Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=1win-registration23.top
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 17, 2026
Valid Until
September 15, 2026
80 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
67:2F:BA:F5:2E:9E:EB:DD:D2:55:27:68:7A:F6:C9:2C:C5:75:2E:9C:94:FB:7E:D0:47:1D:92:1F:96:6D:3B:2C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
uspssecure.com
*.uspssecure.com
1win-registration23.top
*.1win-registration23.top
*.conf.1win-registration23.top
*.meet.1win-registration23.top
777xm.cc
*.777xm.cc
*.h5.777xm.cc
*.de.destinationsae.com
destinationsae.com
*.destinationsae.com
*.en.destinationsae.com
*.er.destinationsae.com
*.gb.destinationsae.com
*.na.destinationsae.com
*.no.destinationsae.com
huaxiwx.com
*.huaxiwx.com
hxwpx.my
*.hxwpx.my
*.32.masrawy.chat
masrawy.chat
*.masrawy.chat
*.activesync.mundofree.com
*.bioinfo.mundofree.com
*.dashboard.mundofree.com
*.fortigatevpn.mundofree.com
*.hongkong.mundofree.com
*.inbound.mundofree.com
*.ldap02.mundofree.com
mundofree.com
*.mundofree.com
*.nn.mundofree.com
*.notexistssql.mundofree.com
*.secure.mundofree.com
*.suboffer.mundofree.com
*.sun1.mundofree.com
*.vid2.mundofree.com
*.vpn5b.mundofree.com
*.vpntoj.mundofree.com
*.codeislaw.ottspott.co
*.connect-devel-alexis.ottspott.co
*.countr.ottspott.co
*.desktop.ottspott.co
*.empower.ottspott.co
*.espacerdv.ottspott.co
*.help-connect.ottspott.co
*.help.ottspott.co
*.left.ottspott.co
*.myapp.ottspott.co
*.neuxpower.ottspott.co
*.oosteo.ottspott.co
*.ottspott-desktop-client-devel-alexis.ottspott.co
*.ottspott-desktop-client-devel.ottspott.co
*.ottspott-devel-alexis.ottspott.co
*.ottspott-devel.ottspott.co
ottspott.co
*.ottspott.co
*.redlean.ottspott.co
*.saagie.ottspott.co
*.slicedbrand.ottspott.co
*.try.ottspott.co
*.wazo-prod-de-fra-1.ottspott.co
*.wazo1.ottspott.co
*.www.ottspott.co
rcmtechnologies.com
*.rcmtechnologies.com
*.webmail.rcmtechnologies.com
tuiwenge.com
*.tuiwenge.com
tysfy.video
*.tysfy.video
ucglw.video
*.ucglw.video
udybj.video
*.udybj.video
udyyzt.video
*.udyyzt.video
user-2faverify.com
*.user-2faverify.com
valleyacresmarket.com
*.valleyacresmarket.com
vertexaction354.top
*.vertexaction354.top
vibemarketingvault.com
*.vibemarketingvault.com
virtualsis.com
*.virtualsis.com
Other domains in certificate