Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=thirstythursday.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 13, 2026
Valid Until
May 14, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F0:DF:99:A4:11:68:AD:9E:B9:BD:7C:48:DC:66:73:C6:B8:16:F6:88:60:C2:72:C1:84:04:23:1C:85:34:97:DF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
thirstythursday.com *.thirstythursday.com

Other domains in certificate

blucas.com *.blucas.com
*.adguard.boldvekra.com boldvekra.com *.boldvekra.com *.shop.boldvekra.com
*.api.catholiccreditcard.com catholiccreditcard.com *.catholiccreditcard.com *.dev.catholiccreditcard.com *.forum.catholiccreditcard.com *.hostmaster.catholiccreditcard.com *.mail.catholiccreditcard.com *.sitemaps.catholiccreditcard.com *.test.catholiccreditcard.com *.ww1.catholiccreditcard.com *.ww16.catholiccreditcard.com *.ww25.catholiccreditcard.com *.www.catholiccreditcard.com
*.api.cotedenacre.com *.app.cotedenacre.com cotedenacre.com *.cotedenacre.com *.crm.cotedenacre.com *.emv1.cotedenacre.com *.getsimnum.cotedenacre.com *.m.cotedenacre.com *.mail.cotedenacre.com *.mijn.cotedenacre.com *.sitemap.cotedenacre.com *.sitemaps.cotedenacre.com *.sqs.cotedenacre.com *.stage.cotedenacre.com *.www3.cotedenacre.com
dateorditch.com *.dateorditch.com *.ww25.dateorditch.com
freshdeak.com *.freshdeak.com
*.cg4o5.fwor3fisofhwolijwrne.xyz *.dwij7.fwor3fisofhwolijwrne.xyz fwor3fisofhwolijwrne.xyz *.fwor3fisofhwolijwrne.xyz
khouhytansldockv.com *.khouhytansldockv.com
*.d90eda8c-9837-4b12-984c-f8d187c59a8d.klikdunia777.xyz klikdunia777.xyz *.klikdunia777.xyz
*.demo.lampadesolari.it lampadesolari.it *.lampadesolari.it
mycarlocal.com *.mycarlocal.com *.ww25.mycarlocal.com
ntemba24.com *.ntemba24.com *.webmail.ntemba24.com *.ww25.ntemba24.com
*.hostmaster.olympuscameras.com *.mail.olympuscameras.com olympuscameras.com *.olympuscameras.com *.poc.olympuscameras.com *.ww25.olympuscameras.com
*.alexisfamichen.qmlvh8.club *.api.qmlvh8.club *.app.qmlvh8.club *.azurmichen.qmlvh8.club *.blackbemichen.qmlvh8.club *.cmichen.qmlvh8.club *.comichen.qmlvh8.club *.dev.qmlvh8.club *.incubamichen.qmlvh8.club *.lizardsomichen.qmlvh8.club *.michen.qmlvh8.club *.news.qmlvh8.club qmlvh8.club *.qmlvh8.club *.wap.qmlvh8.club *.web.qmlvh8.club *.wildcard.qmlvh8.club
renounion.com.au *.renounion.com.au
scholarships911.org *.scholarships911.org
supplymanagement.com.au *.supplymanagement.com.au