Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=yamahamatsakti.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 18, 2026
Valid Until
September 16, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B4:49:FD:9C:27:69:56:D1:31:26:B9:09:BD:F9:58:C3:15:3E:F4:F1:D1:6D:35:84:4B:83:E9:85:59:C9:5D:7E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
virtuosobali.com
*.virtuosobali.com
*.comm.virtuosobali.com
addcoupons.com
*.addcoupons.com
*.ftp.addcoupons.com
*.ssh.addcoupons.com
aibrightname.com
*.aibrightname.com
*.test.aibrightname.com
cityofeve.com
*.cityofeve.com
*.www3.cityofeve.com
crackingpaching.com
*.crackingpaching.com
dinohoki.live
*.dinohoki.live
*.yls600.dinohoki.live
*.c58c115b.guvupade.xyz
guvupade.xyz
*.guvupade.xyz
*.6441056b613c32a9.htoh.cc
htoh.cc
*.htoh.cc
*.ww25.htoh.cc
icharper.net
*.icharper.net
*.rdl.icharper.net
*.apple.icloudunlock.com
*.ff.icloudunlock.com
*.hostmaster.icloudunlock.com
*.iclouddnsbypass.icloudunlock.com
icloudunlock.com
*.icloudunlock.com
*.remove.icloudunlock.com
*.ww25.icloudunlock.com
*.www.icloudunlock.com
lionglobal.au
*.lionglobal.au
lioze.xyz
*.lioze.xyz
*.xyz.lioze.xyz
*.kwid9.modelcloud.xyz
modelcloud.xyz
*.modelcloud.xyz
omniacapital.co
*.omniacapital.co
*.8bei.oo4440.cc
oo4440.cc
*.oo4440.cc
ooutd.qpon
*.ooutd.qpon
*.pp4gk.qsttuvw.top
qsttuvw.top
*.qsttuvw.top
stogieworld.us
*.stogieworld.us
*.app.toyprince.com
toyprince.com
*.toyprince.com
*.logpainter.trpgbot.com
*.qsign.trpgbot.com
*.s03.trpgbot.com
trpgbot.com
*.trpgbot.com
*.32.v12.studio
v12.studio
*.v12.studio
wissa.online
*.wissa.online
*.ww25.wissa.online
*.wildcard.xn--4gqw10d7va.com
xn--4gqw10d7va.com
*.xn--4gqw10d7va.com
*.hostmaster.xn--mgba0gibjn.com
xn--mgba0gibjn.com
*.xn--mgba0gibjn.com
*.cpanel.yamahamatsakti.com
*.o.yamahamatsakti.com
yamahamatsakti.com
*.yamahamatsakti.com
*.01.zhin.com
*.mtxz2026.zhin.com
*.pay.zhin.com
*.test.zhin.com
*.tool.zhin.com
*.xj.zhin.com
zhin.com
*.zhin.com
*.zzsjyjc.zhin.com
Other domains in certificate