76/100 SECURITY SCORE

Certificate Information

Subject
CN=getahair.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
86:F1:B2:1C:AD:B3:CD:8C:39:B2:31:AF:5D:B2:A6:4E:64:BA:25:C9:9D:8D:5E:C9:16:A8:55:43:33:0B:71:95
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
grapefruitog.com *.grapefruitog.com *.42d99063-89a5-4090-8246-72978e6c95fa.grapefruitog.com *.4317a15e-1fae-4918-a8f7-715aa4450b17.grapefruitog.com *.a.grapefruitog.com *.api.grapefruitog.com *.app.grapefruitog.com *.brueca.grapefruitog.com *.testing.grapefruitog.com

Other domains in certificate

*.1my5v.972m.com *.1rqbb.972m.com *.3979194652.972m.com *.4556160422.972m.com *.4x0f3.972m.com *.5349546194.972m.com *.5r4zp.972m.com *.6495609320.972m.com *.6895093447.972m.com *.7lkyd.972m.com *.7p5o5.972m.com 972m.com *.972m.com *.b9f7j.972m.com *.cqq3g.972m.com *.dcyq4.972m.com *.f94yz.972m.com *.fiq1r.972m.com *.fomn9.972m.com *.gp6io.972m.com *.jtgy5.972m.com *.k1jjw.972m.com *.ljc7k.972m.com *.mk538.972m.com *.p2v31.972m.com *.q9bce.972m.com *.qqfzt.972m.com *.qrxaq.972m.com *.rhuig.972m.com *.s0jjg.972m.com *.vvdwd.972m.com *.www.972m.com *.wxplj.972m.com *.xuxs5.972m.com *.y828w.972m.com
*.api.attitude.boutique attitude.boutique *.attitude.boutique
clubtaylorrain.com *.clubtaylorrain.com *.join.clubtaylorrain.com *.v3.clubtaylorrain.com *.ww25.clubtaylorrain.com *.www.clubtaylorrain.com
*.cpanel.getahair.com *.ftp.getahair.com getahair.com *.getahair.com
*.admin.popuptimersupplier.com *.api.popuptimersupplier.com *.app.popuptimersupplier.com *.assets.popuptimersupplier.com *.dashboard.popuptimersupplier.com *.demo.popuptimersupplier.com *.dev.popuptimersupplier.com *.hostmaster.popuptimersupplier.com *.mail.popuptimersupplier.com *.mailer.popuptimersupplier.com *.marketing.popuptimersupplier.com popuptimersupplier.com *.popuptimersupplier.com *.qa.popuptimersupplier.com *.secure.popuptimersupplier.com *.stg.popuptimersupplier.com *.test.popuptimersupplier.com *.uat.popuptimersupplier.com *.v1.popuptimersupplier.com *.v2.popuptimersupplier.com *.web.popuptimersupplier.com
pro-hormones.co *.pro-hormones.co
pyatprocentov.online *.pyatprocentov.online
qingerhealth.com *.qingerhealth.com *.wap.qingerhealth.com
sovoc.icu *.sovoc.icu
*.familyfund.travelinspire.co.uk travelinspire.co.uk *.travelinspire.co.uk