Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=andymark.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 19, 2026
Valid Until
August 17, 2026
72 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AD:DB:4C:38:96:78:B9:73:33:7D:BF:DB:D1:A8:72:FA:33:A3:B3:28:DB:48:2C:EC:13:BD:08:09:F4:64:25:1D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
wk06.cc
*.wk06.cc
andymark.co
*.andymark.co
atmclassaction.co
*.atmclassaction.co
automecanico.co
*.automecanico.co
barbiemini.co
*.barbiemini.co
cbdnhempblog.com
*.cbdnhempblog.com
cciti.co
*.cciti.co
coolour.co
*.coolour.co
qjydl.qpon
*.qjydl.qpon
qlmpo.qpon
*.qlmpo.qpon
qlyyau.cn
*.qlyyau.cn
qqc11.co
*.qqc11.co
stampyone.com
*.stampyone.com
standblack.xyz
*.standblack.xyz
theelgnce.co
*.theelgnce.co
u7e53c.cyou
*.u7e53c.cyou
vintluxury.com
*.vintluxury.com
vkagx.bid
*.vkagx.bid
vnnnv.com
*.vnnnv.com
vocalstrip.com
*.vocalstrip.com
weekpass.io
*.weekpass.io
weightlesshydration.com
*.weightlesshydration.com
westgateprimary.com
*.westgateprimary.com
wgijab.club
*.wgijab.club
wiedlelaw.co
*.wiedlelaw.co
willsgpt.com
*.willsgpt.com
wjnxz.com
*.wjnxz.com
worthitall.org
*.worthitall.org
wow77in.lat
*.wow77in.lat
wrcvk.loan
*.wrcvk.loan
wwtma.loan
*.wwtma.loan
www12uu.me
*.www12uu.me
www61xx.me
*.www61xx.me
www92y.cc
*.www92y.cc
wwwb56.me
*.wwwb56.me
wwwc7211.com
*.wwwc7211.com
wwwyw58777.com
*.wwwyw58777.com
x6x6x6.com
*.x6x6x6.com
xmxog.loan
*.xmxog.loan
xn--0lqx9j.com
*.xn--0lqx9j.com
xn--8r2a.com
*.xn--8r2a.com
xn--ciudadseora-8db.com
*.xn--ciudadseora-8db.com
xn--cjr84w.com
*.xn--cjr84w.com
xn--czru2d927afw3b.com
*.xn--czru2d927afw3b.com
xn--eqrz12dk2c015c.com
*.xn--eqrz12dk2c015c.com
Other domains in certificate