76/100 SECURITY SCORE

Certificate Information

Subject
CN=guardianeyewash.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 15, 2026
Valid Until
August 13, 2026 84 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A6:F4:20:82:36:D7:66:B6:38:6E:C1:C8:D4:A5:8E:F4:AF:ED:35:CE:5E:7E:66:16:E5:8F:E7:4D:23:04:A2:26
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
perlai.com *.perlai.com *.portal.perlai.com *.sitemaps.perlai.com *.soundhunter.perlai.com *.www.perlai.com

Other domains in certificate

500course.com *.500course.com *.5pv1t2.500course.com *.ftp.500course.com
*.app.biologiccotton.com biologiccotton.com *.biologiccotton.com *.demo.biologiccotton.com *.superset.biologiccotton.com *.test.biologiccotton.com
dillingerwheels.com *.dillingerwheels.com *.sitemap.dillingerwheels.com
estudiantes.net *.estudiantes.net *.ffffffffffff.estudiantes.net *.mx.estudiantes.net
*.com.guardianeyewash.com guardianeyewash.com *.guardianeyewash.com
hsx0022.com *.hsx0022.com *.ww25.hsx0022.com *.www.hsx0022.com
*.hostmaster.lozioni.com lozioni.com *.lozioni.com *.mail.lozioni.com *.mail2.lozioni.com
*.c.lud.au *.huja.lud.au *.kasha.lud.au lud.au *.lud.au *.musha.lud.au *.sina.lud.au *.ume.lud.au *.umesha.lud.au *.usha.lud.au *.ww25.lud.au
*.media.otelciler.com otelciler.com *.otelciler.com *.sitemaps.otelciler.com *.ww1.otelciler.com
*.32.rwvjdspot.store rwvjdspot.store *.rwvjdspot.store *.ww16.rwvjdspot.store
*.admin.santoleri.it *.app.santoleri.it *.backend.santoleri.it *.dashboard.santoleri.it *.dashboards.santoleri.it *.data.santoleri.it *.demo.santoleri.it *.dev.santoleri.it *.redash.santoleri.it *.reports.santoleri.it santoleri.it *.santoleri.it *.superset.santoleri.it
tropicrum.com *.tropicrum.com
*.deuy6.xn--u0x64a.com *.m.xn--u0x64a.com *.nksmydeuy6.xn--u0x64a.com *.www.xn--u0x64a.com xn--u0x64a.com *.xn--u0x64a.com
*.admin.youroffice.it *.analytics.youroffice.it *.api.youroffice.it *.app.youroffice.it *.dev.youroffice.it *.owa.youroffice.it *.remote.youroffice.it *.report.youroffice.it *.reporting.youroffice.it *.reports.youroffice.it *.superset.youroffice.it youroffice.it *.youroffice.it