Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=kaufgemeinschaft.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 04, 2026
Valid Until
July 03, 2026 54 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B0:E8:00:A6:C7:59:F8:8E:0F:D0:58:F5:A4:C1:F4:D4:B1:27:13:37:B1:1D:B8:97:6A:69:F3:0A:E0:85:CC:17
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
smartai.diy *.smartai.diy *.app.smartai.diy

Other domains in certificate

988920a5.buzz *.988920a5.buzz *.988920lt-4b50b.988920a5.buzz *.988920lt-c9a1p.988920a5.buzz *.988920lt-fjipc.988920a5.buzz
kaufgemeinschaft.com *.kaufgemeinschaft.com *.lwtidautoconfig.kaufgemeinschaft.com
*.a.paypal.locker *.airbnbhostsupplystore.paypal.locker *.airbnbinstagram.paypal.locker *.airbnbinsure.paypal.locker *.airbnbmotocross.paypal.locker *.beta108d.paypal.locker *.carriermobilityrefund.paypal.locker *.cl.paypal.locker *.client22.paypal.locker *.coinbase-withdraw-verifications.paypal.locker *.coinbase73.paypal.locker *.coinbasewalletrecovery.paypal.locker *.dev-docs.paypal.locker *.devsite.paypal.locker *.dispute.paypal.locker *.dot-baojiqiaoluntan.paypal.locker *.else.paypal.locker *.fbjs.paypal.locker *.ftl.paypal.locker *.fwd.paypal.locker *.g.paypal.locker *.glassdoorrefrigeratorcommercial.paypal.locker *.kayakak.paypal.locker *.lesschwab.paypal.locker *.linkedinaccount.paypal.locker *.maild-he.paypal.locker *.multisite-test.paypal.locker *.netflix-francefr.paypal.locker *.netflix-supportcare.paypal.locker *.nrd.paypal.locker *.ocrcard.paypal.locker *.pala.paypal.locker *.paypal-confirmation-info.paypal.locker paypal.locker *.paypal.locker *.pnqoxxbs.paypal.locker *.prod.paypal.locker *.redditleaks.paypal.locker *.sasgnamgite-com.paypal.locker *.secure.paypal.locker *.shf.paypal.locker *.snapchatagram.paypal.locker *.snapchataidrafox.paypal.locker *.snapchatrecovery.paypal.locker *.stage.paypal.locker *.supernatural-itlb01external.paypal.locker *.t.paypal.locker *.tinder-code-verify.paypal.locker *.tinder-notification.paypal.locker *.twitter-helpmanage.paypal.locker *.twitteradsacademy.paypal.locker *.twitterstoners.paypal.locker *.vhmgs.paypal.locker *.wc.paypal.locker *.webflywheel.paypal.locker *.xbs.paypal.locker *.yahoo-bingo.paypal.locker *.yahoo-verification.paypal.locker *.yahoo333.paypal.locker *.yst.paypal.locker
*.5147ff3a-b362-4042-8001-36ddbaa7ca52.simplementeia.com *.944b1a10-b4cb-4da2-bc0d-ca6af4fe0386.simplementeia.com *.a.simplementeia.com *.admin.simplementeia.com *.app.simplementeia.com *.bgvzva.simplementeia.com *.cloud.simplementeia.com *.d20a3e72-e579-4854-b7e0-fb3fffc77432.simplementeia.com *.demo.simplementeia.com *.dev.simplementeia.com *.mail.simplementeia.com *.rds.simplementeia.com *.rdweb.simplementeia.com *.remote.simplementeia.com simplementeia.com *.simplementeia.com *.test.simplementeia.com *.wmcsbrd.simplementeia.com