76/100 SECURITY SCORE

Certificate Information

Subject
CN=intimate.so
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 23, 2026
Valid Until
July 22, 2026 70 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C6:94:45:C9:F5:C7:00:33:1D:92:23:70:DB:E2:86:75:5C:CD:85:7D:33:AF:F1:48:01:9E:E4:C6:1E:52:47:B1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
collectionmanagement.it *.collectionmanagement.it *.admin.collectionmanagement.it *.api.collectionmanagement.it *.backend.collectionmanagement.it *.data.collectionmanagement.it *.dev.collectionmanagement.it *.development.collectionmanagement.it *.forecast.collectionmanagement.it *.preview.collectionmanagement.it *.staging.collectionmanagement.it *.superset.collectionmanagement.it

Other domains in certificate

*.468af76d-024c-4b06-a93f-5a69c9f7103d.9sport.media *.6a680f5f-ce32-45d9-a0b0-cd0f67f19946.9sport.media 9sport.media *.9sport.media *.admin.9sport.media *.af77b164-d699-4e42-b774-50c48a5984ac.9sport.media *.app.9sport.media *.assets.9sport.media *.demo.9sport.media *.dev.9sport.media *.external.9sport.media *.intranet.9sport.media *.portal.9sport.media *.public.9sport.media *.sharepoint.9sport.media *.staging.9sport.media *.test.9sport.media *.vps.9sport.media
*.32.betist1345.com *.bet.betist1345.com betist1345.com *.betist1345.com *.vpn.betist1345.com *.ww38.betist1345.com
*.ichat.intimate.so intimate.so *.intimate.so *.sitemap.intimate.so
*.abaf438.nmccpgl.top nmccpgl.top *.nmccpgl.top
*.blog.porno-tube.it porno-tube.it *.porno-tube.it *.relay.porno-tube.it
*.m.secretsphinx.io secretsphinx.io *.secretsphinx.io
ticketpoint.co *.ticketpoint.co *.www.ticketpoint.co
*.1b3d2b6f-9ffc-4e6f-a9c6-07e975b37213.twtz.net *.45db9fc7-9835-45de-903a-c4c062dbba4b.twtz.net *.4934e438-8820-4cc8-b43b-2d49914d7151.twtz.net *.account.twtz.net *.app.twtz.net *.arch4.twtz.net *.arch5.twtz.net *.arch6.twtz.net *.b1ca5bdc-dc27-4bb5-acbc-25613d881791.twtz.net *.b2ec6da8-befd-4954-8446-d3a825dfc03e.twtz.net *.m.twtz.net *.media2.twtz.net *.media3.twtz.net *.sql.twtz.net twtz.net *.twtz.net *.vpn.twtz.net *.www.twtz.net
*.729d968b-4306-4418-88ef-d64f39c29c76.vip789betj.cc *.admin.vip789betj.cc *.api.vip789betj.cc *.app.vip789betj.cc *.assets.vip789betj.cc *.blog.vip789betj.cc *.demo.vip789betj.cc *.dev.vip789betj.cc *.hostmaster.vip789betj.cc *.shop.vip789betj.cc *.staging.vip789betj.cc *.test.vip789betj.cc vip789betj.cc *.vip789betj.cc
*.95vhx.zbxhbngjszgf.top *.o1ghs.zbxhbngjszgf.top zbxhbngjszgf.top *.zbxhbngjszgf.top