Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=cnm.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 07, 2026
Valid Until
May 08, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FB:70:D0:7C:9F:4C:F0:9E:BF:1A:EA:07:A5:00:42:A4:59:CC:E3:69:BC:ED:9B:A9:08:82:5C:C4:A2:1B:4F:ED
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
baki.net
*.baki.net
*.wildcard.baki.net
ballena.de
*.ballena.de
*.dash.ballena.de
beddingkits.com
*.beddingkits.com
*.image.beddingkits.com
*.azzurra.cnm.it
cnm.it
*.cnm.it
*.ap-guangzhou.edargingre.club
edargingre.club
*.edargingre.club
*.eu.edargingre.club
*.ww25.edargingre.club
*.api.elsalsero.it
elsalsero.it
*.elsalsero.it
genuinekeyhome.com
*.genuinekeyhome.com
gestioneaffitto.it
*.gestioneaffitto.it
*.mx.gestioneaffitto.it
*.beta.greatlakesrehab.com
greatlakesrehab.com
*.greatlakesrehab.com
*.mx.greatlakesrehab.com
*.t.greatlakesrehab.com
*.ww38.greatlakesrehab.com
gthkdlking.top
*.gthkdlking.top
*.bi.harddarkness.xyz
*.flowise.harddarkness.xyz
*.ftp.harddarkness.xyz
harddarkness.xyz
*.harddarkness.xyz
*.ns1.harddarkness.xyz
*.ww25.harddarkness.xyz
*.www.harddarkness.xyz
harslly.com
*.harslly.com
*.business.inflow.biz
inflow.biz
*.inflow.biz
italianbuilding.it
*.italianbuilding.it
*.login.italianbuilding.it
*.com.machabyouthproject.org
machabyouthproject.org
*.machabyouthproject.org
*.box.mackmytrip.com
mackmytrip.com
*.mackmytrip.com
*.demo.multiproprieta.com
multiproprieta.com
*.multiproprieta.com
*.vpn.multiproprieta.com
*.ww38.multiproprieta.com
*.kwid9.mythhub.top
mythhub.top
*.mythhub.top
*.vizaseq.mythhub.top
qlq.au
*.qlq.au
*.ww25.qlq.au
*.http.rankar.com
rankar.com
*.rankar.com
*.outlook.rebsamen.com
rebsamen.com
*.rebsamen.com
*.luckytextile.uat.biz
uat.biz
*.uat.biz
*.demo.yourdesire.it
yourdesire.it
*.yourdesire.it
*.g.zxez.com
*.gf.zxez.com
*.mx02.zxez.com
*.pr.zxez.com
*.server.zxez.com
*.store.zxez.com
*.w.zxez.com
*.ww25.zxez.com
*.zimbra.zxez.com
zxez.com
*.zxez.com
Other domains in certificate