Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=markspencer.cz
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 31, 2026
Valid Until
August 29, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1E:12:A0:2B:AA:B3:05:87:D6:59:EF:59:09:B1:5F:71:DB:DB:49:5D:99:44:2A:00:C6:D2:FE:DB:07:13:26:BF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
soi.golf *.soi.golf *.32.soi.golf

Other domains in certificate

1149yhc301.top *.1149yhc301.top *.ctdlhl.1149yhc301.top
1jingshen15.top *.1jingshen15.top *.xn--0ws07i1vm7z5a.1jingshen15.top
489723.lol *.489723.lol *.k3w5td.489723.lol
accountsopenai.com *.accountsopenai.com *.cvs.accountsopenai.com *.e0b76195-0fa5-4cd6-ab7c-49047392fe3e.accountsopenai.com *.forum.accountsopenai.com *.m.accountsopenai.com *.random.accountsopenai.com *.ww25.accountsopenai.com *.ww38.accountsopenai.com
birthinjury.baby *.birthinjury.baby *.hostmaster.birthinjury.baby *.m.birthinjury.baby *.pkfbmg.birthinjury.baby *.www.birthinjury.baby
*.a.discovr-line-story.info discovr-line-story.info *.discovr-line-story.info *.m.discovr-line-story.info *.sitemap.discovr-line-story.info
getlockedin.tech *.getlockedin.tech *.gitlab.getlockedin.tech *.ios.getlockedin.tech *.mail2.getlockedin.tech *.mx.getlockedin.tech *.staging.getlockedin.tech *.webdisk.getlockedin.tech *.webmail.getlockedin.tech *.ww38.getlockedin.tech *.www.getlockedin.tech
*.bankid.log-inf.com *.intesasanpaolo.log-inf.com log-inf.com *.log-inf.com *.m-t.log-inf.com *.pendaftaran-kerja.log-inf.com *.ww25.log-inf.com
*.mail.markspencer.cz markspencer.cz *.markspencer.cz
privately.in *.privately.in *.ronapeedfly.privately.in
*.cloud.sewingpro.com *.rdweb.sewingpro.com *.remote.sewingpro.com sewingpro.com *.sewingpro.com *.www.sewingpro.com
*.server2.tirexo.cc *.support.tirexo.cc tirexo.cc *.tirexo.cc *.ww1.tirexo.cc *.ww2.tirexo.cc *.ww25.tirexo.cc *.www2.tirexo.cc
tvmada.com *.tvmada.com *.www.tvmada.com
*.assets.vibegamble.com *.blog.vibegamble.com *.m.vibegamble.com *.sitemaps.vibegamble.com vibegamble.com *.vibegamble.com
*.websearch.wonderfulsearches.info wonderfulsearches.info *.wonderfulsearches.info *.ww25.wonderfulsearches.info
*.sslvpn.xn--9kr752h9jah19b.com xn--9kr752h9jah19b.com *.xn--9kr752h9jah19b.com
*.ssl.xn--i6z.com xn--i6z.com *.xn--i6z.com