Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=man169.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 21, 2025
Valid Until
March 21, 2026
41 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:02:1B:4A:C4:07:6F:11:71:94:08:32:D1:D9:9E:44:48:B0:DB:F9:55:25:28:31:AF:1D:36:29:30:F5:54:18
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
tarefa.info
*.tarefa.info
abuser.org
*.abuser.org
*.ranger.abuser.org
*.19.ao2.info
*.1a.ao2.info
ao2.info
*.ao2.info
*.ww38.ao2.info
*.0acef673-00c9-4b42-8292-725cf35cc11a.bheib.xyz
bheib.xyz
*.bheib.xyz
*.ww25.bheib.xyz
bibliaccb.co
*.bibliaccb.co
*.ww25.bibliaccb.co
blazedclothing.click
*.blazedclothing.click
*.admin.cherokee12.net
cherokee12.net
*.cherokee12.net
*.cvhs.cherokee12.net
*.johnstones.cherokee12.net
*.knox.cherokee12.net
*.libertyes.cherokee12.net
*.mail.cherokee12.net
*.rmmes.cherokee12.net
*.sixes.cherokee12.net
*.ww38.cherokee12.net
contenteddealstoday.click
*.contenteddealstoday.click
cutlerybargains.click
*.cutlerybargains.click
*.cpcontacts.dgbmining.com
dgbmining.com
*.dgbmining.com
*.server1.dgbmining.com
inquisitivebargains.click
*.inquisitivebargains.click
inquisitivegirl.click
*.inquisitivegirl.click
*.forum.man169.com
*.m.man169.com
man169.com
*.man169.com
*.ww25.man169.com
nbalive.net
*.nbalive.net
*.ww25.nbalive.net
*.ww38.nbalive.net
oakwoodfurniture.com
*.oakwoodfurniture.com
*.random.oakwoodfurniture.com
preachdeal.click
*.preachdeal.click
prescottactionshooters.org
*.prescottactionshooters.org
rippleoffers.click
*.rippleoffers.click
rostral.com
*.rostral.com
*.ww25.rostral.com
sck56mkp.cc
*.sck56mkp.cc
*.ww25.sck56mkp.cc
seed-germination.xyz
*.seed-germination.xyz
*.api.servicecu.online
*.app.servicecu.online
*.d2hhei9vjk5s73ep9b1g.servicecu.online
*.login.servicecu.online
servicecu.online
*.servicecu.online
*.staging.servicecu.online
*.web.servicecu.online
*.weblog.servicecu.online
sipsclothing.click
*.sipsclothing.click
solidbargains.click
*.solidbargains.click
steamsat.us
*.steamsat.us
windfallbargains.click
*.windfallbargains.click
windfallconstruction.click
*.windfallconstruction.click
yyakilith.info
*.yyakilith.info
Other domains in certificate