Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=kiwiorealeymeas.com.de
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 02, 2026
Valid Until
July 31, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8F:B1:45:82:A7:24:A5:84:2C:4E:E9:9A:7E:45:90:71:92:5B:AB:02:3F:ED:82:42:1E:4E:15:CA:2E:92:2F:8A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
thelight.lol
*.thelight.lol
1win-bookmaker.sbs
*.1win-bookmaker.sbs
353913.lgbt
*.353913.lgbt
*.lgbt.353913.lgbt
50xknx.top
*.50xknx.top
764193.vip
*.764193.vip
99878.click
*.99878.click
a259fhxy.top
*.a259fhxy.top
*.abc.a259fhxy.top
*.ab1a6668-54e0-4bc2-80f8-83239a66c5cd.canadavisit.org
canadavisit.org
*.canadavisit.org
*.m.canadavisit.org
*.www.canadavisit.org
depression-online-self-test-6l.sbs
*.depression-online-self-test-6l.sbs
detect-a-dose.com
*.detect-a-dose.com
gaotgc.co
*.gaotgc.co
*.admin.genpack123.my
genpack123.my
*.genpack123.my
*.m.genpack123.my
great-bingodice.xyz
*.great-bingodice.xyz
great-bluffcash.xyz
*.great-bluffcash.xyz
hijau555-1.xyz
*.hijau555-1.xyz
iiqbwj.co
*.iiqbwj.co
kerj5uid.top
*.kerj5uid.top
kiwiorealeymeas.com.de
*.kiwiorealeymeas.com.de
kumbuka.co
*.kumbuka.co
lida.pro
*.lida.pro
*.www1.lida.pro
linkite.com
*.linkite.com
lucky-rollace.xyz
*.lucky-rollace.xyz
lucky-rolldice.xyz
*.lucky-rolldice.xyz
lucky-vegasdealer.xyz
*.lucky-vegasdealer.xyz
ma77.cfd
*.ma77.cfd
*.wakkl.ma77.cfd
*.com.mazzakooffer.com
mazzakooffer.com
*.mazzakooffer.com
seamstress-jobs-678439.sbs
*.seamstress-jobs-678439.sbs
small-business-loans-1.sbs
*.small-business-loans-1.sbs
tempate.com
*.tempate.com
*.0e171164-df51-4947-a306-81135d37d84d.tether.meme
*.1454c5b0-68ed-4d5b-82a7-475cfd56141d.tether.meme
*.admin.tether.meme
*.app.tether.meme
*.bot.tether.meme
*.dev.tether.meme
*.dflqcyjo.tether.meme
*.external.tether.meme
*.intranet.tether.meme
*.mail.tether.meme
*.members.tether.meme
*.my.tether.meme
*.public.tether.meme
*.qowvipublic.tether.meme
*.share.tether.meme
*.sharepoint.tether.meme
*.staging.tether.meme
tether.meme
*.tether.meme
*.www.tether.meme
tfee18.com
*.tfee18.com
Other domains in certificate