76/100 SECURITY SCORE

Certificate Information

Subject
CN=319624.lgbt
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 06, 2026
Valid Until
July 05, 2026 54 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
68:F7:D0:58:0F:6B:53:64:BF:25:85:65:9A:C3:83:BA:82:5E:47:C3:6D:E5:6F:16:42:39:58:D5:FD:28:20:71
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
itbagospice.com *.itbagospice.com

Other domains in certificate

319624.lgbt *.319624.lgbt
4daos.com *.4daos.com
aide-webmaster.com *.aide-webmaster.com
billionaireacademy.com *.billionaireacademy.com
blackownedclothing.com *.blackownedclothing.com
blazecrestgameverse.com *.blazecrestgameverse.com
blazeexplorer72.info *.blazeexplorer72.info
blgts.chat *.blgts.chat
bnbvancouver.com *.bnbvancouver.com
boofiya.com *.boofiya.com
bounceperformance.com *.bounceperformance.com
brainige.com *.brainige.com
built-by-john.com *.built-by-john.com
cledepeau-beaute.in *.cledepeau-beaute.in
cltnuh.top *.cltnuh.top
codebase.ventures *.codebase.ventures
collazoprojects.com *.collazoprojects.com
creationistmathematics.com *.creationistmathematics.com
dteyu.futbol *.dteyu.futbol
dzzeq.beer *.dzzeq.beer
en-en--primebiome.us *.en-en--primebiome.us
enboks.com *.enboks.com
eniyilerbizdevarsasndeburayagel.shop *.eniyilerbizdevarsasndeburayagel.shop
eoeaf.com *.eoeaf.com
fitplaces.com *.fitplaces.com
formatservices.com *.formatservices.com
helpdebt.org *.helpdebt.org
herstesting.com *.herstesting.com
hfashd.cc *.hfashd.cc
hydrotherapy.cc *.hydrotherapy.cc
i5a84g2ffltkv.top *.i5a84g2ffltkv.top
interiorsketch.com *.interiorsketch.com
ivs1.cc *.ivs1.cc
jumpstreet.org *.jumpstreet.org
lawfixer.com *.lawfixer.com
madisonbymadison.org *.madisonbymadison.org
mar-oon.com *.mar-oon.com
myopap.com *.myopap.com
revolucionario.com *.revolucionario.com
saltedmarketing.com *.saltedmarketing.com
winstone.cc *.winstone.cc
wise-choice.com *.wise-choice.com
worksdesignguru.pro *.worksdesignguru.pro
xn--45q56x.com *.xn--45q56x.com