76/100 SECURITY SCORE

Certificate Information

Subject
CN=fitnesspros.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 14, 2026
Valid Until
July 13, 2026 34 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D1:D7:16:F7:39:5B:94:C7:90:BB:0F:33:17:B6:9D:8E:5D:74:D0:72:8B:D1:BB:02:00:AE:E2:9B:43:E0:0F:B6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

87 domains
createyourmood.it *.createyourmood.it *.aa.createyourmood.it *.admin.createyourmood.it *.ae.createyourmood.it *.af.createyourmood.it *.ah.createyourmood.it *.ai.createyourmood.it *.al.createyourmood.it *.am.createyourmood.it *.api.createyourmood.it *.app.createyourmood.it *.backend.createyourmood.it *.bb.createyourmood.it *.bk.createyourmood.it *.bo.createyourmood.it *.cb.createyourmood.it *.cc.createyourmood.it *.ck.createyourmood.it *.cl.createyourmood.it *.cr.createyourmood.it *.cu.createyourmood.it *.dashboard.createyourmood.it *.db.createyourmood.it *.dc.createyourmood.it *.de.createyourmood.it *.dev.createyourmood.it *.df.createyourmood.it *.dg.createyourmood.it *.ds.createyourmood.it *.ec.createyourmood.it *.postmaster.createyourmood.it *.qa-agent.createyourmood.it *.qa.createyourmood.it *.securesmtp.createyourmood.it *.staging.createyourmood.it *.www.createyourmood.it

Other domains in certificate

*.65e8129d-8d8a-4d4e-960a-1e7d54f30475.fitnesspros.xyz *.app.fitnesspros.xyz *.assets.fitnesspros.xyz *.autodiscover.fitnesspros.xyz *.c47a4861-77c2-4122-9bdb-0fb15169a821.fitnesspros.xyz *.cac0e77a-d846-4f68-8ca1-c8163c0a032b.fitnesspros.xyz *.cpanel.fitnesspros.xyz *.d.fitnesspros.xyz *.dashboard.fitnesspros.xyz *.dpqbkebmail.fitnesspros.xyz *.ebmail.fitnesspros.xyz fitnesspros.xyz *.fitnesspros.xyz *.gpt.fitnesspros.xyz *.hs1.fitnesspros.xyz *.m.fitnesspros.xyz *.mail.fitnesspros.xyz *.marketing.fitnesspros.xyz *.mta-sts.fitnesspros.xyz *.notexistsautodiscover.fitnesspros.xyz *.notexistswebdisk.fitnesspros.xyz *.qa.fitnesspros.xyz *.remote.fitnesspros.xyz *.sandbox.fitnesspros.xyz *.secure.fitnesspros.xyz *.sitemap.fitnesspros.xyz *.sitemaps.fitnesspros.xyz *.stg.fitnesspros.xyz *.tpxvlqa.fitnesspros.xyz *.uat.fitnesspros.xyz *.webdisk.fitnesspros.xyz *.webmail.fitnesspros.xyz *.whymasitemaps.fitnesspros.xyz *.www.fitnesspros.xyz
*.91272f44-d3ae-4d9f-9622-69ebb01c8f56.mup88.tv *.admin.mup88.tv *.api.mup88.tv *.app.mup88.tv *.arca.mup88.tv *.assets.mup88.tv *.demo.mup88.tv *.dev.mup88.tv *.ekmgcgucbvuidladev.mup88.tv *.mail.mup88.tv mup88.tv *.mup88.tv *.test.mup88.tv *.uidladev.mup88.tv
wigannews.co.uk *.wigannews.co.uk