Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=noveldrama.io
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 02, 2026
Valid Until
April 02, 2026
36 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7E:77:F3:9D:1B:48:F0:97:3C:AF:81:91:B2:F8:E9:73:E5:79:BD:2B:2F:08:C5:B9:B2:90:B1:57:32:72:EE:6B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
schoolmaster.me
*.schoolmaster.me
ashemalez.com
*.ashemalez.com
autoaccidents.au
*.autoaccidents.au
avaliadorpremiado.pro
*.avaliadorpremiado.pro
coala.bet
*.coala.bet
coranacong.xyz
*.coranacong.xyz
*.gdwtce5ynj.coranacong.xyz
eurocarparts.store
*.eurocarparts.store
*.ww25.eurocarparts.store
*.ww38.eurocarparts.store
foreigninvestments.au
*.foreigninvestments.au
gamespix.bet
*.gamespix.bet
global-alpari.com
*.global-alpari.com
*.my-mobile.global-alpari.com
godspeed.ltd
*.godspeed.ltd
indiavision.live
*.indiavision.live
iosdeveloper.guru
*.iosdeveloper.guru
lotto123.bio
*.lotto123.bio
manishamaternityhospital.com
*.manishamaternityhospital.com
*.app.mpoyou.xyz
mpoyou.xyz
*.mpoyou.xyz
*.pop3.mpoyou.xyz
*.ww12.mpoyou.xyz
namdev.studio
*.namdev.studio
noveldrama.io
*.noveldrama.io
*.ww25.noveldrama.io
numa.blog
*.numa.blog
*.cdn.rateseter.com
*.free.rateseter.com
*.hostmaster.rateseter.com
*.it.rateseter.com
rateseter.com
*.rateseter.com
*.webapp.rateseter.com
*.ww25.rateseter.com
*.random.russische-hochzeit-deutschland.info
russische-hochzeit-deutschland.info
*.russische-hochzeit-deutschland.info
sportspodcastingnetwork.com
*.sportspodcastingnetwork.com
*.cpanel.tanjasovulj.com
tanjasovulj.com
*.tanjasovulj.com
*.webmail.tanjasovulj.com
*.www.tanjasovulj.com
tersess.com
*.tersess.com
*.dedic.topflix.club
*.demo.topflix.club
*.dev.topflix.club
*.magento.topflix.club
*.old.topflix.club
*.pop.topflix.club
*.shop.topflix.club
*.smtp.topflix.club
*.staging.topflix.club
*.store.topflix.club
*.test.topflix.club
topflix.club
*.topflix.club
*.ww38.topflix.club
*.www.topflix.club
*.zeus.topflix.club
weakheart.com
*.weakheart.com
xyzylsl.xyz
*.xyzylsl.xyz
*.z1.xyzylsl.xyz
*.random.yka.com.au
yka.com.au
*.yka.com.au
Other domains in certificate