Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=sigmafaucets.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 20, 2026
Valid Until
July 19, 2026 48 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D9:75:CD:F8:B0:50:E4:6C:B0:47:B1:25:77:95:40:6C:3C:A8:E3:64:2B:70:D1:0A:CF:B2:2A:78:11:99:A1:71
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
bhq.it *.bhq.it *.admin.bhq.it *.analytics.bhq.it *.api.bhq.it *.backend.bhq.it *.bi.bhq.it *.board.bhq.it *.chart.bhq.it *.dashboard.bhq.it *.dashboards.bhq.it *.demo.bhq.it *.hostmaster.bhq.it *.intelligence.bhq.it *.notexistsapp.bhq.it *.notexistsdev.bhq.it *.remote.bhq.it *.report.bhq.it *.reports.bhq.it *.sandbox.bhq.it *.stats.bhq.it

Other domains in certificate

*.1dpi1dpi.36huo301che.xyz *.1dpisjsf.36huo301che.xyz 36huo301che.xyz *.36huo301che.xyz *.msdtcd6h.36huo301che.xyz *.msdtmsdt.36huo301che.xyz *.msdtsjsf.36huo301che.xyz *.r2ymr2ym.36huo301che.xyz *.r2ymsjsf.36huo301che.xyz *.sjsfr2ym.36huo301che.xyz *.sjsfsjsf.36huo301che.xyz
*.199883dd-adcc-4138-8989-234183e69276.axxxess.com *.adobe.axxxess.com *.app.axxxess.com axxxess.com *.axxxess.com *.b1ca3eec-706c-4219-a966-e3bb49083b98.axxxess.com *.bigdata.axxxess.com *.core.axxxess.com *.dev.axxxess.com *.home.axxxess.com *.kvjbophpmyadmin.axxxess.com *.links.axxxess.com *.m.axxxess.com *.mail.axxxess.com *.mobile.axxxess.com *.news.axxxess.com *.ns.axxxess.com *.owa.axxxess.com *.phpmyadmin.axxxess.com *.random.axxxess.com *.remote.axxxess.com *.sistema.axxxess.com *.smtp.axxxess.com *.vpn.axxxess.com *.wap.axxxess.com *.www.axxxess.com
*.art.paisal.com *.cicd.paisal.com paisal.com *.paisal.com *.portal.paisal.com *.press.paisal.com *.production.paisal.com *.rustore.paisal.com *.tv.paisal.com *.ww1.paisal.com *.ww25.paisal.com
*.api.rollergloves.com *.cloud.rollergloves.com *.hostmaster.rollergloves.com *.kubeflow-pipeline.rollergloves.com *.mobile.rollergloves.com *.news.rollergloves.com *.rdweb.rollergloves.com rollergloves.com *.rollergloves.com *.staging.rollergloves.com *.test.rollergloves.com *.vpn.rollergloves.com *.wap.rollergloves.com
*.ap.selom.com *.portal.selom.com selom.com *.selom.com
sigmafaucets.com *.sigmafaucets.com *.ww38.sigmafaucets.com