76/100 SECURITY SCORE

Certificate Information

Subject
CN=tjmaxxjobs.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 24, 2026
Valid Until
July 23, 2026 59 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
23:A2:A7:DB:B7:3E:15:1D:70:8F:F2:56:31:2D:5C:DC:9C:CB:53:57:DD:05:70:B3:C3:49:B1:B9:32:2B:FB:52
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
urinary.it *.urinary.it *.notexistszimbra.urinary.it *.staging.urinary.it

Other domains in certificate

03270.pw *.03270.pw *.ww25.03270.pw
6chi.com *.6chi.com *.vpn.6chi.com *.www.6chi.com
backpqge.com *.backpqge.com *.superset.backpqge.com
*.a.catnetssr.com catnetssr.com *.catnetssr.com
conferencetables.com.au *.conferencetables.com.au *.random.conferencetables.com.au
*.autodiscover.emmtrc-tramonti2021.org emmtrc-tramonti2021.org *.emmtrc-tramonti2021.org
*.admin.gon88.tv *.api.gon88.tv *.demo.gon88.tv *.dev.gon88.tv gon88.tv *.gon88.tv *.test.gon88.tv
iocapecod.com *.iocapecod.com *.w2w.iocapecod.com
*.dc-865f0f46a008.javzx.com javzx.com *.javzx.com *.ww7.javzx.com
*.com.julielawsontimmer.com *.comune.julielawsontimmer.com *.eivc.julielawsontimmer.com *.hyhpfy.julielawsontimmer.com julielawsontimmer.com *.julielawsontimmer.com *.mail.julielawsontimmer.com *.mx.julielawsontimmer.com
*.8k5u7403l2rore3a.lgbtq.cam *.analytics-hotfix.lgbtq.cam *.backend.lgbtq.cam *.beta-analytic.lgbtq.cam lgbtq.cam *.lgbtq.cam *.qxu8op93i7m6jbbb.lgbtq.cam *.sitemaps.lgbtq.cam *.urz0uirm56ss5ved.lgbtq.cam *.wildcard.lgbtq.cam *.www.lgbtq.cam
*.cpanel.mixedandmotions.com *.mail.mixedandmotions.com mixedandmotions.com *.mixedandmotions.com
nhacam.com *.nhacam.com
prores.it *.prores.it *.remote.prores.it *.www.prores.it
*.real.starfollowers.site starfollowers.site *.starfollowers.site
*.cpanel.starlet.life starlet.life *.starlet.life *.ww25.starlet.life
tjmaxxjobs.com *.tjmaxxjobs.com *.ww25.tjmaxxjobs.com
vf8bevt.click *.vf8bevt.click *.ww25.vf8bevt.click
wraiter.xyz *.wraiter.xyz
*.sitemaps.xn--fhqs68hxkd58o.com xn--fhqs68hxkd58o.com *.xn--fhqs68hxkd58o.com
*.dddd.zbrush.work *.random.zbrush.work *.ww25.zbrush.work zbrush.work *.zbrush.work