Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=xfsh1.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 19, 2026
Valid Until
July 18, 2026
47 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EC:0F:C2:1C:9A:66:14:8D:05:CF:D3:AF:99:07:77:97:0D:71:24:FB:A0:FA:0D:AD:E6:73:AA:95:16:8B:F8:0D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
70 domains
zure.us
*.zure.us
*.a.zure.us
*.atp.zure.us
*.avd.zure.us
*.awvd.zure.us
*.catalogapi.zure.us
*.enercitya.zure.us
*.fcaylwvd.zure.us
*.myaccount.zure.us
*.wbd.zure.us
*.web.zure.us
*.wvb.zure.us
*.wvd.zure.us
*.wvda.zure.us
468bet.pro
*.468bet.pro
bosobile.com
*.bosobile.com
capygames.click
*.capygames.click
dewv.net
*.dewv.net
fempsk7xa.cc
*.fempsk7xa.cc
gasoline.studio
*.gasoline.studio
geared.life
*.geared.life
graindevie.org
*.graindevie.org
kagelog.com
*.kagelog.com
movidoz.xyz
*.movidoz.xyz
*.admin.njexoticpets.biz
njexoticpets.biz
*.njexoticpets.biz
*.ww1.njexoticpets.biz
*.www.njexoticpets.biz
*.ad.psychologydegree.shop
*.backend.psychologydegree.shop
*.checkout.psychologydegree.shop
*.ns.psychologydegree.shop
psychologydegree.shop
*.psychologydegree.shop
*.remote.psychologydegree.shop
queenfash.com
*.queenfash.com
rebren.org
*.rebren.org
saigonrestaurant.website
*.saigonrestaurant.website
*.ww25.saigonrestaurant.website
sotflays.co
*.sotflays.co
*.ww25.sotflays.co
*.ww38.sotflays.co
*.sitemap.startgame.click
startgame.click
*.startgame.click
*.ww25.startgame.click
volvobenifits.com
*.volvobenifits.com
*.ww25.xfsh1.xyz
*.ww38.xfsh1.xyz
xfsh1.xyz
*.xfsh1.xyz
xunexpress.net
*.xunexpress.net
Other domains in certificate