91/100 SECURITY SCORE

Certificate Information

Subject
CN=cosafare.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 19, 2026
Valid Until
July 18, 2026 42 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
82:28:5C:8B:B1:47:26:EF:E2:26:FD:00:E6:8F:76:B4:D8:18:77:4B:F2:15:A5:49:72:CA:A0:24:7C:EE:9E:1B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin
Permissions-Policy
Present
geolocation=(), midi=(), sync-xhr=(); +6 more
Recommendations
  • Add Content-Security-Policy header to prevent XSS attacks

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
random.money *.random.money *.organizing.random.money *.status.random.money

Other domains in certificate

855acdirect.com *.855acdirect.com *.ww25.855acdirect.com
autosahko.net *.autosahko.net *.ns.autosahko.net
badkamermeubels.com *.badkamermeubels.com *.sitemap.badkamermeubels.com *.ww16.badkamermeubels.com *.ww17.badkamermeubels.com *.ww25.badkamermeubels.com *.ww38.badkamermeubels.com *.www.badkamermeubels.com
bmzhfbcse.com *.bmzhfbcse.com *.pz.bmzhfbcse.com
bonglyrics.com *.bonglyrics.com *.data.bonglyrics.com *.ibank.bonglyrics.com *.paypal.bonglyrics.com *.web3.bonglyrics.com *.www2.bonglyrics.com
*.api.brangkas22.info brangkas22.info *.brangkas22.info *.www.brangkas22.info
contentmarket.com.au *.contentmarket.com.au *.ww25.contentmarket.com.au
*.ariel.cosafare.com cosafare.com *.cosafare.com *.dev.cosafare.com *.emv1.cosafare.com *.test.cosafare.com *.ww1.cosafare.com
directhvac.us *.directhvac.us
djposh.com *.djposh.com *.vpn.djposh.com *.www.djposh.com
expanding.au *.expanding.au
howmuch.help *.howmuch.help *.someanxiousmoments.howmuch.help *.xiousmoments.howmuch.help
ipc9.org *.ipc9.org
*.38.localiz.me *.admin.localiz.me localiz.me *.localiz.me *.mail.localiz.me *.remote.localiz.me *.ww16.localiz.me *.ww25.localiz.me *.ww38.localiz.me *.www.localiz.me
organism.in *.organism.in *.ww38.organism.in
*.assets.pivonrevy.com *.beta.pivonrevy.com *.cloud.pivonrevy.com *.dev.pivonrevy.com pivonrevy.com *.pivonrevy.com *.rd.pivonrevy.com
*.franchise.rewed.com *.hostmaster.rewed.com rewed.com *.rewed.com *.uang.rewed.com *.ww25.rewed.com
*.smtp.torpbats.com torpbats.com *.torpbats.com
*.cpcalendars.viralpost.in *.cpcontacts.viralpost.in *.login.viralpost.in viralpost.in *.viralpost.in