Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=toscan.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 06, 2026
Valid Until
July 05, 2026 31 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5E:52:7A:6C:6A:06:92:1D:32:2F:D7:D3:86:AB:6C:E4:E8:F5:59:0B:0F:E6:27:90:6B:84:8D:8C:D8:E1:BB:1A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bluebird.it *.bluebird.it *.email.bluebird.it *.imap.bluebird.it *.mail3.bluebird.it *.mx001.bluebird.it *.newmail2013.bluebird.it *.outlook.bluebird.it *.remoteaccess.bluebird.it

Other domains in certificate

*.9b910c75-774e-48b3-99cb-8db61251755c.supervag.cz *.a7d00cab-81b9-4b99-98ee-ee65978bb5a6.supervag.cz *.access.supervag.cz *.admin.supervag.cz *.anyconnect.supervag.cz *.anywhere.supervag.cz *.api.supervag.cz *.app.supervag.cz *.apps.supervag.cz *.autodiscover.supervag.cz *.b405fc84-86af-4102-b7f8-66e4c5f913f7.supervag.cz *.backup.supervag.cz *.bi.supervag.cz *.cisapp.supervag.cz *.citrix.supervag.cz *.clientesvpn.supervag.cz *.cms.supervag.cz *.connect.supervag.cz *.data.supervag.cz *.dev.supervag.cz *.docs.supervag.cz *.dovutekp.supervag.cz *.email.supervag.cz *.exchange.supervag.cz *.gateway.supervag.cz *.gp.supervag.cz *.gwikuanyconnect.supervag.cz *.intranet.supervag.cz *.m.supervag.cz *.mail.supervag.cz *.mobile.supervag.cz *.mysql.supervag.cz *.outlook.supervag.cz *.pfghrgp.supervag.cz *.portal.supervag.cz *.ra-vpn.supervag.cz *.rdp.supervag.cz *.rds.supervag.cz *.rdweb.supervag.cz *.remote.supervag.cz *.service.supervag.cz *.shop.supervag.cz *.ssl.supervag.cz *.sslvpn.supervag.cz *.store.supervag.cz supervag.cz *.supervag.cz *.vdi.supervag.cz *.vdqzhclientesvpn.supervag.cz *.viz.supervag.cz *.vpn.supervag.cz *.vpngate.supervag.cz *.wcbhlwebvpn.supervag.cz *.webmail.supervag.cz *.webvpn.supervag.cz *.wildcard.supervag.cz *.www.supervag.cz *.xapp.supervag.cz *.xzfhndsqexvterdclientesvpn.supervag.cz *.yliimwebvpn.supervag.cz
*.ao-pisa.toscan.it *.aou-careggi.toscan.it *.art.toscan.it *.artea.toscan.it *.asf.toscan.it *.chart.toscan.it *.demo.toscan.it *.estar.toscan.it *.it.toscan.it *.mail.toscan.it *.mx.toscan.it *.qmdsimail.toscan.it *.regione.toscan.it *.rete.toscan.it *.sanita.toscan.it *.servizi.toscan.it *.srr.toscan.it *.ssr.toscan.it toscan.it *.toscan.it *.uslcentro.toscan.it