Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=honghuo-y9mf7.sbs
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E7:95:B8:9C:AA:19:3B:14:D5:2F:CA:21:44:FE:55:5E:17:AC:E2:5E:AC:BC:C2:8B:72:4C:85:9C:77:CF:64:94
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
cyano.it
*.cyano.it
conson.it
*.conson.it
corr-eios.pro
*.corr-eios.pro
countertop.it
*.countertop.it
croccantini.it
*.croccantini.it
cubanos.it
*.cubanos.it
curandero.it
*.curandero.it
dalili.it
*.dalili.it
dalmare.it
*.dalmare.it
danida.it
*.danida.it
decorazioniartistiche.it
*.decorazioniartistiche.it
deltaprojects.it
*.deltaprojects.it
descripto.it
*.descripto.it
dimadvanced.com
*.dimadvanced.com
disfrazdepayaso.com
*.disfrazdepayaso.com
dokter77.com
*.dokter77.com
downland.it
*.downland.it
dralin.com
*.dralin.com
e5438310.vip
*.e5438310.vip
envidia.it
*.envidia.it
everycom.it
*.everycom.it
expressway.it
*.expressway.it
fahad.it
*.fahad.it
familytrip.it
*.familytrip.it
fastbody.it
*.fastbody.it
finanziamentorata.it
*.finanziamentorata.it
fireoff.it
*.fireoff.it
fitnessunitycentral.run
*.fitnessunitycentral.run
fitsmart.it
*.fitsmart.it
fuggitivo.it
*.fuggitivo.it
gell.it
*.gell.it
getsmarter.it
*.getsmarter.it
gettrinion.com
*.gettrinion.com
ghzks.net
*.ghzks.net
goldshop.it
*.goldshop.it
goot.it
*.goot.it
goure.it
*.goure.it
green-roofs-147973929.click
*.green-roofs-147973929.click
greeneyes.it
*.greeneyes.it
hamsik.it
*.hamsik.it
hebrewcalendar.it
*.hebrewcalendar.it
helloprivatelabelbeauty.com
*.helloprivatelabelbeauty.com
honghuo-y9mf7.sbs
*.honghuo-y9mf7.sbs
hots.it
*.hots.it
*.mail.hots.it
Other domains in certificate