Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=rocafiel.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 14, 2026
Valid Until
May 15, 2026
81 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F5:29:D3:A9:86:A7:DE:ED:CA:C7:12:A6:AD:2E:D0:49:F0:4F:9B:17:FC:C3:51:13:EA:9C:75:CB:15:F2:9B:21
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
voxlibrorum.com
*.voxlibrorum.com
bernados.com
*.bernados.com
dentrixremote.com
*.dentrixremote.com
*.dns.dentrixremote.com
*.hostmaster.dentrixremote.com
*.mx7.dentrixremote.com
denverwestapartments.com
*.denverwestapartments.com
diabetesphil.org
*.diabetesphil.org
ellaberinto.com
*.ellaberinto.com
embexpart.net
*.embexpart.net
empoweredfitnesssouls.run
*.empoweredfitnesssouls.run
erciyessogutma.com
*.erciyessogutma.com
festival.co.za
*.festival.co.za
*.fringe.festival.co.za
*.walkin.festival.co.za
findsalesassemblyservice.com
*.findsalesassemblyservice.com
fitnessmindsetshift.club
*.fitnessmindsetshift.club
getboonhring.com
*.getboonhring.com
gettrigifyservice.com
*.gettrigifyservice.com
grandtraveladventures.live
*.grandtraveladventures.live
harmonygardenquest.live
*.harmonygardenquest.live
harmonynaturegardens.live
*.harmonynaturegardens.live
*.hnb-lesen.hobbyfabrik.de
hobbyfabrik.de
*.hobbyfabrik.de
*.kulturmagazin.hobbyfabrik.de
*.lesen.hobbyfabrik.de
*.liesel.hobbyfabrik.de
*.literaturmagazin.hobbyfabrik.de
hqxwy.net
*.hqxwy.net
livingspces.com
*.livingspces.com
*.random.livingspces.com
rocafiel.com
*.rocafiel.com
shiori-takei.com
*.shiori-takei.com
*.www.shiori-takei.com
*.canales.telefivegb.com
*.cpanel.telefivegb.com
*.hostmaster.telefivegb.com
*.m.telefivegb.com
*.mail.telefivegb.com
*.plesk.telefivegb.com
telefivegb.com
*.telefivegb.com
*.webdisk.telefivegb.com
*.webmail.telefivegb.com
*.ww25.telefivegb.com
*.www.telefivegb.com
theemptyteabox.com
*.theemptyteabox.com
useclassuphub.com
*.useclassuphub.com
vollemaan.com
*.vollemaan.com
weddingsmajesticglimpse.beauty
*.weddingsmajesticglimpse.beauty
wfimap.io
*.wfimap.io
*.ww25.wfimap.io
worships.com
*.worships.com
*.www.xmcy1.vip
xmcy1.vip
*.xmcy1.vip
xn--associao-xza3b.com
*.xn--associao-xza3b.com
*.hostmaster.xn--hq1bm8jm9lmob95g.net
xn--hq1bm8jm9lmob95g.net
*.xn--hq1bm8jm9lmob95g.net
Other domains in certificate