Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=rightly.org
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 05, 2026
Valid Until
May 06, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FA:A2:9F:65:6A:28:F3:66:BD:12:95:F9:85:EE:9C:47:CA:0A:AE:79:29:D8:75:CF:B6:F8:EF:30:E7:AE:99:B1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
servixai.com
*.servixai.com
qyf8qiuobiyqivd.top
*.qyf8qiuobiyqivd.top
r2xtfp.my
*.r2xtfp.my
r365slot.org
*.r365slot.org
rasputin.one
*.rasputin.one
restaurant-mule-blanche.com
*.restaurant-mule-blanche.com
restaurantegepetto.com
*.restaurantegepetto.com
rhawh.com
*.rhawh.com
rightly.org
*.rightly.org
riskmapp.click
*.riskmapp.click
rnd777.net
*.rnd777.net
rnimoniasdealrchpro.shop
*.rnimoniasdealrchpro.shop
rnioasdealrchgrid.cyou
*.rnioasdealrchgrid.cyou
rnmpdszihmf.cc
*.rnmpdszihmf.cc
rnx11win.club
*.rnx11win.club
rnyma.net
*.rnyma.net
robertsilverman.com
*.robertsilverman.com
royalbroadway.com
*.royalbroadway.com
royalpetssociety.live
*.royalpetssociety.live
royalpropertiesdubai.com
*.royalpropertiesdubai.com
runnersgr.com
*.runnersgr.com
rwqdw00558wqedw02wqedqn.vip
*.rwqdw00558wqedw02wqedqn.vip
s0uyr8v.cyou
*.s0uyr8v.cyou
sahwaacademy.com
*.sahwaacademy.com
saintpatrick.biz
*.saintpatrick.biz
samotna.com
*.samotna.com
seo-without-borders.com
*.seo-without-borders.com
sepidmedical.com
*.sepidmedical.com
serpability.com
*.serpability.com
sharevideo.it
*.sharevideo.it
shedoesincity.com
*.shedoesincity.com
shochan.org
*.shochan.org
skyhills.co
*.skyhills.co
slots996.com
*.slots996.com
solcat.net
*.solcat.net
soojishop.com
*.soojishop.com
spadino.it
*.spadino.it
sportcity.it
*.sportcity.it
sqlhubz.click
*.sqlhubz.click
srxlikereal.com
*.srxlikereal.com
ssaircond.com
*.ssaircond.com
szss14.cn
*.szss14.cn
tarafbet440.com
*.tarafbet440.com
tarntarancity.com
*.tarntarancity.com
tastygourmetfood.cfd
*.tastygourmetfood.cfd
Other domains in certificate