Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=travelquote.com.au
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 28, 2025
Valid Until
March 28, 2026
41 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:19:D2:0B:2E:94:AE:07:4C:EE:97:F9:66:FD:C4:F5:9B:57:47:A1:CD:44:77:7A:95:6D:FF:7F:03:9B:E8:F1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
87 domains
timecapsule.com.au
*.timecapsule.com.au
biuuu.lol
*.biuuu.lol
carperformanceparts.com.au
*.carperformanceparts.com.au
*.cartoon.cetaking.com
cetaking.com
*.cetaking.com
*.cpcalendars.cetaking.com
*.mail.cetaking.com
*.minimalist.cetaking.com
*.premium.cetaking.com
*.rusty.cetaking.com
*.songket.cetaking.com
chezsugaya-french.com
*.chezsugaya-french.com
disneyalnd.com
*.disneyalnd.com
*.anamdrub.ecia.com
*.apb.ecia.com
ecia.com
*.ecia.com
*.paularobizdj.ecia.com
*.publicidade.ecia.com
ecomeninas.com
*.ecomeninas.com
elsazonmexicanfood.com
*.elsazonmexicanfood.com
executiverecruiters.au
*.executiverecruiters.au
fui.com.au
*.fui.com.au
*.hostmaster.fui.com.au
handrolledscarves.com
*.handrolledscarves.com
idahodepartmentoflabor.com
*.idahodepartmentoflabor.com
jiancaiku.com
*.jiancaiku.com
*.superset.jiancaiku.com
*.hajim2.kony.store
*.hostmaster.kony.store
*.kik.kony.store
kony.store
*.kony.store
*.www.kony.store
ktj.au
*.ktj.au
luxuryspa.com.au
*.luxuryspa.com.au
miqcengineerings.com
*.miqcengineerings.com
*.hostmaster.myhaw.de
myhaw.de
*.myhaw.de
*.www.myhaw.de
*.blog.perduowl.com
perduowl.com
*.perduowl.com
*.jogos.pula.bet
*.menu.pula.bet
pula.bet
*.pula.bet
putlocker.es
*.putlocker.es
*.autodiscover.setiaku.click
*.cpanel.setiaku.click
*.cpcalendars.setiaku.click
*.cpcontacts.setiaku.click
*.mail.setiaku.click
setiaku.click
*.setiaku.click
*.sitemaps.setiaku.click
*.webdisk.setiaku.click
*.webmail.setiaku.click
*.wwwcpanel.setiaku.click
slit.com.au
*.slit.com.au
thefoodpantry.net
*.thefoodpantry.net
travelquote.com.au
*.travelquote.com.au
wwwrealtracs.com
*.wwwrealtracs.com
zearn.cm
*.zearn.cm
Other domains in certificate