Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=loredane.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 24, 2026
Valid Until
May 25, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B3:9D:1C:61:59:26:BB:53:C2:2A:17:3A:02:75:4E:93:BC:75:21:58:9A:C1:B8:5C:A1:E5:27:A1:88:A1:DF:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
brochet.com *.brochet.com

Other domains in certificate

bigbabyboss.com *.bigbabyboss.com *.sitemaps.bigbabyboss.com *.www.bigbabyboss.com
boldtravelquests.live *.boldtravelquests.live
branno.com *.branno.com
brightgroveglobal.com *.brightgroveglobal.com
brighttravelvistas.live *.brighttravelvistas.live
brightweddingsconcepts.beauty *.brightweddingsconcepts.beauty
brindleberry.com *.brindleberry.com
broadoaks.com *.broadoaks.com
*.api-prod.chicago.vip *.app.chicago.vip *.assets.chicago.vip *.bigquery.chicago.vip *.cdn-stage.chicago.vip chicago.vip *.chicago.vip *.ci-cd.chicago.vip *.docker.chicago.vip *.email.chicago.vip *.expo.chicago.vip *.graphql.chicago.vip *.health.chicago.vip *.healthcheck.chicago.vip *.hgs.chicago.vip *.hostmaster.chicago.vip *.kube.chicago.vip *.scripts.chicago.vip *.vpn.chicago.vip *.zanies.chicago.vip
consolidationguide.com *.consolidationguide.com *.remote.consolidationguide.com
karsbasrc.biz *.karsbasrc.biz
lacuevana.biz *.lacuevana.biz
*.admin.lazy.money *.api.lazy.money *.app.lazy.money *.autodiscover.lazy.money *.email.lazy.money *.exchange.lazy.money *.intranet.lazy.money lazy.money *.lazy.money *.mail.lazy.money *.mail1.lazy.money *.mail2.lazy.money *.mx.lazy.money *.not.lazy.money *.outlook.lazy.money *.owa.lazy.money *.portal.lazy.money *.remote.lazy.money *.shop.lazy.money *.smtp.lazy.money *.store.lazy.money *.www.lazy.money
*.demo.loredane.it loredane.it *.loredane.it
merahtoto.cc *.merahtoto.cc
setotoro.com *.setotoro.com
*.cpcontacts.surgimac.us *.mail.surgimac.us *.old.surgimac.us surgimac.us *.surgimac.us *.webdisk.surgimac.us *.ww25.surgimac.us
urlsaver.work *.urlsaver.work *.ww25.urlsaver.work
*.intranet.xn--sadenotempreo-0eb1euq.com *.vpn.xn--sadenotempreo-0eb1euq.com xn--sadenotempreo-0eb1euq.com *.xn--sadenotempreo-0eb1euq.com