Open
Cached
·
just now
87/100
SECURITY SCORE
Certificate Information
Subject
CN=mega-summit.online
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 11, 2025
Valid Until
March 11, 2026
43 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AA:44:25:1B:64:C0:52:84:13:23:82:86:96:84:02:FB:3F:70:2B:18:2C:93:A3:50:AA:18:7A:32:1A:54:D9:3E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
untitleddocument.co.uk
*.untitleddocument.co.uk
*.admin.aix-asia.click
aix-asia.click
*.aix-asia.click
*.api.aix-asia.click
*.test.aix-asia.click
aj2shop.com
*.aj2shop.com
bbywhite.com
*.bbywhite.com
*.youtube.bbywhite.com
betnacinal.com
*.betnacinal.com
bolly4u.bio
*.bolly4u.bio
ca5t9.com
*.ca5t9.com
chessforkids.com.au
*.chessforkids.com.au
chocolatine.net
*.chocolatine.net
*.random.chocolatine.net
*.ww38.chocolatine.net
*.comune.congtybocavn.online
congtybocavn.online
*.congtybocavn.online
*.mail.congtybocavn.online
developmyproperty.au
*.developmyproperty.au
duta89aman.xyz
*.duta89aman.xyz
elcockreisen.co.uk
*.elcockreisen.co.uk
*.remote.elcockreisen.co.uk
gengpt.io
*.gengpt.io
*.mx1.gengpt.io
*.net.gengpt.io
internationalposts.com
*.internationalposts.com
jaceney.info
*.jaceney.info
kdb.au
*.kdb.au
*.ww16.kdb.au
labia.com.au
*.labia.com.au
lcvo.online
*.lcvo.online
*.api.mega-summit.online
*.emv1.mega-summit.online
*.integration.mega-summit.online
mega-summit.online
*.mega-summit.online
*.portal.mega-summit.online
*.staging.mega-summit.online
onixcoin.biz
*.onixcoin.biz
*.ww25.onixcoin.biz
planboo.com
*.planboo.com
*.random.planboo.com
*.welcome.planboo.com
porn-film.cc
*.porn-film.cc
pornmomstv.pro
*.pornmomstv.pro
*.ww38.pornmomstv.pro
*.hostmaster.portal-cifi.com
portal-cifi.com
*.portal-cifi.com
*.w.portal-cifi.com
*.webmail.portal-cifi.com
*.www.portal-cifi.com
sa2hara.com
*.sa2hara.com
*.ww38.sa2hara.com
southsideproperty.au
*.southsideproperty.au
*.box.supplicart.online
*.random.supplicart.online
supplicart.online
*.supplicart.online
truyensex18.pro
*.truyensex18.pro
v12.studio
*.v12.studio
woodguides4.xyz
*.woodguides4.xyz
Other domains in certificate