Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=buckledown.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 21, 2026
Valid Until
July 20, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:A6:B2:6F:70:C0:52:A0:70:19:EF:45:3F:13:FF:91:24:39:C4:31:80:6E:38:AA:91:A9:01:C0:5C:17:43:E3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
thaihandbook.com
*.thaihandbook.com
29801.co
*.29801.co
360chatbot.com
*.360chatbot.com
balance.band
*.balance.band
bounty.so
*.bounty.so
buckledown.org
*.buckledown.org
cheap-cars-in-installments-no-down-payment-search-fr.sbs
*.cheap-cars-in-installments-no-down-payment-search-fr.sbs
climatology.io
*.climatology.io
clock.finance
*.clock.finance
cloud-storage-sservice-vo.click
*.cloud-storage-sservice-vo.click
coches-segunda-mano.sbs
*.coches-segunda-mano.sbs
cochesfinanciadossinentrada.sbs
*.cochesfinanciadossinentrada.sbs
coffee-machine-pl1.today
*.coffee-machine-pl1.today
coffeeaxis.com
*.coffeeaxis.com
cwmstaging.info
*.cwmstaging.info
cybawi.pro
*.cybawi.pro
danceteaching.com
*.danceteaching.com
designbuildpa.com
*.designbuildpa.com
dizipal1022.info
*.dizipal1022.info
dizipal1023.info
*.dizipal1023.info
doudou-badyba.fr
*.doudou-badyba.fr
echostride.com
*.echostride.com
electrician-services-1503.click
*.electrician-services-1503.click
elphenomena.com
*.elphenomena.com
fernagency.com
*.fernagency.com
firearmsacademytexas.com
*.firearmsacademytexas.com
flourishgardeners.xyz
*.flourishgardeners.xyz
gdwlp.work
*.gdwlp.work
grouphealthselect.com
*.grouphealthselect.com
gubetlics.com
*.gubetlics.com
indianplan.com
*.indianplan.com
joycegrace.studio
*.joycegrace.studio
quadrantcreative.com
*.quadrantcreative.com
razgledi.net
*.razgledi.net
roam.scot
*.roam.scot
sanb.org
*.sanb.org
sbsf.shop
*.sbsf.shop
seguir.net
*.seguir.net
sergipe.bet
*.sergipe.bet
sjcm.org
*.sjcm.org
skayon.sale
*.skayon.sale
solarbiblebus.com
*.solarbiblebus.com
st-wealth.cc
*.st-wealth.cc
teleporrt.com
*.teleporrt.com
xrayhomeinspection.com
*.xrayhomeinspection.com
Other domains in certificate