76/100 SECURITY SCORE

Certificate Information

Subject
CN=glav.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 17, 2026
Valid Until
May 18, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:EA:10:F1:9C:E0:17:C9:0F:1F:B7:70:57:3B:69:05:58:88:38:F4:25:D2:66:2E:BD:48:D0:BE:D3:8D:A1:C8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
affiliate-program-amazon.com *.affiliate-program-amazon.com *.jenkins.affiliate-program-amazon.com *.ww38.affiliate-program-amazon.com

Other domains in certificate

aardvarkfloorservices.com.au *.aardvarkfloorservices.com.au *.mail.aardvarkfloorservices.com.au
bgplanetbola88.xyz *.bgplanetbola88.xyz *.kwid9.bgplanetbola88.xyz *.lbcp6.bgplanetbola88.xyz *.nxc75.bgplanetbola88.xyz *.pwb3b.bgplanetbola88.xyz *.rczhl.bgplanetbola88.xyz *.yhue2.bgplanetbola88.xyz
*.apk.bolu777.org bolu777.org *.bolu777.org
classyshark.com *.classyshark.com
chh.co.in *.chh.co.in *.in.chh.co.in *.sitemap.chh.co.in *.ticrunotexistsprimary.chh.co.in
*.adguard.dmikn.net dmikn.net *.dmikn.net
esbet24.com *.esbet24.com *.hostmaster.esbet24.com
glav.it *.glav.it *.rd.glav.it *.uat.glav.it
*.hostmaster.iceskaterental.com iceskaterental.com *.iceskaterental.com
injectionmouldingproducts.com *.injectionmouldingproducts.com *.korean.injectionmouldingproducts.com *.ww25.injectionmouldingproducts.com
marinaio.net *.marinaio.net
montacarichidacantiere.com *.montacarichidacantiere.com
montrespascher.fr *.montrespascher.fr
mpl-studios.org *.mpl-studios.org
nkr.com.au *.nkr.com.au *.ww25.nkr.com.au
ohcourts.us *.ohcourts.us *.random.ohcourts.us
*.hostmaster.replacenents.com replacenents.com *.replacenents.com *.www.replacenents.com
*.598b2de5-7e29-40b2-944f-22fe049323ab.situsgokil168.sbs *.cpanel.situsgokil168.sbs *.localhost.situsgokil168.sbs *.pop.situsgokil168.sbs situsgokil168.sbs *.situsgokil168.sbs *.smtp.situsgokil168.sbs *.webmail.situsgokil168.sbs
smartinvenstments.store *.smartinvenstments.store *.ww25.smartinvenstments.store
*.outlook.tudien.me tudien.me *.tudien.me
*.cpanel.voicegulf.com *.m.voicegulf.com *.mailer.voicegulf.com *.uat.voicegulf.com voicegulf.com *.voicegulf.com *.vpvdjqa.voicegulf.com *.web.voicegulf.com *.www.voicegulf.com
*.mail.wilkes.it wilkes.it *.wilkes.it *.www.wilkes.it
winairairlines.com *.winairairlines.com