Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=phimmoi.asia
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 18, 2026
Valid Until
July 17, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DB:82:6C:62:6D:90:60:C6:A8:44:37:D6:27:D2:07:20:50:29:57:40:E2:AB:03:F3:95:BD:90:C9:9A:6A:F2:39
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
signamint.com
*.signamint.com
*.m.signamint.com
bidding.vc
*.bidding.vc
*.hostmaster.bidding.vc
*.www.bidding.vc
bucharest.it
*.bucharest.it
*.a074f73f-2536-429c-8112-e626732b847c.couponsave.blog
*.admin.couponsave.blog
*.api.couponsave.blog
*.app.couponsave.blog
*.assets.couponsave.blog
*.backup.couponsave.blog
couponsave.blog
*.couponsave.blog
*.dashboard.couponsave.blog
*.fxmvwhostmaster.couponsave.blog
*.hostmaster.couponsave.blog
*.kapedmembers.couponsave.blog
*.mail.couponsave.blog
*.portal.couponsave.blog
*.stg.couponsave.blog
*.test.couponsave.blog
*.uat.couponsave.blog
*.web.couponsave.blog
*.www.couponsave.blog
denverregionalequityatlas.org
*.denverregionalequityatlas.org
*.ww25.denverregionalequityatlas.org
*.backup.httpatt.com
*.blog.httpatt.com
*.crm.httpatt.com
*.dash.httpatt.com
*.forums.httpatt.com
httpatt.com
*.httpatt.com
*.news.httpatt.com
*.staging.httpatt.com
*.admin.instructions.it
*.api.instructions.it
instructions.it
*.instructions.it
kdream.info
*.kdream.info
*.re.kdream.info
*.ai.kinocoin.online
*.cms.kinocoin.online
*.fhd.kinocoin.online
*.flow.kinocoin.online
*.flowise.kinocoin.online
*.flowiseai.kinocoin.online
*.hd.kinocoin.online
kinocoin.online
*.kinocoin.online
*.preview.kinocoin.online
*.prod.kinocoin.online
*.test.kinocoin.online
*.video.kinocoin.online
*.eb375d59-0ba5-4d68-8884-7d1cf0516420.mugqr.com
mugqr.com
*.mugqr.com
*.admin.nibbler.it
*.dev.nibbler.it
*.metrics.nibbler.it
nibbler.it
*.nibbler.it
*.superset.nibbler.it
*.9574b38.nzqqo05.top
*.eab5d37.nzqqo05.top
nzqqo05.top
*.nzqqo05.top
*.cpanel.phimmoi.asia
phimmoi.asia
*.phimmoi.asia
*.ww1.phimmoi.asia
*.ww16.phimmoi.asia
*.ww25.phimmoi.asia
*.ecp.tag-a-bag.com
*.exmb2.tag-a-bag.com
*.mail3.tag-a-bag.com
*.mailgate.tag-a-bag.com
*.smtp.tag-a-bag.com
tag-a-bag.com
*.tag-a-bag.com
*.webmail.tag-a-bag.com
*.pg9.vipgame4.cc
vipgame4.cc
*.vipgame4.cc
Other domains in certificate