76/100 SECURITY SCORE

Certificate Information

Subject
CN=diagnoaq.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 15, 2026
Valid Until
August 13, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
22:CB:24:2E:F8:F6:33:A5:AC:B1:7F:21:2F:64:88:A4:CF:B4:8E:7B:11:C6:BD:A5:AF:EC:B6:63:D0:6A:EC:40
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
boostdigitalia.space *.boostdigitalia.space *.951d848f-76c7-43cd-aaee-0e5cef268954.boostdigitalia.space *.admin.boostdigitalia.space *.aging.boostdigitalia.space *.api.boostdigitalia.space *.app.boostdigitalia.space *.assets.boostdigitalia.space *.auwnrver.boostdigitalia.space *.b.boostdigitalia.space *.backup.boostdigitalia.space *.cure.boostdigitalia.space *.dashboard.boostdigitalia.space *.dev.boostdigitalia.space *.g.boostdigitalia.space *.lr14h.boostdigitalia.space *.mail.boostdigitalia.space *.marketing.boostdigitalia.space *.qa.boostdigitalia.space *.rver.boostdigitalia.space *.secure.boostdigitalia.space *.server.boostdigitalia.space *.slr14h.boostdigitalia.space *.staging.boostdigitalia.space *.vps.boostdigitalia.space *.web.boostdigitalia.space

Other domains in certificate

99zybo.com *.99zybo.com *.video.99zybo.com *.ww38.99zybo.com
a225crxy.top *.a225crxy.top *.b54zj.a225crxy.top *.jxc88.a225crxy.top *.kac0t.a225crxy.top *.l8kqx.a225crxy.top *.z4r76.a225crxy.top
adrooms.com *.adrooms.com *.app.adrooms.com *.intranet.adrooms.com
canlimaclar46.site *.canlimaclar46.site *.ww16.canlimaclar46.site *.www.canlimaclar46.site
diagnoaq.com *.diagnoaq.com *.oni34e.diagnoaq.com
*.cpanel.discipline.studio *.dc-a7ec19a8a86c.discipline.studio *.dev.discipline.studio discipline.studio *.discipline.studio *.staging.discipline.studio *.webmail.discipline.studio
ekoo-shop.de *.ekoo-shop.de
*.appacademy.itvasity.org itvasity.org *.itvasity.org *.mysite.itvasity.org
*.blog.mustlookhere.com *.com--www.mustlookhere.com *.comsuslwww.mustlookhere.com *.files.mustlookhere.com *.final.mustlookhere.com *.httpwww.mustlookhere.com mustlookhere.com *.mustlookhere.com *.ns2.mustlookhere.com *.w.mustlookhere.com *.ww.mustlookhere.com *.ww25.mustlookhere.com *.ww38.mustlookhere.com *.wwwwww.mustlookhere.com
*.api.schuylkillriver.com *.dev.schuylkillriver.com *.mail.schuylkillriver.com schuylkillriver.com *.schuylkillriver.com *.test.schuylkillriver.com *.ww25.schuylkillriver.com *.ww38.schuylkillriver.com
*.32.smmall.pro smmall.pro *.smmall.pro *.ww25.smmall.pro
*.ns2.v-r.app v-r.app *.v-r.app