Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=otar.io
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 07, 2026
Valid Until
August 05, 2026
83 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E1:14:39:44:AA:39:42:7E:10:79:86:45:16:10:74:EC:B8:2D:98:FB:CC:F7:6B:4F:D8:FD:93:63:A0:2E:94:49
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ramezz.com
*.ramezz.com
*.api.ramezz.com
*.beta.ramezz.com
*.co.ramezz.com
*.cpcalendars.ramezz.com
*.dc-991ae00d4a16.ramezz.com
*.vorof.ramezz.com
*.ww38.ramezz.com
2share.co
*.2share.co
69x2101.cc
*.69x2101.cc
88av4608.cc
*.88av4608.cc
*.32.aleebet.com
aleebet.com
*.aleebet.com
*.assets.autoaction.io
autoaction.io
*.autoaction.io
*.dev.autoaction.io
*.relay.autoaction.io
*.ww1.autoaction.io
*.32.casino33.pro
casino33.pro
*.casino33.pro
*.32.chocolataulaitboutique.com
chocolataulaitboutique.com
*.chocolataulaitboutique.com
*.art.chopshoptattoos.com
chopshoptattoos.com
*.chopshoptattoos.com
*.comune.chopshoptattoos.com
*.email.chopshoptattoos.com
*.images.chopshoptattoos.com
*.32.geobdg.com
geobdg.com
*.geobdg.com
*.mail.geobdg.com
h-comic.site
*.h-comic.site
*.apps.marshmello.io
*.colleague.marshmello.io
marshmello.io
*.marshmello.io
*.secure.marshmello.io
*.staging.marshmello.io
*.vip.marshmello.io
*.www.marshmello.io
*.443d57296576e8d959d2d6acfd0362ea.otar.io
otar.io
*.otar.io
*.ww25.otar.io
*.32.ovagames.xyz
ovagames.xyz
*.ovagames.xyz
*.sitemaps.ovagames.xyz
*.32.pakdatacf.com
pakdatacf.com
*.pakdatacf.com
*.32.pcastbaby.com
pcastbaby.com
*.pcastbaby.com
*.ww38.pcastbaby.com
pieceoffranco.xyz
*.pieceoffranco.xyz
*.32.r99.bet
r99.bet
*.r99.bet
*.outbound-1618477747-101.realtimes.io
realtimes.io
*.realtimes.io
rtp-slotogel1.us
*.rtp-slotogel1.us
*.m.rtpgascorkkv99.click
rtpgascorkkv99.click
*.rtpgascorkkv99.click
*.sitemaps.rtpgascorkkv99.click
*.ww38.rtpgascorkkv99.click
*.32.seatmouthfullopen.xyz
seatmouthfullopen.xyz
*.seatmouthfullopen.xyz
*.affiliates.socialhuge.io
*.app.socialhuge.io
socialhuge.io
*.socialhuge.io
*.v2.socialhuge.io
ufabetcp.click
*.ufabetcp.click
Other domains in certificate