76/100 SECURITY SCORE

Certificate Information

Subject
CN=thingumyandbob.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 11, 2026
Valid Until
August 09, 2026 75 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
22:B3:63:18:5E:91:A5:F1:1C:7C:42:53:CD:A4:CB:7D:AD:54:C5:5A:85:89:70:B8:34:A5:4E:1B:61:AD:01:B1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
world-classespear.com *.world-classespear.com

Other domains in certificate

thingumyandbob.com *.thingumyandbob.com
tildaspicymexicanrice.com *.tildaspicymexicanrice.com
tkaxu1044.com *.tkaxu1044.com
tmndr.cc *.tmndr.cc
tnbc-treatment-1e6zz.click *.tnbc-treatment-1e6zz.click
topyai1.com *.topyai1.com
torchest.com *.torchest.com
translinguamig.com *.translinguamig.com
treyans.com *.treyans.com
trollinggeorgia.com *.trollinggeorgia.com
try-sveing.com *.try-sveing.com
tryoculon.com *.tryoculon.com
trywhat3wordsapi.com *.trywhat3wordsapi.com
trywhat3wordsglobal.com *.trywhat3wordsglobal.com
*.a.twinklegemsaga.com twinklegemsaga.com *.twinklegemsaga.com
tysp22.top *.tysp22.top
ugdewaux.com *.ugdewaux.com
undke.com *.undke.com
ungenially.com *.ungenially.com
va92.com *.va92.com
vehuwi.com *.vehuwi.com
vertex-advisorybase.com *.vertex-advisorybase.com
vhfkj1350.com *.vhfkj1350.com
vipqtt.com *.vipqtt.com
*.7zbydc.virtuartworks.com virtuartworks.com *.virtuartworks.com
voltageblitz.com *.voltageblitz.com
vymyg.com *.vymyg.com
w3wforbusiness.net *.w3wforbusiness.net
w3wforbusinesshub.com *.w3wforbusinesshub.com
w3wforbusinesssite.com *.w3wforbusinesssite.com
wa-bluechipjobs.com *.wa-bluechipjobs.com
wapuda.com *.wapuda.com
washingjob-dish-disheswashingjob522.sbs *.washingjob-dish-disheswashingjob522.sbs
watsaty.com *.watsaty.com
what3wordscontactsite.com *.what3wordscontactsite.com
what3wordsglobal-team.com *.what3wordsglobal-team.com
what3wordshub.com *.what3wordshub.com
what3wordssite.com *.what3wordssite.com
what3wordsteam.com *.what3wordsteam.com
whatthreewordshub.com *.whatthreewordshub.com
whattsapwebos.com *.whattsapwebos.com
wilas-array.com *.wilas-array.com
wm-telegran.org *.wm-telegran.org