Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=toscan.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 06, 2026
Valid Until
July 05, 2026
31 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5E:52:7A:6C:6A:06:92:1D:32:2F:D7:D3:86:AB:6C:E4:E8:F5:59:0B:0F:E6:27:90:6B:84:8D:8C:D8:E1:BB:1A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
bluebird.it
*.bluebird.it
*.email.bluebird.it
*.imap.bluebird.it
*.mail3.bluebird.it
*.mx001.bluebird.it
*.newmail2013.bluebird.it
*.outlook.bluebird.it
*.remoteaccess.bluebird.it
*.9b910c75-774e-48b3-99cb-8db61251755c.supervag.cz
*.a7d00cab-81b9-4b99-98ee-ee65978bb5a6.supervag.cz
*.access.supervag.cz
*.admin.supervag.cz
*.anyconnect.supervag.cz
*.anywhere.supervag.cz
*.api.supervag.cz
*.app.supervag.cz
*.apps.supervag.cz
*.autodiscover.supervag.cz
*.b405fc84-86af-4102-b7f8-66e4c5f913f7.supervag.cz
*.backup.supervag.cz
*.bi.supervag.cz
*.cisapp.supervag.cz
*.citrix.supervag.cz
*.clientesvpn.supervag.cz
*.cms.supervag.cz
*.connect.supervag.cz
*.data.supervag.cz
*.dev.supervag.cz
*.docs.supervag.cz
*.dovutekp.supervag.cz
*.email.supervag.cz
*.exchange.supervag.cz
*.gateway.supervag.cz
*.gp.supervag.cz
*.gwikuanyconnect.supervag.cz
*.intranet.supervag.cz
*.m.supervag.cz
*.mail.supervag.cz
*.mobile.supervag.cz
*.mysql.supervag.cz
*.outlook.supervag.cz
*.pfghrgp.supervag.cz
*.portal.supervag.cz
*.ra-vpn.supervag.cz
*.rdp.supervag.cz
*.rds.supervag.cz
*.rdweb.supervag.cz
*.remote.supervag.cz
*.service.supervag.cz
*.shop.supervag.cz
*.ssl.supervag.cz
*.sslvpn.supervag.cz
*.store.supervag.cz
supervag.cz
*.supervag.cz
*.vdi.supervag.cz
*.vdqzhclientesvpn.supervag.cz
*.viz.supervag.cz
*.vpn.supervag.cz
*.vpngate.supervag.cz
*.wcbhlwebvpn.supervag.cz
*.webmail.supervag.cz
*.webvpn.supervag.cz
*.wildcard.supervag.cz
*.www.supervag.cz
*.xapp.supervag.cz
*.xzfhndsqexvterdclientesvpn.supervag.cz
*.yliimwebvpn.supervag.cz
*.ao-pisa.toscan.it
*.aou-careggi.toscan.it
*.art.toscan.it
*.artea.toscan.it
*.asf.toscan.it
*.chart.toscan.it
*.demo.toscan.it
*.estar.toscan.it
*.it.toscan.it
*.mail.toscan.it
*.mx.toscan.it
*.qmdsimail.toscan.it
*.regione.toscan.it
*.rete.toscan.it
*.sanita.toscan.it
*.servizi.toscan.it
*.srr.toscan.it
*.ssr.toscan.it
toscan.it
*.toscan.it
*.uslcentro.toscan.it
Other domains in certificate