76/100 SECURITY SCORE

Certificate Information

Subject
CN=mbsound.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 13, 2026
Valid Until
May 14, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BA:6E:AE:80:AF:34:A2:59:4B:37:28:99:5C:75:31:B6:15:A7:4D:14:7F:03:7F:37:83:D5:FC:FE:0E:1B:35:D7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
mbsound.com *.mbsound.com *.ebay.mbsound.com *.sitemaps.mbsound.com *.store.mbsound.com *.wiki.mbsound.com *.ww1.mbsound.com *.ww11.mbsound.com *.ww25.mbsound.com *.ww38.mbsound.com

Other domains in certificate

*.admin.carbazar.in carbazar.in *.carbazar.in
*.api.cariera.biz *.app.cariera.biz *.assets.cariera.biz *.bk.cariera.biz cariera.biz *.cariera.biz *.cpcalendars.cariera.biz *.cpcontacts.cariera.biz *.dev.cariera.biz *.ftp.cariera.biz *.help.cariera.biz *.localhost.cariera.biz *.m.cariera.biz *.mail.cariera.biz *.members.cariera.biz *.share.cariera.biz *.site.cariera.biz *.test.cariera.biz *.web.cariera.biz *.webdisk.cariera.biz *.whm.cariera.biz *.www.cariera.biz
*.1a3b816e-a95f-4521-a7f3-9b1bc57b641f.goldenprimer.org *.5ea8bc0c-52fa-4c20-b344-d784cc88ec25.goldenprimer.org *.admin.goldenprimer.org *.api.goldenprimer.org *.assets.goldenprimer.org goldenprimer.org *.goldenprimer.org *.test.goldenprimer.org *.www.goldenprimer.org
*.11.gs8.co *.14.gs8.co *.15.gs8.co *.5134.gs8.co *.78953.gs8.co *.dw.gs8.co gs8.co *.gs8.co *.hostmaster.gs8.co *.kf.gs8.co *.m.gs8.co *.mail.gs8.co *.nimdq.gs8.co *.www.gs8.co *.y.gs8.co *.z.gs8.co
*.gaqnazbjnvt.scheier.com *.hostmaster.scheier.com *.remote.scheier.com *.remote2.scheier.com scheier.com *.scheier.com *.ssl.scheier.com *.sslvpn.scheier.com *.sslvpn2.scheier.com *.vpn2.scheier.com *.vpn3.scheier.com *.ww1.scheier.com *.ww11.scheier.com *.ww16.scheier.com *.ww25.scheier.com *.ww38.scheier.com *.ww5.scheier.com
*.4623e8f0-65b1-4fcf-8bed-23c6946183b8.sidepor.us *.b0500f2f-90b0-41c5-a143-b70465510b86.sidepor.us *.d57b7267-672c-4f1d-8e0e-c7665dea1f73.sidepor.us *.emv1.sidepor.us *.mail.sidepor.us sidepor.us *.sidepor.us *.www.sidepor.us
*.sitemap.yyfx1565266.cc yyfx1565266.cc *.yyfx1565266.cc