Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=commune.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 15, 2026
Valid Until
May 16, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
66:AA:3A:83:31:E7:C1:2E:F2:88:0D:76:C3:8B:A1:AC:8D:D7:4D:80:2F:89:E6:3E:48:35:C4:78:1D:D5:54:05
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
commune.it *.commune.it

Other domains in certificate

18avmm.com *.18avmm.com *.com-www.18avmm.com *.help.18avmm.com
ca5u5.com *.ca5u5.com
*.analytic.calciostreaming.live *.app.calciostreaming.live calciostreaming.live *.calciostreaming.live *.chart.calciostreaming.live *.remoteaccess.calciostreaming.live *.supersets.calciostreaming.live
cofin.it *.cofin.it
comborangers.com *.comborangers.com
conducts.it *.conducts.it
consulentedelrisparmio.it *.consulentedelrisparmio.it
corporateventure.it *.corporateventure.it
crunching.it *.crunching.it
decuplo.it *.decuplo.it
*.admin.deepfunds.org *.api.deepfunds.org *.app.deepfunds.org deepfunds.org *.deepfunds.org *.dev.deepfunds.org *.m.deepfunds.org *.www.deepfunds.org
dendo.it *.dendo.it
dentalmarket.it *.dentalmarket.it
digitalmedialab.it *.digitalmedialab.it
dioro.it *.dioro.it
lowcostpraga.it *.lowcostpraga.it
mason-near-me.click *.mason-near-me.click
mmabet.love *.mmabet.love
musicbands.it *.musicbands.it
mybottle.it *.mybottle.it
ngoti.net *.ngoti.net
nndxn.bid *.nndxn.bid
olla.it *.olla.it
papafrancisco.it *.papafrancisco.it
*.aaf.photoproevent.com *.anae.photoproevent.com *.blog.photoproevent.com *.clients.photoproevent.com *.mail.photoproevent.com photoproevent.com *.photoproevent.com *.relay.photoproevent.com *.sncf.photoproevent.com *.ww25.photoproevent.com
pioneerbikestop.com *.pioneerbikestop.com
pjojo.pro *.pjojo.pro
prezzooriginale.it *.prezzooriginale.it
qualityfoodservice.it *.qualityfoodservice.it
repubblicadellebanane.it *.repubblicadellebanane.it
retepuglia.it *.retepuglia.it
roomonline.it *.roomonline.it
spasser.com *.spasser.com