Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=sephora.click
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 08, 2026
Valid Until
August 06, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:BC:62:00:B8:17:CC:AF:49:58:81:89:28:09:EA:10:D9:4E:24:B2:7C:AC:FD:75:3C:F4:47:D3:BA:48:4A:00
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
xepp.info
*.xepp.info
*.website.xepp.info
*.ww38.xepp.info
apick.vip
*.apick.vip
*.ww25.apick.vip
*.atlas.congentco.com
congentco.com
*.congentco.com
*.demark.congentco.com
*.ns1.congentco.com
*.ns2.congentco.com
*.sys.congentco.com
dooptoupouwhuwu.xyz
*.dooptoupouwhuwu.xyz
*.ww25.dooptoupouwhuwu.xyz
*.ww38.dooptoupouwhuwu.xyz
goalootv1.sbs
*.goalootv1.sbs
*.link6.goalootv1.sbs
*.4u22hs.jstv1382.xyz
*.5m4kpo.jstv1382.xyz
*.7wfquk.jstv1382.xyz
*.bany66.jstv1382.xyz
*.c047ew.jstv1382.xyz
*.i1rqvb.jstv1382.xyz
*.is2nk7.jstv1382.xyz
jstv1382.xyz
*.jstv1382.xyz
*.quqt46.jstv1382.xyz
*.ww38.jstv1382.xyz
*.50r8io.jstv2222.xyz
*.53s8v7.jstv2222.xyz
*.53sysr.jstv2222.xyz
*.59beia.jstv2222.xyz
*.7wfo3n.jstv2222.xyz
*.8fr7waf.jstv2222.xyz
*.8tce6zi.jstv2222.xyz
*.8wrkz4e.jstv2222.xyz
*.bcqodydq7ft.jstv2222.xyz
*.djvbc4h00s3.jstv2222.xyz
*.dongbei.jstv2222.xyz
*.e2qpgc.jstv2222.xyz
*.e2u2c9.jstv2222.xyz
*.i4vmw8.jstv2222.xyz
*.jingpin.jstv2222.xyz
jstv2222.xyz
*.jstv2222.xyz
*.m6k0f7.jstv2222.xyz
*.nbpyi8j3yp6b.jstv2222.xyz
*.oohjfxotcgi.jstv2222.xyz
*.qsmbh609xqo.jstv2222.xyz
*.qt9waq.jstv2222.xyz
*.qtsluydqy8p.jstv2222.xyz
*.sadrkcafek5.jstv2222.xyz
*.sghfseacn6b.jstv2222.xyz
*.tsgema958149338.jstv2222.xyz
*.uipodyk56rm.jstv2222.xyz
*.urkcj4h00im.jstv2222.xyz
*.wlmrjiiafy4.jstv2222.xyz
*.ww38.jstv2222.xyz
*.xrjlpe4oynk.jstv2222.xyz
*.ydndnf.jstv2222.xyz
*.32.sephora.click
sephora.click
*.sephora.click
*.ww25.sephora.click
*.autoconfig.springtime.life
springtime.life
*.springtime.life
*.test.springtime.life
*.webmail.springtime.life
*.whm.springtime.life
*.ww38.springtime.life
stryke.pro
*.stryke.pro
*.www.stryke.pro
*.server1.wael.website
wael.website
*.wael.website
*.firstclasslearnithumb-v6.xhware.world
*.hsbc.xhware.world
*.ic-tt-lm.xhware.world
*.ic-ut-nss.xhware.world
*.ww38.xhware.world
xhware.world
*.xhware.world
*.zh.xhware.world
Other domains in certificate