Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=ascendingkoi.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FD:0F:84:47:93:F6:8F:13:11:3F:1D:C5:74:43:E7:F1:32:13:14:8F:DD:B8:A2:F2:AD:7E:86:41:F1:51:64:8C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
elahamd.com
*.elahamd.com
ascendingkoi.com
*.ascendingkoi.com
asd123dadar.xyz
*.asd123dadar.xyz
askjannew.com
*.askjannew.com
assassino.de
*.assassino.de
astro-pop.net
*.astro-pop.net
atendimento-ofc.site
*.atendimento-ofc.site
authority.chat
*.authority.chat
avvocatoestero.it
*.avvocatoestero.it
axelliant-tech.com
*.axelliant-tech.com
axio88h.org
*.axio88h.org
ayokbakar69.tube
*.ayokbakar69.tube
b232849.cyou
*.b232849.cyou
b888y625.vip
*.b888y625.vip
babu88apk.click
*.babu88apk.click
backyardgardeningknowhow.xyz
*.backyardgardeningknowhow.xyz
badutcihuy-002.cfd
*.badutcihuy-002.cfd
balance-cortisol-289174977.click
*.balance-cortisol-289174977.click
bangkokmanagement.com
*.bangkokmanagement.com
baylorhelpinghands.org
*.baylorhelpinghands.org
bdrtotomaju.xyz
*.bdrtotomaju.xyz
begodsversionofyou.com
*.begodsversionofyou.com
bet888pro.biz
*.bet888pro.biz
betbet.in
*.betbet.in
bhkyjm.academy
*.bhkyjm.academy
bigplayer.it
*.bigplayer.it
bigtexasranches.com
*.bigtexasranches.com
dong77.vip
*.dong77.vip
doublesport.net
*.doublesport.net
dragon969bone.com
*.dragon969bone.com
dresshop.co.uk
*.dresshop.co.uk
duckblindmafia.com
*.duckblindmafia.com
dung.it
*.dung.it
duquesaasmr.online
*.duquesaasmr.online
dyk9k7dhm.buzz
*.dyk9k7dhm.buzz
e5484771.vip
*.e5484771.vip
e666eq.com
*.e666eq.com
ebookpdf.info
*.ebookpdf.info
ecobasketbest.com
*.ecobasketbest.com
edahubzzz.xyz
*.edahubzzz.xyz
escolapiascolombia.org
*.escolapiascolombia.org
eskoni.com
*.eskoni.com
esset.it
*.esset.it
estoresgalore.com
*.estoresgalore.com
etichettebagagli.it
*.etichettebagagli.it
Other domains in certificate