Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=gbtours.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 10, 2026
Valid Until
July 09, 2026
67 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5A:C2:57:57:3D:5A:1A:AD:B3:21:0C:0F:61:EB:AB:BE:4A:00:AC:4E:DD:AF:76:D3:FC:BC:89:21:60:A3:1A:16
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
worldfast.biz
*.worldfast.biz
004avtt.com
*.004avtt.com
84138.bet
*.84138.bet
aktivasarnix.org
*.aktivasarnix.org
crcpuk.my
*.crcpuk.my
creandoando.com
*.creandoando.com
creative-banner-182857211.click
*.creative-banner-182857211.click
cred-debtfinancebanking.com
*.cred-debtfinancebanking.com
cruise-travel.sbs
*.cruise-travel.sbs
crvlk.forsale
*.crvlk.forsale
cvgqt.my
*.cvgqt.my
dea2a.com
*.dea2a.com
delta-tools.com
*.delta-tools.com
demosignal.com
*.demosignal.com
dental-care-46154.click
*.dental-care-46154.click
dragon-play2.casino
*.dragon-play2.casino
ecotransport.co.uk
*.ecotransport.co.uk
*.magento.ecotransport.co.uk
*.vpn.ecotransport.co.uk
fhcp.reviews
*.fhcp.reviews
funfood.co.uk
*.funfood.co.uk
gbtours.co.uk
*.gbtours.co.uk
itlianigame.top
*.itlianigame.top
ja-dllire004.com
*.ja-dllire004.com
jatengbintangtoto.com
*.jatengbintangtoto.com
jnvlvr.my
*.jnvlvr.my
joinbloomsolutions.co
*.joinbloomsolutions.co
lhfdt.my
*.lhfdt.my
livemingles.com
*.livemingles.com
lumendrive.co
*.lumendrive.co
lustypost.com
*.lustypost.com
maniefic.com
*.maniefic.com
thedogandparrot.co.uk
*.thedogandparrot.co.uk
worker-packing-company-in-my-area.sbs
*.worker-packing-company-in-my-area.sbs
wqhkt.my
*.wqhkt.my
www000289.com
*.www000289.com
www000310.com
*.www000310.com
www000551.com
*.www000551.com
www368488.com
*.www368488.com
www499902.com
*.www499902.com
www985506.com
*.www985506.com
www993341.com
*.www993341.com
www999832.com
*.www999832.com
youthcamps.co.uk
*.youthcamps.co.uk
zs75qk8z.top
*.zs75qk8z.top
zztt36.fun
*.zztt36.fun
Other domains in certificate