76/100 SECURITY SCORE

Certificate Information

Subject
CN=vavadaez71.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 12, 2026
Valid Until
August 10, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:73:38:AA:19:56:2D:65:5D:F8:3C:C8:7E:5B:C8:3C:12:17:9D:68:F5:93:4A:CB:2C:71:3E:B0:6C:A6:19:37
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
vavadaez71.com *.vavadaez71.com *.api.vavadaez71.com *.demo.vavadaez71.com *.rds.vavadaez71.com *.rdweb.vavadaez71.com *.sitemaps.vavadaez71.com *.wp.vavadaez71.com *.wwwremote.vavadaez71.com *.yqgwzebpjhsitemaps.vavadaez71.com

Other domains in certificate

169che.com *.169che.com *.blog.169che.com *.healthsolutions.169che.com *.hostmaster.169che.com *.mail.169che.com *.www.169che.com
akura7.space *.akura7.space *.dev.akura7.space *.smtp.akura7.space *.y.akura7.space
jinbhagu.com *.jinbhagu.com
*.f70y0w.kanas.net kanas.net *.kanas.net *.login.kanas.net *.mobile.kanas.net *.office.kanas.net *.portal.kanas.net *.vpn1.kanas.net *.web.kanas.net *.webconnect.kanas.net *.www.kanas.net
*.autoconfig.missionnames.com *.ftp.missionnames.com *.localhost.missionnames.com *.mail.missionnames.com missionnames.com *.missionnames.com
pausuvaunazeena.com *.pausuvaunazeena.com
payrplumber.de *.payrplumber.de
perrysplumbingandheating.de *.perrysplumbingandheating.de
*.analytics.simpatiche.com *.dev.simpatiche.com simpatiche.com *.simpatiche.com *.staging.simpatiche.com *.test.simpatiche.com
ssparfumatelier.com *.ssparfumatelier.com
*.aa-32186.starbucks.cc *.account.starbucks.cc *.acquisition.starbucks.cc *.airbnb-request-home.starbucks.cc *.app.starbucks.cc *.cn.starbucks.cc *.commerce.starbucks.cc *.devel.starbucks.cc *.m.starbucks.cc *.scmdev.starbucks.cc starbucks.cc *.starbucks.cc *.wfmnapimst.starbucks.cc *.ww25.starbucks.cc *.ww38.starbucks.cc
*.bnbod.vwxy01.top *.civoh.vwxy01.top *.kac0t.vwxy01.top *.kwid9.vwxy01.top *.osc36.vwxy01.top *.ovsrrb.vwxy01.top *.rkuvx.vwxy01.top *.v3ywp.vwxy01.top *.vizaseq.vwxy01.top vwxy01.top *.vwxy01.top
wellcarehealthnetcalifornia.com *.wellcarehealthnetcalifornia.com
*.cloud.xn--tiq240h1ls.com *.m.xn--tiq240h1ls.com *.rd.xn--tiq240h1ls.com *.rdweb.xn--tiq240h1ls.com *.remote.xn--tiq240h1ls.com xn--tiq240h1ls.com *.xn--tiq240h1ls.com