Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=getahair.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026
69 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
86:F1:B2:1C:AD:B3:CD:8C:39:B2:31:AF:5D:B2:A6:4E:64:BA:25:C9:9D:8D:5E:C9:16:A8:55:43:33:0B:71:95
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
grapefruitog.com
*.grapefruitog.com
*.42d99063-89a5-4090-8246-72978e6c95fa.grapefruitog.com
*.4317a15e-1fae-4918-a8f7-715aa4450b17.grapefruitog.com
*.a.grapefruitog.com
*.api.grapefruitog.com
*.app.grapefruitog.com
*.brueca.grapefruitog.com
*.testing.grapefruitog.com
*.1my5v.972m.com
*.1rqbb.972m.com
*.3979194652.972m.com
*.4556160422.972m.com
*.4x0f3.972m.com
*.5349546194.972m.com
*.5r4zp.972m.com
*.6495609320.972m.com
*.6895093447.972m.com
*.7lkyd.972m.com
*.7p5o5.972m.com
972m.com
*.972m.com
*.b9f7j.972m.com
*.cqq3g.972m.com
*.dcyq4.972m.com
*.f94yz.972m.com
*.fiq1r.972m.com
*.fomn9.972m.com
*.gp6io.972m.com
*.jtgy5.972m.com
*.k1jjw.972m.com
*.ljc7k.972m.com
*.mk538.972m.com
*.p2v31.972m.com
*.q9bce.972m.com
*.qqfzt.972m.com
*.qrxaq.972m.com
*.rhuig.972m.com
*.s0jjg.972m.com
*.vvdwd.972m.com
*.www.972m.com
*.wxplj.972m.com
*.xuxs5.972m.com
*.y828w.972m.com
*.api.attitude.boutique
attitude.boutique
*.attitude.boutique
clubtaylorrain.com
*.clubtaylorrain.com
*.join.clubtaylorrain.com
*.v3.clubtaylorrain.com
*.ww25.clubtaylorrain.com
*.www.clubtaylorrain.com
*.cpanel.getahair.com
*.ftp.getahair.com
getahair.com
*.getahair.com
*.admin.popuptimersupplier.com
*.api.popuptimersupplier.com
*.app.popuptimersupplier.com
*.assets.popuptimersupplier.com
*.dashboard.popuptimersupplier.com
*.demo.popuptimersupplier.com
*.dev.popuptimersupplier.com
*.hostmaster.popuptimersupplier.com
*.mail.popuptimersupplier.com
*.mailer.popuptimersupplier.com
*.marketing.popuptimersupplier.com
popuptimersupplier.com
*.popuptimersupplier.com
*.qa.popuptimersupplier.com
*.secure.popuptimersupplier.com
*.stg.popuptimersupplier.com
*.test.popuptimersupplier.com
*.uat.popuptimersupplier.com
*.v1.popuptimersupplier.com
*.v2.popuptimersupplier.com
*.web.popuptimersupplier.com
pro-hormones.co
*.pro-hormones.co
pyatprocentov.online
*.pyatprocentov.online
qingerhealth.com
*.qingerhealth.com
*.wap.qingerhealth.com
sovoc.icu
*.sovoc.icu
*.familyfund.travelinspire.co.uk
travelinspire.co.uk
*.travelinspire.co.uk
Other domains in certificate