneconsultant.it *.telephoneconsultant.it
theheartofdallas.org *.theheartofdallas.org
*.mail.theverge.media theverge.media *.theverge.media
*.cg4o5.wawe-gazecore.xyz *.kwid9.wawe-gazecore.xyz wawe-gazecore.xyz *.wawe-gazecore.xyz *.z4gbs.wawe-gazecore.xyz