76/100 SECURITY SCORE

Certificate Information

Subject
CN=33648.lgbt
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 23, 2026
Valid Until
August 21, 2026 70 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
82:4A:5F:A4:8C:15:0F:D1:F1:B1:9F:A2:83:BB:F8:BE:87:DF:79:A1:D0:33:FC:3E:A9:19:C8:5C:C4:BD:96:C7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
linkers.org *.linkers.org

Other domains in certificate

33648.lgbt *.33648.lgbt
36968.lgbt *.36968.lgbt
dental-implant-t32.click *.dental-implant-t32.click
depressiontestonksdfs32.sbs *.depressiontestonksdfs32.sbs
desertmanor.com *.desertmanor.com
designerids.com *.designerids.com
destz.cn *.destz.cn
dewislot77-1.shop *.dewislot77-1.shop
dewislot77it.lol *.dewislot77it.lol
dewislot77it.xyz *.dewislot77it.xyz
dexscreeners-live.com *.dexscreeners-live.com
dfacpz34.com *.dfacpz34.com
dfceph.sbs *.dfceph.sbs
dfpaz.win *.dfpaz.win
dhdaop.cn *.dhdaop.cn
diabetes-screening-for-employees.sbs *.diabetes-screening-for-employees.sbs
dialoguestudio1.com *.dialoguestudio1.com
dzkjd.loan *.dzkjd.loan
eastafricanbushsafaris.com *.eastafricanbushsafaris.com
educateclassavo.com *.educateclassavo.com
eqmcare.com *.eqmcare.com
eqmcoaches.com *.eqmcoaches.com
eurekaportugal2021-22.pt *.eurekaportugal2021-22.pt
fe1sx8.cyou *.fe1sx8.cyou
femalesymbol.com *.femalesymbol.com
fortuneconnectltd.com *.fortuneconnectltd.com
lusciouslivingtoday.com *.lusciouslivingtoday.com
margarine.studio *.margarine.studio
mm6oinpdr9.icu *.mm6oinpdr9.icu
mmtacademy.online *.mmtacademy.online
modernologistics.com *.modernologistics.com
n43x.cyou *.n43x.cyou
neurotribeuk.com *.neurotribeuk.com
nicherie.com *.nicherie.com
noblegardenteam.live *.noblegardenteam.live
nofje.town *.nofje.town
nrgkings.com *.nrgkings.com
officialauthenticsaintshops.com *.officialauthenticsaintshops.com
openbeanstalkwebsolutions.com *.openbeanstalkwebsolutions.com
palmbeachfl.org *.palmbeachfl.org
photon.lol *.photon.lol
planetfootwear.com *.planetfootwear.com
plantanopowerchips.com *.plantanopowerchips.com
plosworkshop.org *.plosworkshop.org