Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=thebirdwatchingcafe.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 15, 2026
Valid Until
August 13, 2026
69 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:8C:5F:B9:2F:AF:F9:65:54:01:66:0A:DD:CF:D3:19:18:00:5F:EA:6F:73:EC:A4:4B:3B:C3:EE:B2:1C:2C:C4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
78 domains
vastsneakers.com
*.vastsneakers.com
3btclottery.com
*.3btclottery.com
*.m.3btclottery.com
alditald.de
*.alditald.de
*.hostmaster.alditald.de
alertmarkshop.com
*.alertmarkshop.com
*.random.alertmarkshop.com
americancolectors.com
*.americancolectors.com
*.hostmaster.americancolectors.com
*.ww25.americancolectors.com
*.www.americancolectors.com
australianaviationmuseum.com.au
*.australianaviationmuseum.com.au
*.jasonagustina.australianaviationmuseum.com.au
*.ns3155861.australianaviationmuseum.com.au
druckerzugehoer.de
*.druckerzugehoer.de
hometimeksa.com
*.hometimeksa.com
hsy762.com
*.hsy762.com
*.xy.hsy762.com
*.central.iptv-nextt.club
iptv-nextt.club
*.iptv-nextt.club
isoldeetlesbens.com
*.isoldeetlesbens.com
*.jenkins.isoldeetlesbens.com
*.random.isoldeetlesbens.com
jlb2023.com
*.jlb2023.com
*.random.jlb2023.com
jre.au
*.jre.au
*.hostmaster.low3s.com
low3s.com
*.low3s.com
*.hostmaster.makemkv.de
makemkv.de
*.makemkv.de
ottawasportsmen.org
*.ottawasportsmen.org
*.ww16.ottawasportsmen.org
overtins.com
*.overtins.com
*.remote.overtins.com
*.guide.pettura.com
pettura.com
*.pettura.com
*.cas2.questdiagnosrics.com
*.myquest.questdiagnosrics.com
questdiagnosrics.com
*.questdiagnosrics.com
sagespa-springhouse.com
*.sagespa-springhouse.com
shopvangogh.com
*.shopvangogh.com
thebirdwatchingcafe.com
*.thebirdwatchingcafe.com
trianasbeautycosmetics.com
*.trianasbeautycosmetics.com
*.hostmaster.wesrelm.com
wesrelm.com
*.wesrelm.com
*.www.wesrelm.com
*.hostmaster.wwwfox.com
*.ws.wwwfox.com
*.wss.wwwfox.com
*.www.wwwfox.com
wwwfox.com
*.wwwfox.com
zibashopp.com
*.zibashopp.com
Other domains in certificate