76/100 SECURITY SCORE

Certificate Information

Subject
CN=mywasiyat.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 04, 2026
Valid Until
September 02, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
19:EF:52:67:59:F2:F2:12:9B:A7:1F:EF:0B:75:4F:1D:87:99:0F:F0:DE:9F:54:C0:47:90:B8:8E:FB:54:E2:60
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
thunderscore668.shop *.thunderscore668.shop

Other domains in certificate

grayfalkontech.com *.grayfalkontech.com
hansviewglobal.com *.hansviewglobal.com
hbfrrtddc2.xyz *.hbfrrtddc2.xyz
mywasiyat.com *.mywasiyat.com
newyorkpilots.com *.newyorkpilots.com
niloticoafricasafaris.com *.niloticoafricasafaris.com
northhollywoodlocksmith.com *.northhollywoodlocksmith.com
ojfqk.my *.ojfqk.my
oldsixbieyongxiazaikejisix27.xyz *.oldsixbieyongxiazaikejisix27.xyz
optarixtrader.co *.optarixtrader.co
oyxdg.loan *.oyxdg.loan
packingjob-dorosh-ae-1.click *.packingjob-dorosh-ae-1.click
paula.one *.paula.one
playonlinegamblingforrealmoney.online *.playonlinegamblingforrealmoney.online
pre440.info *.pre440.info
procecocloud.com *.procecocloud.com
programmablestablecoin.com *.programmablestablecoin.com
pzkebz.club *.pzkebz.club
rawstitch.info *.rawstitch.info
recoolsolutions.com *.recoolsolutions.com
replycleverrealty.com *.replycleverrealty.com
rhatn.shop *.rhatn.shop
rna-synthesis-444767843.click *.rna-synthesis-444767843.click
robertrandolphtour2025.com *.robertrandolphtour2025.com
roofingcompanyreno.com *.roofingcompanyreno.com
ruyga.work *.ruyga.work
saleslistwithclever.com *.saleslistwithclever.com
sanqingsiyu.com *.sanqingsiyu.com
sarsgovsa.com *.sarsgovsa.com
schonskateboard.com *.schonskateboard.com
sebo91.cc *.sebo91.cc
selluminarspace.online *.selluminarspace.online
shengcargoxpress.com *.shengcargoxpress.com
sivarmania.com *.sivarmania.com
slotsparadise.xyz *.slotsparadise.xyz
slotsuniverse.xyz *.slotsuniverse.xyz
snbow.my *.snbow.my
sportbold.com *.sportbold.com
sportsurgetvs.online *.sportsurgetvs.online
startcleverrealestate.com *.startcleverrealestate.com
storytelling.click *.storytelling.click
t8l.cc *.t8l.cc
tagesgeld-verifikation.com *.tagesgeld-verifikation.com
texlo.org *.texlo.org