76/100 SECURITY SCORE

Certificate Information

Subject
CN=caslino.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 22, 2026
Valid Until
August 20, 2026 58 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
59:B0:4C:FC:9E:D9:50:92:E5:76:66:7E:D1:3F:21:2F:25:52:A6:7E:88:36:C7:0B:69:25:1F:0B:54:50:6C:3A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
bluemade.it *.bluemade.it *.backend.bluemade.it *.chart.bluemade.it *.demo.bluemade.it *.relay.bluemade.it *.reporting.bluemade.it *.summary.bluemade.it

Other domains in certificate

*.analytics.arius.it *.api.arius.it *.app.arius.it arius.it *.arius.it *.backend.arius.it *.demo.arius.it *.dev.arius.it *.hostmaster.arius.it *.mail.arius.it *.report.arius.it *.rot.arius.it *.staging.arius.it
caslino.it *.caslino.it *.hostmaster.caslino.it
disoriented.it *.disoriented.it *.mx.disoriented.it
doxpoint.it *.doxpoint.it *.pop.doxpoint.it *.www.doxpoint.it
elpadre.it *.elpadre.it *.hostmaster.elpadre.it *.owa.elpadre.it
*.analytic.flightseurope.it *.api.flightseurope.it *.app.flightseurope.it *.demo.flightseurope.it flightseurope.it *.flightseurope.it
*.hostmaster.ilos.it ilos.it *.ilos.it *.mta-sts.ilos.it *.venezia.ilos.it
lightmusic.it *.lightmusic.it *.remote.lightmusic.it
*.cloud.mainpartners.it *.email.mainpartners.it *.globalprotect.mainpartners.it *.imap4.mainpartners.it mainpartners.it *.mainpartners.it *.pop.mainpartners.it *.pop3.mainpartners.it *.portal.mainpartners.it *.rd.mainpartners.it *.smtp.mainpartners.it
*.hostmaster.tentacles.it tentacles.it *.tentacles.it
*.admin.throwrug.it *.analytics.throwrug.it *.api.throwrug.it *.dashboards.throwrug.it *.demo.throwrug.it *.dev.throwrug.it *.intranet.throwrug.it *.metric.throwrug.it *.reporting.throwrug.it *.reports.throwrug.it *.superset.throwrug.it throwrug.it *.throwrug.it *.uat.throwrug.it *.www.throwrug.it
*.admin.tipro.it *.chart.tipro.it *.dashboards.tipro.it *.demo.tipro.it *.hostmaster.tipro.it *.report.tipro.it *.reports.tipro.it *.superset.tipro.it tipro.it *.tipro.it
uptospeed.it *.uptospeed.it