Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=spotloan.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026 39 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
84:52:11:70:9B:16:F5:CC:63:53:85:90:19:54:1A:A6:F6:E4:4D:29:87:24:DD:A0:46:59:C1:1A:9C:E6:A6:7E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
florana.it *.florana.it *.admin.florana.it *.app.florana.it *.backend.florana.it *.dash.florana.it *.dashboards.florana.it *.dashs.florana.it *.demo.florana.it *.dev.florana.it *.prod.florana.it *.redash.florana.it *.staging.florana.it *.summary.florana.it *.superset.florana.it

Other domains in certificate

268537.top *.268537.top
*.caixa.digitalinfo.fun digitalinfo.fun *.digitalinfo.fun *.fun.digitalinfo.fun
eden-enchanted.com *.eden-enchanted.com
*.api.flatirron.com *.assets.flatirron.com *.cloud.flatirron.com *.demo.flatirron.com *.dev.flatirron.com flatirron.com *.flatirron.com *.rds.flatirron.com *.rdweb.flatirron.com *.remote.flatirron.com *.shop.flatirron.com *.test.flatirron.com
homero.me *.homero.me
ipiuamati.com *.ipiuamati.com
jccmdi226.asia *.jccmdi226.asia *.sitemap.jccmdi226.asia
*.bbs.kuvaz.com kuvaz.com *.kuvaz.com *.ww38.kuvaz.com
*.55750a89-f75c-4352-a7ea-4d881fb0ee15.skypey.quest *.admin.skypey.quest *.app.skypey.quest *.assets.skypey.quest *.c224e305-f132-43ce-b590-5cd1c1e19084.skypey.quest *.demo.skypey.quest *.dev.skypey.quest *.finance.skypey.quest *.hostmaster.skypey.quest *.rustore.skypey.quest skypey.quest *.skypey.quest *.test.skypey.quest
*.7a6b7aa0-a0e4-4988-aad2-70a9313e75c8.spotloan.co *.8a716461-9508-44d7-a430-231f5d4136dc.spotloan.co *.a115244c-61fb-47ff-b9ef-d905a3504646.spotloan.co *.apply.spotloan.co *.autodiscover.spotloan.co *.backup.spotloan.co *.beta.spotloan.co *.blog.spotloan.co *.crm.spotloan.co *.demo.spotloan.co *.e193e2cc-9f99-4c5d-9c86-d216badfc97e.spotloan.co *.emv1.spotloan.co *.forum.spotloan.co *.forums.spotloan.co *.help.spotloan.co *.m.spotloan.co *.mail.spotloan.co *.new.spotloan.co *.old.spotloan.co *.payment.spotloan.co *.remote.spotloan.co *.shop.spotloan.co spotloan.co *.spotloan.co *.store.spotloan.co *.temp.spotloan.co *.test.spotloan.co *.wiki.spotloan.co *.wmihxjlp.spotloan.co *.www.spotloan.co