Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=charmancy.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 28, 2026
Valid Until
August 26, 2026
64 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
54:D9:1E:94:EF:7C:64:96:EE:03:E9:38:1F:E2:6C:44:A1:2C:0D:82:8D:5D:F8:B6:3B:11:1D:D6:A3:6A:F6:91
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
sunfish.group
*.sunfish.group
charmancy.com
*.charmancy.com
clicktograb.online
*.clicktograb.online
coursecreek.org
*.coursecreek.org
cvigent.com
*.cvigent.com
d2c03a63e82cf0ba.com
*.d2c03a63e82cf0ba.com
destinationcentralcoast.com.au
*.destinationcentralcoast.com.au
digimartshop.online
*.digimartshop.online
doppelgangerbeardco.com
*.doppelgangerbeardco.com
dosomailhvc.trade
*.dosomailhvc.trade
dosomailhvz.vip
*.dosomailhvz.vip
dosomailovg.win
*.dosomailovg.win
educating.io
*.educating.io
elmavitrin5.monster
*.elmavitrin5.monster
emilyywang.com
*.emilyywang.com
enginetrading.com
*.enginetrading.com
metex.live
*.metex.live
metricsrevgen.com
*.metricsrevgen.com
mjjgg.com
*.mjjgg.com
morocco-vacation-packages-uk.sbs
*.morocco-vacation-packages-uk.sbs
mortgage-agency.info
*.mortgage-agency.info
mortgage-loan-agency.click
*.mortgage-loan-agency.click
motionprotecttechnology.com
*.motionprotecttechnology.com
mountmytv.co
*.mountmytv.co
smartsavercart.online
*.smartsavercart.online
smithwill.com
*.smithwill.com
systemkitto.com
*.systemkitto.com
taishengkh.com
*.taishengkh.com
thegrowing-team.com
*.thegrowing-team.com
thegrowinglabs.com
*.thegrowinglabs.com
thegrowth-team.com
*.thegrowth-team.com
thelawofficesofdanielfjimenez.cyou
*.thelawofficesofdanielfjimenez.cyou
theprimeamz-team.com
*.theprimeamz-team.com
theprimeamz.com
*.theprimeamz.com
theprimeamzapp.com
*.theprimeamzapp.com
therenaissanceadvisors-team.com
*.therenaissanceadvisors-team.com
therenaissanceadvisorscrew.com
*.therenaissanceadvisorscrew.com
therenaissanceadvisorshq.com
*.therenaissanceadvisorshq.com
therenaissanceadvisorslabs.com
*.therenaissanceadvisorslabs.com
therenaissanceadvisorsteam.com
*.therenaissanceadvisorsteam.com
therenaissancehq.com
*.therenaissancehq.com
thestrategichq.com
*.thestrategichq.com
thestrategyapp.com
*.thestrategyapp.com
thiscreativelife.org
*.thiscreativelife.org
thunderexplorer864.info
*.thunderexplorer864.info
Other domains in certificate