Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=coinstruct.io
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 30, 2026
Valid Until
July 29, 2026
80 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:D5:A8:1E:AE:14:E0:F4:BC:8A:51:73:5D:F6:8F:BB:C1:50:3A:DF:3C:52:D8:AB:7A:F3:7F:37:03:ED:25:8D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
61 domains
senata.io
*.senata.io
amediasocial.click
*.amediasocial.click
*.random.amediasocial.click
barumulai20.click
*.barumulai20.click
*.m.barumulai20.click
*.ww25.barumulai20.click
bestaustralianhoney.com.au
*.bestaustralianhoney.com.au
carlislenews.co.uk
*.carlislenews.co.uk
carselect.net.au
*.carselect.net.au
*.random.carselect.net.au
coinstruct.io
*.coinstruct.io
*.cpcontacts.coinstruct.io
*.m.coinstruct.io
enevu.com
*.enevu.com
*.mx.enevu.com
*.el.fcl.de
fcl.de
*.fcl.de
fofifo.com
*.fofifo.com
*.ww38.fofifo.com
fxfx333.com
*.fxfx333.com
*.com.hipk.vip
*.gov.hipk.vip
hipk.vip
*.hipk.vip
*.ftp.holmesimprovementsllc.com
holmesimprovementsllc.com
*.holmesimprovementsllc.com
kinderschwimmbecken.de
*.kinderschwimmbecken.de
kwchamber.org
*.kwchamber.org
*.random.kwchamber.org
morrisandraper.com
*.morrisandraper.com
*.app.quantos.online
quantos.online
*.quantos.online
sayalipatankar.com
*.sayalipatankar.com
steezy.life
*.steezy.life
thp4851.cc
*.thp4851.cc
trybroadwave.com
*.trybroadwave.com
*.ww25.trybroadwave.com
wwwedisoninsurance.com
*.wwwedisoninsurance.com
xxxpornvideoxxx.online
*.xxxpornvideoxxx.online
Other domains in certificate