Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=14771.one
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 29, 2026
Valid Until
July 28, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1F:2F:56:FF:C7:4F:4E:93:56:2A:E9:10:11:70:89:CD:C0:D7:FB:33:A4:33:7A:4E:A3:BB:01:E9:D7:35:06:AF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
ticketpoint.co *.ticketpoint.co *.mx.ticketpoint.co *.www.ticketpoint.co

Other domains in certificate

14771.one *.14771.one
16545.mobi *.16545.mobi
30329610.top *.30329610.top
64986.my *.64986.my
75517.my *.75517.my
actiinsurance.com *.actiinsurance.com
appliga.com *.appliga.com
arwardco.com *.arwardco.com
awesome-pixelspace.quest *.awesome-pixelspace.quest
*.autodiscover.brandontate.com brandontate.com *.brandontate.com *.cpcalendars.brandontate.com *.cpcontacts.brandontate.com *.mail.brandontate.com *.mta-sts.brandontate.com *.vpn.brandontate.com *.webdisk.brandontate.com *.wwww.brandontate.com
camsmt.com *.camsmt.com
cnmplay.xyz *.cnmplay.xyz
dumfather.com *.dumfather.com
eallywasnothy.com *.eallywasnothy.com *.random.eallywasnothy.com *.ww25.eallywasnothy.com *.ww38.eallywasnothy.com
exprelty.com *.exprelty.com
ing-aktiv.net *.ing-aktiv.net
*.7o6tkp.intelligenttrading.online *.citrix.intelligenttrading.online *.demo.intelligenttrading.online intelligenttrading.online *.intelligenttrading.online
laurawingsofstyle.com *.laurawingsofstyle.com
*.comyukbx.lhodkiewicz.com lhodkiewicz.com *.lhodkiewicz.com *.xyzhfiek.lhodkiewicz.com
lipagest.com *.lipagest.com
mushroomplant.com *.mushroomplant.com
novazone346.top *.novazone346.top
oxfordkitchen.com *.oxfordkitchen.com
pcqgl.auction *.pcqgl.auction
photobox.digital *.photobox.digital
pvk8kw.cyou *.pvk8kw.cyou
*.m.reminda.com.cn reminda.com.cn *.reminda.com.cn *.smtp.reminda.com.cn
rup75.icu *.rup75.icu
selokian.org *.selokian.org
toginol.com *.toginol.com
valeyhealth.com *.valeyhealth.com
wwgdlp.cyou *.wwgdlp.cyou
yanxinanty.com *.yanxinanty.com