76/100 SECURITY SCORE

Certificate Information

Subject
CN=chevycamaromi.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 18, 2025
Valid Until
March 18, 2026 38 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A5:56:2B:C7:B0:73:36:CC:0D:1E:03:2C:A2:8A:91:93:83:FB:7A:68:0F:6B:47:C9:60:F3:1B:F8:8E:0C:E1:D7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
dokibit.com *.dokibit.com *.docs.dokibit.com

Other domains in certificate

aidedd.com *.aidedd.com *.dev.aidedd.com *.rpg.aidedd.com
*.api.carpapaautogroup.com *.backend.carpapaautogroup.com carpapaautogroup.com *.carpapaautogroup.com *.demo.carpapaautogroup.com *.dev.carpapaautogroup.com *.ww25.carpapaautogroup.com
chevycamaromi.com *.chevycamaromi.com *.dev.chevycamaromi.com
*.development-bi.digitabili.blog digitabili.blog *.digitabili.blog *.insight.digitabili.blog
*.d.flixzone.xyz flixzone.xyz *.flixzone.xyz *.tm.flixzone.xyz
*.d.hacomics.xyz hacomics.xyz *.hacomics.xyz *.www.hacomics.xyz
*.dns1.hi-it-songs.xyz *.download.hi-it-songs.xyz hi-it-songs.xyz *.hi-it-songs.xyz
*.dev-slack.hotpizza.io hotpizza.io *.hotpizza.io *.pay.hotpizza.io *.slack.hotpizza.io
*.dev.jioai.io jioai.io *.jioai.io
*.comune.keyaeurope.com *.dev.keyaeurope.com keyaeurope.com *.keyaeurope.com
*.atherischesleben.lilyloom.xyz *.dewalt.lilyloom.xyz *.enamel.lilyloom.xyz lilyloom.xyz *.lilyloom.xyz *.omaha.lilyloom.xyz
*.demo.mansfieldelectrical.co.uk *.dev.mansfieldelectrical.co.uk *.magento.mansfieldelectrical.co.uk mansfieldelectrical.co.uk *.mansfieldelectrical.co.uk
*.download.paprikagranada.com paprikagranada.com *.paprikagranada.com *.ww38.paprikagranada.com
*.dev.phareg.life phareg.life *.phareg.life
*.dev.ratengeslot.click ratengeslot.click *.ratengeslot.click *.rustore.ratengeslot.click
*.a29.realmhard.online *.dev.realmhard.online *.ns1.realmhard.online *.ns2.realmhard.online realmhard.online *.realmhard.online
*.dev.safewebbrowsing-zone.com *.pop.safewebbrowsing-zone.com safewebbrowsing-zone.com *.safewebbrowsing-zone.com *.smtp.safewebbrowsing-zone.com *.www.safewebbrowsing-zone.com
*.demo.sanautos.com sanautos.com *.sanautos.com *.toyotainfo.sanautos.com
*.app.scene.bio *.demo.scene.bio *.full.scene.bio *.random.scene.bio scene.bio *.scene.bio *.www.scene.bio