Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=mirrorme.store
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 05, 2026
Valid Until
September 03, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:C5:6E:87:39:AD:B7:4B:E8:7D:33:B0:AA:BD:59:9A:C5:30:0E:2B:9A:33:F8:36:B9:25:91:B5:97:5F:2D:C7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
slotmacau288.com
*.slotmacau288.com
emissaoservicos.sbs
*.emissaoservicos.sbs
expertgardenthinkers.xyz
*.expertgardenthinkers.xyz
exteriorpaintersorlando.com
*.exteriorpaintersorlando.com
filmai98.top
*.filmai98.top
fishball.pro
*.fishball.pro
flightduttpack.com
*.flightduttpack.com
gengtoto88.vip
*.gengtoto88.vip
hairoiladivasi.shop
*.hairoiladivasi.shop
halte4d-news.xyz
*.halte4d-news.xyz
hireflynet.com
*.hireflynet.com
hivecrate.shop
*.hivecrate.shop
honorgardens.qpon
*.honorgardens.qpon
i6lj09cg.xyz
*.i6lj09cg.xyz
integrityfitsolutions.club
*.integrityfitsolutions.club
jav89.xyz
*.jav89.xyz
jeansview.com
*.jeansview.com
jrpm.org
*.jrpm.org
kommunalwirtschaft.com
*.kommunalwirtschaft.com
krf5y.com
*.krf5y.com
kw-5-yes.vip
*.kw-5-yes.vip
lasiol.com
*.lasiol.com
letrix.co
*.letrix.co
lratxzflse.xyz
*.lratxzflse.xyz
mirrorme.store
*.mirrorme.store
mltalenstrategies.co
*.mltalenstrategies.co
mm660.xyz
*.mm660.xyz
moonoxmeme.xyz
*.moonoxmeme.xyz
mylifeai.tech
*.mylifeai.tech
naijacng.com
*.naijacng.com
notesofhearts.com
*.notesofhearts.com
nulvon.town
*.nulvon.town
opthire.com
*.opthire.com
outfitgram.com
*.outfitgram.com
pelunari.com
*.pelunari.com
pixeriqahiex.org
*.pixeriqahiex.org
pobup.com
*.pobup.com
pool-caddie.com
*.pool-caddie.com
powershotg7xstore.info
*.powershotg7xstore.info
shopyardnest.com
*.shopyardnest.com
siemens251.com
*.siemens251.com
sklmy.qpon
*.sklmy.qpon
smtp.in
*.smtp.in
soraaoi.xyz
*.soraaoi.xyz
stst.store
*.stst.store
Other domains in certificate