76/100 SECURITY SCORE

Certificate Information

Subject
CN=random.money
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 28, 2026
Valid Until
July 27, 2026 54 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
44:F8:C5:42:88:22:18:02:ED:6E:5A:88:19:88:72:33:72:36:9A:BD:EC:C2:DE:26:22:70:C9:A2:0E:9B:47:85
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
purenutritious.com *.purenutritious.com *.cpcalendars.purenutritious.com *.sitemap.purenutritious.com *.webmail.purenutritious.com *.wwww.purenutritious.com

Other domains in certificate

acnalktubqf.com *.acnalktubqf.com
*.api.bambinionline.it bambinionline.it *.bambinionline.it *.dev.bambinionline.it *.staging.bambinionline.it
*.cloud.hsjeans.com hsjeans.com *.hsjeans.com *.intranet.hsjeans.com *.m.hsjeans.com *.portal.hsjeans.com *.rds.hsjeans.com *.rdweb.hsjeans.com *.remote.hsjeans.com *.www.hsjeans.com *.wwww.hsjeans.com
*.admin.luxed.net *.api.luxed.net *.autoconfig.luxed.net *.bbs.luxed.net *.cloud.luxed.net *.ebmail.luxed.net *.localhost.luxed.net *.log.luxed.net luxed.net *.luxed.net *.m.luxed.net *.pop.luxed.net *.rd.luxed.net *.remote.luxed.net *.smtp.luxed.net *.usps.luxed.net *.vpn.luxed.net *.wildcard.luxed.net *.www.luxed.net
nof-orientering.org *.nof-orientering.org *.webmail.nof-orientering.org
*.mbox.nymetrore.com nymetrore.com *.nymetrore.com *.ww25.nymetrore.com
ozveriyiz.org *.ozveriyiz.org *.sitemap.ozveriyiz.org
*.hostmaster.random.money *.organizing.random.money *.pas.random.money random.money *.random.money *.status.random.money *.ughpbsitemaps.random.money
*.admin.resultdrive.pro *.assets.resultdrive.pro *.dev.resultdrive.pro resultdrive.pro *.resultdrive.pro
*.1b9896c2-d719-4671-9953-0fc7b96991d2.universalorlandoai.com *.api.universalorlandoai.com *.b5f27691-13bc-4783-a464-60a8f63b119e.universalorlandoai.com *.bwujoyai.universalorlandoai.com *.ce9f8c23-b7cd-4766-bf64-0e77530e8033.universalorlandoai.com *.intranet.universalorlandoai.com *.mail.universalorlandoai.com *.nysxzrwc.universalorlandoai.com *.portal.universalorlandoai.com *.share.universalorlandoai.com *.sharepoint.universalorlandoai.com *.szfhnged.universalorlandoai.com universalorlandoai.com *.universalorlandoai.com *.vps.universalorlandoai.com
*.azzpyapp.winecave.club *.blog.winecave.club *.dev.winecave.club *.localhost.winecave.club *.m.winecave.club *.news.winecave.club *.test.winecave.club *.web.winecave.club winecave.club *.winecave.club