Open
Cached
·
just now
73/100
SECURITY SCORE
Certificate Information
Subject
CN=*.sakura.ne.jp
Issuer
C=JP, ST=Tokyo, L=Chiyoda-ku, O=Gehirn Inc., CN=Gehirn Managed Certification Authority - RSA DV
Valid From
April 29, 2025
Valid Until
May 19, 2026
189 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:62:C1:CD:AA:19:AC:86:EB:A1:65:C0:7F:00:8F:7D:C2:76:F4:CC:2A:28:42:A6:2F:AC:F8:68:F1:05:F2:7C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
Forward Secrecy
Limited
(Check cipher configuration)
Warnings
- • TLS 1.3 is not supported (recommended)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
64 domains
*.ivory.ne.jp
*.mail-box.ne.jp
*.mints.ne.jp
*.mokuren.ne.jp
*.opal.ne.jp
*.sakura.ne.jp
*.sumomo.ne.jp
*.topaz.ne.jp
*.180r.com
*.2-d.jp
*.achoo.jp
*.amaretto.jp
*.bona.jp
*.chew.jp
*.crap.jp
*.daynight.jp
*.deko8.jp
*.dojin.com
*.eek.jp
*.flop.jp
*.from.tv
*.fubuki.info
*.gokujou.biz
*.grats.jp
*.grrr.jp
*.halfmoon.jp
*.jeez.jp
*.jpn.org
*.kirara.st
*.kokage.cc
*.matrix.jp
*.mimoza.jp
*.nazo.cc
*.netgamers.jp
*.noob.jp
*.nyanta.jp
*.o0o0.jp
*.rash.jp
*.razor.jp
*.rdy.jp
*.rgr.jp
*.rojo.jp
*.rossa.cc
*.rulez.jp
*.rusk.to
*.saikyou.biz
*.sakura.tv
*.sakuratan.com
*.sakuraweb.com
*.saloon.jp
*.sblo.jp
*.silk.to
*.skr.jp
*.spawn.jp
*.squares.net
*.tank.jp
*.thyme.jp
*.uh-oh.jp
*.undo.jp
*.websozai.jp
*.whoa.jp
*.x0.com
*.x0.to
*.xii.jp
Other domains in certificate