Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=starthobby.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 24, 2026
Valid Until
July 23, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CA:55:EC:9B:9E:EA:7B:E3:64:BB:E7:8D:87:4B:E6:8D:EB:45:EA:4B:BB:54:B7:9D:06:DD:C7:32:7F:13:B1:28
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
germano.gr *.germano.gr *.15e13b9c-8b28-436b-be03-f293e6325602.germano.gr *.admin.germano.gr *.asa.germano.gr *.bdo.germano.gr *.bi.germano.gr *.checkin.germano.gr *.console.germano.gr *.correo.germano.gr *.cpanel.germano.gr *.cpcalendars.germano.gr *.crm.germano.gr *.customers.germano.gr *.data.germano.gr *.egwlusmail.germano.gr *.email.germano.gr *.ex02.germano.gr *.exchange.germano.gr *.exchangecorp.germano.gr *.exmail2.germano.gr *.fortinet.germano.gr *.gcpmeruh.germano.gr *.hq.germano.gr *.intelligence.germano.gr *.kbfdosvg.germano.gr *.leads.germano.gr *.mail.germano.gr *.mail3.germano.gr *.mcorreu.germano.gr *.mmymail.germano.gr *.mobile.germano.gr *.msexch2k13.germano.gr *.mx001.germano.gr *.mymail.germano.gr *.mywebmail.germano.gr *.nawzmpyg.germano.gr *.newmail2013.germano.gr *.notexistsexchange.germano.gr *.notexistsexchmail.germano.gr *.notexistsnewmail2013.germano.gr *.notexistsogrencieposta.germano.gr *.notexistsremote.germano.gr *.notexistswebmail05.germano.gr *.notexistswebmail2013.germano.gr *.ogrencieposta.germano.gr *.one.germano.gr *.rdg.germano.gr *.rds.germano.gr *.rds1.germano.gr *.rdsmum.germano.gr *.remoteapps.germano.gr *.sharepoint.germano.gr *.smail.germano.gr *.taidtpilntkqf.germano.gr *.ucuxeapp.germano.gr *.uewpzmax.germano.gr *.webmail.germano.gr *.www.germano.gr *.ya.germano.gr

Other domains in certificate

*.admin.starthobby.com *.api.starthobby.com *.app.starthobby.com *.backup.starthobby.com *.cloud.starthobby.com *.dashboard.starthobby.com *.data.starthobby.com *.demo.starthobby.com *.dev.starthobby.com *.formation.starthobby.com *.hostmaster.starthobby.com *.m.starthobby.com *.marketing.starthobby.com *.rd.starthobby.com *.rds.starthobby.com *.rdweb.starthobby.com *.remote.starthobby.com *.secure.starthobby.com *.shop.starthobby.com *.sitemap.starthobby.com *.sitemaps.starthobby.com *.staging.starthobby.com starthobby.com *.starthobby.com *.stg.starthobby.com *.vacgqbackup.starthobby.com *.web.starthobby.com *.wevafvacgqbackup.starthobby.com *.wildcard.starthobby.com