Open
Cached
·
2h ago
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=serramar.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 21, 2026
Valid Until
July 20, 2026
67 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
66:97:5A:5D:DC:56:A0:F9:97:D8:1C:AB:C6:2A:55:64:42:40:A2:CB:99:81:91:4D:ED:05:7C:E7:1E:B6:B4:BF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
zahtar.com
*.zahtar.com
athkar.com
*.athkar.com
borar.com
*.borar.com
chesler.com
*.chesler.com
*.phyllis.chesler.com
chienbleu.com
*.chienbleu.com
coffeeburst.com
*.coffeeburst.com
copyno.com
*.copyno.com
dashar.com
*.dashar.com
*.ww25.dashar.com
delbianco.com
*.delbianco.com
espritnomade.com
*.espritnomade.com
fitflopsandals.com
*.fitflopsandals.com
*.app.flowbar.com
flowbar.com
*.flowbar.com
fotty.com
*.fotty.com
gerardino.com
*.gerardino.com
glaiza.com
*.glaiza.com
*.chinagoimperio.ilobasco.com
ilobasco.com
*.ilobasco.com
induk.com
*.induk.com
institutomedico.com
*.institutomedico.com
kartar.com
*.kartar.com
latoza.com
*.latoza.com
maceus.com
*.maceus.com
mangru.com
*.mangru.com
nadil.com
*.nadil.com
panyvino.com
*.panyvino.com
parqueinfantil.com
*.parqueinfantil.com
parroco.com
*.parroco.com
phimcine.com
*.phimcine.com
posguide.com
*.posguide.com
redacademica.com
*.redacademica.com
ressamlar.com
*.ressamlar.com
rizgar.com
*.rizgar.com
rucar.com
*.rucar.com
scrapbookstar.com
*.scrapbookstar.com
serramar.com
*.serramar.com
southwide.com
*.southwide.com
tetaza.com
*.tetaza.com
tuhoroscopo.com
*.tuhoroscopo.com
ucuy.com
*.ucuy.com
umpouco.com
*.umpouco.com
viaoreto.com
*.viaoreto.com
youcantstopus.com
*.youcantstopus.com
zamace.com
*.zamace.com
Other domains in certificate