Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tradefist.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 19, 2026
Valid Until
August 17, 2026
75 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:D3:94:49:EB:68:CF:34:24:0C:24:87:1F:D5:EF:FE:96:23:B4:36:B7:04:09:8E:F8:D9:DE:4D:DB:55:B5:74
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
tradefist.com
*.tradefist.com
*.63e20ba6-cc86-4fc0-99a7-0927dce02a7a.tradefist.com
*.6f207ed1-5ae7-4bcc-a230-983b490ee39c.tradefist.com
*.api.tradefist.com
*.app.tradefist.com
*.assets.tradefist.com
*.autoconfig.tradefist.com
*.autodiscover.tradefist.com
*.back.tradefist.com
*.cloud.tradefist.com
*.cpanel.tradefist.com
*.dashboard.tradefist.com
*.ftp.tradefist.com
*.mail.tradefist.com
*.members.tradefist.com
*.rd.tradefist.com
*.rds.tradefist.com
*.rdweb.tradefist.com
*.remote.tradefist.com
*.test.tradefist.com
*.uhhzw6.tradefist.com
*.user.tradefist.com
*.webdisk.tradefist.com
*.3755a9bc-d752-40d7-a23b-fca4624d2b8a.aeple.com
*.aaspot.aeple.com
*.access.aeple.com
*.admin.aeple.com
*.aees.aeple.com
aeple.com
*.aeple.com
*.aeps.aeple.com
*.aijiiwrzokconnect.aeple.com
*.api.aeple.com
*.apps.aeple.com
*.auwww.aeple.com
*.board.aeple.com
*.cdbu.aeple.com
*.checkooerage.aeple.com
*.cloud.aeple.com
*.connect.aeple.com
*.corp.aeple.com
*.d.aeple.com
*.demo.aeple.com
*.dev.aeple.com
*.ess.aeple.com
*.external.aeple.com
*.f3e84678-36b4-4c9c-82c8-8cd4620d57ca.aeple.com
*.fdkxmrdweb.aeple.com
*.gateway.aeple.com
*.google.aeple.com
*.gp.aeple.com
*.gsxapp.aeple.com
*.ht.aeple.com
*.icloud.aeple.com
*.iforgot.aeple.com
*.intranet.aeple.com
*.itunes.aeple.com
*.ls.aeple.com
*.m.aeple.com
*.mail.aeple.com
*.members.aeple.com
*.online.aeple.com
*.podcasts.aeple.com
*.portal.aeple.com
*.rd.aeple.com
*.rdweb.aeple.com
*.remote.aeple.com
*.sslvpn.aeple.com
*.suppert.aeple.com
*.testflicht.aeple.com
*.testflight.aeple.com
*.ts.aeple.com
*.ugwwei.aeple.com
*.virtualapps.aeple.com
*.vpn.aeple.com
*.vpn1.aeple.com
*.ww1.aeple.com
*.ww12.aeple.com
*.www.aeple.com
*.edad5cfe-e616-4372-a0ac-975162de5c86.mashed.in
*.fae98b42-039b-4d77-982b-615068bc88dc.mashed.in
*.glass.mashed.in
*.hostmaster.mashed.in
*.in.mashed.in
mashed.in
*.mashed.in
*.mta-sts.mashed.in
*.primary.mashed.in
*.www.mashed.in
Other domains in certificate