Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=lumumbazapataucsd.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 22, 2026
Valid Until
April 22, 2026 55 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1F:07:B2:9E:CD:A5:E9:1E:14:42:4C:90:5C:99:AB:57:F6:2D:DB:73:79:36:BA:52:D3:2E:F7:AC:0C:8F:55:AB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
theknott.co *.theknott.co

Other domains in certificate

acaixaprotege-cgd.com *.acaixaprotege-cgd.com
bigtittycreampie.com *.bigtittycreampie.com *.hostmaster.bigtittycreampie.com
dencortech.com *.dencortech.com *.panshi.dencortech.com
dog-obedience-training298253.icu *.dog-obedience-training298253.icu
domesticgeneratorsonline173703.icu *.domesticgeneratorsonline173703.icu
ev-ottobrunn.de *.ev-ottobrunn.de
gptshop.xyz *.gptshop.xyz *.ww25.gptshop.xyz
hdb-hamburg.de *.hdb-hamburg.de
iburst.com.au *.iburst.com.au
jastastic.click *.jastastic.click
jumboelectronics.store *.jumboelectronics.store *.ns3.jumboelectronics.store
justlawnmowing.biz *.justlawnmowing.biz
*.ci.littlebooklane.com littlebooklane.com *.littlebooklane.com *.ww25.littlebooklane.com
lumumbazapataucsd.com *.lumumbazapataucsd.com *.random.lumumbazapataucsd.com *.ww25.lumumbazapataucsd.com
mugen.club *.mugen.club *.postmaster.mugen.club *.staging.mugen.club
ngocrongtaydu.me *.ngocrongtaydu.me
ofallonmo.us *.ofallonmo.us
onefinace.com *.onefinace.com *.share.onefinace.com
*.mail.pdsbcareer.online pdsbcareer.online *.pdsbcareer.online
*.admin.rajabuayabos.com rajabuayabos.com *.rajabuayabos.com
*.ebmail.rizzgpt.online rizzgpt.online *.rizzgpt.online *.webmail.rizzgpt.online *.ww25.rizzgpt.online *.ww38.rizzgpt.online
*.developer.serviceow.com *.hostmaster.serviceow.com serviceow.com *.serviceow.com *.ww25.serviceow.com
*.admin.startdisk.com *.random.startdisk.com startdisk.com *.startdisk.com *.ww17.startdisk.com
*.m.suspaparts.co suspaparts.co *.suspaparts.co
thecinemanews.online *.thecinemanews.online
*.admin.toto188-rtpgacor7vy.click toto188-rtpgacor7vy.click *.toto188-rtpgacor7vy.click
traenensaecke.de *.traenensaecke.de
*.admin.uewlihasq.com *.mx.uewlihasq.com uewlihasq.com *.uewlihasq.com
whynotride.co *.whynotride.co
wicket.bet *.wicket.bet