Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=thetoned.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 01, 2026
Valid Until
July 30, 2026
76 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
28:68:89:DD:45:4B:7F:C1:DC:C2:09:C5:F3:82:1B:B1:4F:9D:5B:E3:D0:C2:DE:AB:2D:7C:CE:CC:EB:C6:1A:55
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
trortyzy.com
*.trortyzy.com
*.04b0f2f9-a9cd-45c2-8f0c-8015e3cb4eaa.trortyzy.com
*.06e13cec-d744-4a65-b8e3-545c2ccf4f9d.trortyzy.com
*.149f8924-cf02-43ab-b5d5-da315f955da8.trortyzy.com
*.a.trortyzy.com
*.admin.trortyzy.com
*.api.trortyzy.com
*.app.trortyzy.com
*.assets.trortyzy.com
*.auth.trortyzy.com
*.backoffice.trortyzy.com
*.backup.trortyzy.com
*.bjhwhassets.trortyzy.com
*.blog.trortyzy.com
*.cloud.trortyzy.com
*.dashboard.trortyzy.com
*.demo.trortyzy.com
*.dev.trortyzy.com
*.ead.trortyzy.com
*.mail.trortyzy.com
*.mailer.trortyzy.com
*.marketing.trortyzy.com
*.qa.trortyzy.com
*.rd.trortyzy.com
*.rds.trortyzy.com
*.rdweb.trortyzy.com
*.remote.trortyzy.com
*.secure.trortyzy.com
*.shop.trortyzy.com
*.staging.trortyzy.com
*.stg.trortyzy.com
*.test.trortyzy.com
*.uat.trortyzy.com
*.v1.trortyzy.com
*.v2.trortyzy.com
*.vpn.trortyzy.com
*.web.trortyzy.com
*.www.trortyzy.com
baucheedoa.net
*.baucheedoa.net
*.16320454-5241-47be-83e2-6fd7c9890ea1.naphound.com
*.312723b5-b193-4352-af20-b4e494fa390e.naphound.com
*.9c1c57a5-0627-44a1-b38e-cba0bb0d7b58.naphound.com
*.a.naphound.com
*.api.naphound.com
*.asa.naphound.com
*.assets.naphound.com
*.awghcuat.naphound.com
*.backup.naphound.com
*.cloud.naphound.com
*.cpanel.naphound.com
*.dashboard.naphound.com
*.deac4169-de47-4d16-8637-6dc545e0c58d.naphound.com
*.demo.naphound.com
*.dev.naphound.com
*.erkmka.naphound.com
*.fzhwfloja.naphound.com
*.loja.naphound.com
*.mailer.naphound.com
*.marketing.naphound.com
*.members.naphound.com
naphound.com
*.naphound.com
*.qa.naphound.com
*.rd.naphound.com
*.rdweb.naphound.com
*.remote.naphound.com
*.secure.naphound.com
*.staging.naphound.com
*.staging2.naphound.com
*.stg.naphound.com
*.test.naphound.com
*.uat.naphound.com
*.v1.naphound.com
*.v2.naphound.com
*.voronezh.naphound.com
*.vpn.naphound.com
*.web.naphound.com
*.m.qualityprime.com
qualityprime.com
*.qualityprime.com
*.drbvkumarfoundation.thetoned.com
*.falcongamez.thetoned.com
*.gamessouk.thetoned.com
*.mobimeat.thetoned.com
thetoned.com
*.thetoned.com
*.v5foodyhub.thetoned.com
*.vikasacademy.thetoned.com
Other domains in certificate