Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=huwf5g.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
54:42:33:29:05:83:C8:65:8C:1C:97:C9:CE:22:36:4A:71:11:21:25:99:D3:0C:D6:4D:71:F0:45:76:E0:03:8E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
afrigroup.com
*.afrigroup.com
*.sitemaps.afrigroup.com
01.gd
*.01.gd
*.49.01.gd
*.bms-01.01.gd
*.hoiarapi.01.gd
*.new.01.gd
*.work.01.gd
551.cam
*.551.cam
*.assets.551.cam
*.demo.551.cam
*.dev.551.cam
*.webmail.551.cam
*.www.551.cam
9r3.online
*.9r3.online
*.biolink.9r3.online
acessablecity.click
*.acessablecity.click
alshaikh.com
*.alshaikh.com
*.electro.alshaikh.com
*.smtp2.alshaikh.com
antonioduran.com
*.antonioduran.com
*.pay.antonioduran.com
fnw.com.pl
*.fnw.com.pl
daddylive.net
*.daddylive.net
doctruyen3qv.pro
*.doctruyen3qv.pro
familysearach.org
*.familysearach.org
*.random.familysearach.org
girasoli.com
*.girasoli.com
*.hostmaster.girasoli.com
*.ww25.girasoli.com
golang-challenge.com
*.golang-challenge.com
huwf5g.com
*.huwf5g.com
*.www.huwf5g.com
infinitapanaderia.com
*.infinitapanaderia.com
japantengsu.store
*.japantengsu.store
lifeinsuranceratess.com
*.lifeinsuranceratess.com
magazinepla.net
*.magazinepla.net
*.random.magazinepla.net
marushka.live
*.marushka.live
michaelliou.io
*.michaelliou.io
*.m.ouidadthecurlexperts.com
ouidadthecurlexperts.com
*.ouidadthecurlexperts.com
recuento.com
*.recuento.com
*.ww16.recuento.com
rentmycarpark.online
*.rentmycarpark.online
search-spd.com
*.search-spd.com
*.ww25.search-spd.com
*.payments.shinescan.site
shinescan.site
*.shinescan.site
steaknshakevist.com
*.steaknshakevist.com
thepap.com
*.thepap.com
*.assets.truongdaylaixe.com
truongdaylaixe.com
*.truongdaylaixe.com
*.access.villasana.com
*.ravpn.villasana.com
villasana.com
*.villasana.com
webbdesign.co
*.webbdesign.co
*.backup.wonderway.info
wonderway.info
*.wonderway.info
Other domains in certificate