76/100 SECURITY SCORE

Certificate Information

Subject
CN=xn--4xxw72a.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 25, 2026
Valid Until
July 24, 2026 62 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9C:38:A5:8D:95:07:CD:04:89:AD:54:97:41:0B:01:4F:20:7D:C0:DA:42:18:2A:2F:9C:49:5C:B4:CF:0F:C8:6E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
organizzata.com *.organizzata.com *.admin.organizzata.com *.api.organizzata.com *.app.organizzata.com *.backend.organizzata.com *.bi.organizzata.com *.dash.organizzata.com *.dashboard.organizzata.com *.dashs.organizzata.com *.demo.organizzata.com *.intelligence.organizzata.com *.redash.organizzata.com *.remote.organizzata.com *.workflow.organizzata.com

Other domains in certificate

*.291a6794-b9e8-452c-a674-2c8117559909.bond.ad *.3g.bond.ad *.a.bond.ad *.a4beab63-3d59-4efa-92a2-899fbc61f6a0.bond.ad *.admin.bond.ad *.api.bond.ad *.app.bond.ad *.assets.bond.ad *.b514a4db-ca06-4011-bcbf-f898d21781d7.bond.ad *.backend.bond.ad *.blog.bond.ad bond.ad *.bond.ad *.box.bond.ad *.chat.bond.ad *.demo.bond.ad *.dev.bond.ad *.ekqxxnews.bond.ad *.en.bond.ad *.f0e87605-46e3-4825-99f4-c6b19aeb3360.bond.ad *.fr.bond.ad *.ftp.bond.ad *.gateway.bond.ad *.gitlab.bond.ad *.glpi.bond.ad *.hostmaster.bond.ad *.ipv6.bond.ad *.jzefexzoufnew.bond.ad *.laravel.bond.ad *.mail01.bond.ad *.mobile.bond.ad *.mta.bond.ad *.mx01.bond.ad *.mx1.bond.ad *.my.bond.ad *.new.bond.ad *.news.bond.ad *.postmaster.bond.ad *.server.bond.ad *.server2.bond.ad *.sip.bond.ad *.smtp.bond.ad *.staging.bond.ad *.status.bond.ad *.studant.bond.ad *.support.bond.ad *.test.bond.ad *.vopvaassets.bond.ad *.wiki.bond.ad *.ww7.bond.ad *.www.bond.ad *.xzoufnew.bond.ad *.zjmqphdt.bond.ad
*.1ce8d0bb-cc29-4f4b-9dc9-e30906d9ea97.offpeakdining.com *.439d2a4c-99a7-4aa4-b6cc-86962b74490d.offpeakdining.com *.8cd7872f-ce18-4321-bb2d-3928cd573035.offpeakdining.com *.a.offpeakdining.com *.admin.offpeakdining.com *.api.offpeakdining.com *.app.offpeakdining.com *.assets.offpeakdining.com *.backup.offpeakdining.com *.demo.offpeakdining.com *.dev.offpeakdining.com offpeakdining.com *.offpeakdining.com *.server.offpeakdining.com *.staging.offpeakdining.com *.test.offpeakdining.com *.uat.offpeakdining.com *.vps.offpeakdining.com
*.m.xn--4xxw72a.com xn--4xxw72a.com *.xn--4xxw72a.com