Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=sundararajan.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F6:55:25:0D:47:0A:CC:54:FB:5E:EF:6D:81:B3:D0:76:72:01:57:4F:C8:29:27:84:96:54:76:49:CA:17:D6:0B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
thekai.com
*.thekai.com
aloro.com
*.aloro.com
*.ww16.aloro.com
*.ww38.aloro.com
annabelleshakesheave.net
*.annabelleshakesheave.net
buyic.com
*.buyic.com
*.owa.buyic.com
casagirasol.com
*.casagirasol.com
*.m.casagirasol.com
unionsheng.com.sg
*.unionsheng.com.sg
cp-managment.com
*.cp-managment.com
*.portal.cp-managment.com
dizustu.com
*.dizustu.com
*.ww16.dizustu.com
*.ww17.dizustu.com
*.ww25.dizustu.com
*.akshay.godaddsites.com
*.amalalmamlka.godaddsites.com
*.canisdogayihayvanlarikorumavey.godaddsites.com
*.com.godaddsites.com
*.com1.godaddsites.com
*.eastwardfamilyfuncenter.godaddsites.com
*.freeonlineschool.godaddsites.com
godaddsites.com
*.godaddsites.com
*.heartandjoycprtraining.godaddsites.com
*.mamissoaps46.godaddsites.com
*.okdireportcom.godaddsites.com
*.psychopathfund.godaddsites.com
*.pup4us.godaddsites.com
*.rkcomputer.godaddsites.com
*.saudemental2.godaddsites.com
*.servicioscoorporativossn.godaddsites.com
*.sopawsome.godaddsites.com
*.sunstateestatesales.godaddsites.com
*.wandpleasure.godaddsites.com
*.wishingwelldesigns.godaddsites.com
*.ww25.godaddsites.com
iglesiaapostolica.com
*.iglesiaapostolica.com
*.ww16.iglesiaapostolica.com
orjg.com
*.orjg.com
*.osta.orjg.com
passiondiyprojectshub.live
*.passiondiyprojectshub.live
rowlandboys.com
*.rowlandboys.com
sdkmysqldx.xyz
*.sdkmysqldx.xyz
sundararajan.com
*.sundararajan.com
superkingbed.com
*.superkingbed.com
thesifter.com
*.thesifter.com
trippiehippie.com
*.trippiehippie.com
vidaylibertad.com
*.vidaylibertad.com
weddingslovecelebration.beauty
*.weddingslovecelebration.beauty
xy25.app
*.xy25.app
*.hotel.youngblade.com
*.mobile.youngblade.com
youngblade.com
*.youngblade.com
youtien.com
*.youtien.com
yr3bw057.xyz
*.yr3bw057.xyz
yuvarlak.com
*.yuvarlak.com
yyzzk.net
*.yyzzk.net
zipgologistics.online
*.zipgologistics.online
zole.net
*.zole.net
zuillo.com
*.zuillo.com
Other domains in certificate