76/100 SECURITY SCORE

Certificate Information

Subject
CN=delicatebreeze.it.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 31, 2026
Valid Until
August 29, 2026 78 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
94:F7:A1:D1:E5:49:37:24:96:27:E0:6B:A7:9B:D8:97:D8:D2:4A:07:9C:EA:54:C8:76:CA:1A:88:0D:2B:88:1A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
tattviyoga.com *.tattviyoga.com

Other domains in certificate

beatent.com *.beatent.com *.www.beatent.com
delicatebreeze.it.com *.delicatebreeze.it.com
dominionenergy.co *.dominionenergy.co *.economicdevelopment.dominionenergy.co *.hostmaster.dominionenergy.co *.investors.dominionenergy.co *.ww38.dominionenergy.co
dx5w.sbs *.dx5w.sbs
editales.com *.editales.com
egitim-portali.com *.egitim-portali.com
equestrian-international.com *.equestrian-international.com
ersrzug.com *.ersrzug.com
extrabet873.com *.extrabet873.com *.m.extrabet873.com
freeform.it.com *.freeform.it.com
haze.it.com *.haze.it.com
invitingaroma.it.com *.invitingaroma.it.com
onlinegameclub.it.com *.onlinegameclub.it.com
proyek88-projek.homes *.proyek88-projek.homes
proyek88-projek.lat *.proyek88-projek.lat
readyhomeassisttoday.com *.readyhomeassisttoday.com
revampmailmendteam.info *.revampmailmendteam.info
rhiannonrsalisbury.net *.rhiannonrsalisbury.net
ru-tv.net *.ru-tv.net
rustihka.it.com *.rustihka.it.com
sal.it.com *.sal.it.com
sweetscent.it.com *.sweetscent.it.com
topsexeden.com *.topsexeden.com
toriaezu-namade.com *.toriaezu-namade.com
torrentdosfilmeshd4.net *.torrentdosfilmeshd4.net
tortilleriasanroman.com *.tortilleriasanroman.com
triviagold.org *.triviagold.org
turkzconcept.com *.turkzconcept.com
*.antibiotika.uniklinikumjena.de *.fish.uniklinikumjena.de *.kim2.uniklinikumjena.de *.kiza.uniklinikumjena.de *.mpsy.uniklinikumjena.de uniklinikumjena.de *.uniklinikumjena.de
uturninternet.com *.uturninternet.com
*.api.webdesignerfreelance.it *.app.webdesignerfreelance.it *.dev.webdesignerfreelance.it webdesignerfreelance.it *.webdesignerfreelance.it
whisperingzephyr.it.com *.whisperingzephyr.it.com
winq.io *.winq.io
wwwwc22.cc *.wwwwc22.cc
youguaishou.com.cn *.youguaishou.com.cn
yourcleaning.it *.yourcleaning.it
yukiarashi.com *.yukiarashi.com