Open
Cached
·
2h ago
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=37160.how
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 02, 2026
Valid Until
July 31, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9C:49:77:6D:18:BF:17:76:F0:81:0B:65:F6:5A:00:66:6B:A4:C8:82:4A:75:A4:76:18:70:33:15:AC:65:F5:DF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
attini.io
*.attini.io
37160.how
*.37160.how
441e.cc
*.441e.cc
4860d.cc
*.4860d.cc
51300.net
*.51300.net
58249.xyz
*.58249.xyz
59686av.top
*.59686av.top
601105.top
*.601105.top
62tv250428.top
*.62tv250428.top
6dc5eghzjd.top
*.6dc5eghzjd.top
7832519.com
*.7832519.com
891i129.cc
*.891i129.cc
999750qm.xyz
*.999750qm.xyz
aaoj.org
*.aaoj.org
acomsa.co.za
*.acomsa.co.za
aimyb.com
*.aimyb.com
apollogp.com
*.apollogp.com
arkimedia.art
*.arkimedia.art
avolish.com
*.avolish.com
bapayshu.sbs
*.bapayshu.sbs
best-game-ar.info
*.best-game-ar.info
bintangsukses.store
*.bintangsukses.store
blazeodyssey71.info
*.blazeodyssey71.info
brightstreamnet.sbs
*.brightstreamnet.sbs
bw11110cd678cmggggggtp77ur.top
*.bw11110cd678cmggggggtp77ur.top
byfact.com
*.byfact.com
bzhen522.com
*.bzhen522.com
carnavalboi.bet
*.carnavalboi.bet
cw68by3ghy.top
*.cw68by3ghy.top
d73realm.lol
*.d73realm.lol
d73space.lol
*.d73space.lol
d80437727.com
*.d80437727.com
denverwigs.com
*.denverwigs.com
donasibarang.org
*.donasibarang.org
dyuresdamm.cc
*.dyuresdamm.cc
e83ydzqe2g.top
*.e83ydzqe2g.top
e86w.cyou
*.e86w.cyou
educationalinfozone.com
*.educationalinfozone.com
f0907904r48of3dkcsnd2ie2ng1sp.top
*.f0907904r48of3dkcsnd2ie2ng1sp.top
gates-of-olympus-slot.vip
*.gates-of-olympus-slot.vip
gigsmartsettlment.com
*.gigsmartsettlment.com
gk88o.com
*.gk88o.com
gosl1.live
*.gosl1.live
homeffect.info
*.homeffect.info
hsoh5ku.top
*.hsoh5ku.top
Other domains in certificate