76/100 SECURITY SCORE

Certificate Information

Subject
CN=asrar.info
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 08, 2025
Valid Until
March 08, 2026 47 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
79:38:B0:D4:5D:51:1B:75:C9:2E:41:73:1B:59:0D:22:EE:67:BC:77:D6:2B:FE:D9:DE:D9:9C:30:D9:99:3C:68
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
enersource.ca *.enersource.ca *.dashboard.enersource.ca *.report.enersource.ca *.superset-dev.enersource.ca *.webmail.enersource.ca

Other domains in certificate

2weeks.io *.2weeks.io *.ai.2weeks.io *.chat.2weeks.io *.flow.2weeks.io *.startup.2weeks.io *.test.2weeks.io
asrar.info *.asrar.info
*.anyconnect.babadan.com babadan.com *.babadan.com *.mobileconnect.babadan.com *.random.babadan.com *.remoto.babadan.com *.secureconnect.babadan.com *.studentsvpn.babadan.com *.ww.babadan.com *.ww1.babadan.com *.www.babadan.com
*.af.lularoeleggings.org *.am.lularoeleggings.org *.az.lularoeleggings.org *.bg.lularoeleggings.org *.ceb.lularoeleggings.org *.co.lularoeleggings.org *.cy.lularoeleggings.org *.da1.lularoeleggings.org *.de.lularoeleggings.org *.fr1.lularoeleggings.org *.fy.lularoeleggings.org *.gd.lularoeleggings.org *.gl.lularoeleggings.org *.ht.lularoeleggings.org *.is.lularoeleggings.org *.it.lularoeleggings.org *.jw.lularoeleggings.org *.ka.lularoeleggings.org *.km.lularoeleggings.org *.ko1.lularoeleggings.org *.ku.lularoeleggings.org *.ky.lularoeleggings.org *.lb.lularoeleggings.org *.lt1.lularoeleggings.org lularoeleggings.org *.lularoeleggings.org *.lv1.lularoeleggings.org *.mk.lularoeleggings.org *.ml.lularoeleggings.org *.mr.lularoeleggings.org *.mt.lularoeleggings.org *.ne.lularoeleggings.org *.nl1.lularoeleggings.org *.pa.lularoeleggings.org *.ps.lularoeleggings.org *.ro.lularoeleggings.org *.si.lularoeleggings.org *.so.lularoeleggings.org *.sq.lularoeleggings.org *.sr1.lularoeleggings.org *.su.lularoeleggings.org *.ta.lularoeleggings.org *.te.lularoeleggings.org *.th.lularoeleggings.org *.tl.lularoeleggings.org *.ur1.lularoeleggings.org *.vi.lularoeleggings.org *.xh.lularoeleggings.org *.yi.lularoeleggings.org *.zh.lularoeleggings.org
*.565b080d-22ff-4288-989c-f6a3a178da79.myshelton.com *.flowise.myshelton.com *.forums.myshelton.com *.https.myshelton.com myshelton.com *.myshelton.com *.rustore.myshelton.com *.wildcard.myshelton.com *.ww17.myshelton.com *.ww38.myshelton.com *.www.myshelton.com
*.ww16.xn--sosyalhalsaha-cbc.com xn--sosyalhalsaha-cbc.com *.xn--sosyalhalsaha-cbc.com