76/100 SECURITY SCORE

Certificate Information

Subject
CN=noblesky.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 13, 2026
Valid Until
May 14, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
16:0C:5C:8A:F4:52:33:1E:9D:9A:1F:C6:41:42:3F:AA:21:93:F9:75:59:BA:40:31:F8:DE:D8:D9:C7:8C:D0:04
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
wentylacja.com *.wentylacja.com *.api.wentylacja.com *.dev.wentylacja.com *.hostmaster.wentylacja.com *.mail.wentylacja.com *.random.wentylacja.com *.sitemap.wentylacja.com *.sitemaps.wentylacja.com *.test.wentylacja.com *.ww16.wentylacja.com *.ww25.wentylacja.com *.www.wentylacja.com

Other domains in certificate

*.admin.covarrubia.com *.api.covarrubia.com *.app.covarrubia.com covarrubia.com *.covarrubia.com *.email.covarrubia.com *.exchange.covarrubia.com *.ftp.covarrubia.com *.gitlab.covarrubia.com *.hostmaster.covarrubia.com *.imap1.covarrubia.com *.m.covarrubia.com *.mcrnlgitlab.covarrubia.com *.mx2.covarrubia.com *.postmaster.covarrubia.com *.relay.covarrubia.com *.shop.covarrubia.com *.smtp.covarrubia.com *.smtp2.covarrubia.com *.smtpauth.covarrubia.com *.smtps.covarrubia.com *.staging.covarrubia.com *.test.covarrubia.com *.webmail.covarrubia.com *.ww17.covarrubia.com *.ww38.covarrubia.com *.ww41.covarrubia.com
*.api.kenshi.net *.client.kenshi.net *.forum.kenshi.net *.forums.kenshi.net *.gateway.kenshi.net *.hostmaster.kenshi.net kenshi.net *.kenshi.net *.login.kenshi.net *.mail.kenshi.net *.mailer.kenshi.net *.marketing.kenshi.net *.mobile.kenshi.net *.office.kenshi.net *.portal.kenshi.net *.rebel.kenshi.net *.remoteaccess.kenshi.net *.scorpiosemotion.kenshi.net *.sitemap.kenshi.net *.ssl.kenshi.net *.sslvpn.kenshi.net *.staging.kenshi.net *.stg.kenshi.net *.uat.kenshi.net *.v1.kenshi.net *.v2.kenshi.net *.vpn1.kenshi.net *.vpn2.kenshi.net *.webconnect.kenshi.net *.webmail.kenshi.net *.webvpn.kenshi.net *.wildcard.kenshi.net *.ww1.kenshi.net *.ww16.kenshi.net
*.help.noblesky.com *.m.noblesky.com noblesky.com *.noblesky.com *.store.noblesky.com *.wildcard.noblesky.com
spruik.com.au *.spruik.com.au
*.bbs.traslochicase.com traslochicase.com *.traslochicase.com
*.aac.wheelchairs.me *.c535be74-8993-429a-9d27-eeaf05f8a6dd.wheelchairs.me *.hostmaster.wheelchairs.me wheelchairs.me *.wheelchairs.me