Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=boldrin.eu
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 07, 2026
Valid Until
July 06, 2026 33 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
41:9D:8E:F1:95:55:10:85:89:83:61:7B:06:8A:D1:7E:CA:F6:04:3D:15:B4:3B:80:9C:F3:FB:EA:E3:C3:00:50
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
fabswinhers.com *.fabswinhers.com *.ci.fabswinhers.com *.comww16.fabswinhers.com *.m.fabswinhers.com *.media.fabswinhers.com *.netww16.fabswinhers.com *.ruww16.fabswinhers.com

Other domains in certificate

35728.ca *.35728.ca *.ca.35728.ca
boldrin.eu *.boldrin.eu *.wildcard.boldrin.eu
bradforwhite.com *.bradforwhite.com *.gate.bradforwhite.com *.ww1.bradforwhite.com *.ww25.bradforwhite.com
burut.org *.burut.org *.ww25.burut.org
celadon.org *.celadon.org
*.ancestry.familyserch.com familyserch.com *.familyserch.com *.ww25.familyserch.com
fednews-online.com *.fednews-online.com
geometrystop.com *.geometrystop.com *.ww25.geometrystop.com
*.client.hotlyrics.com *.forms.hotlyrics.com hotlyrics.com *.hotlyrics.com *.june.hotlyrics.com *.maestro.hotlyrics.com *.net.hotlyrics.com *.ww16.hotlyrics.com *.ww42.hotlyrics.com
juhuatv2.com *.juhuatv2.com *.v.juhuatv2.com
lordfilm000.site *.lordfilm000.site
lordfilm7.site *.lordfilm7.site
*.benjaminbritton.ordernewspaper.com *.ci.ordernewspaper.com *.cicd.ordernewspaper.com *.denisegessner5.ordernewspaper.com *.en.ordernewspaper.com *.jenkins.ordernewspaper.com *.josephdyer16.ordernewspaper.com ordernewspaper.com *.ordernewspaper.com *.pipeline.ordernewspaper.com *.preprod.ordernewspaper.com *.support.ordernewspaper.com
*.laurore.press-guinee.com *.lepopulaire.press-guinee.com press-guinee.com *.press-guinee.com
rugsly.pl *.rugsly.pl
schley.co *.schley.co *.www.schley.co
stonybrookrodgun.com *.stonybrookrodgun.com *.ww38.stonybrookrodgun.com
taekang.com *.taekang.com
tipsy.com.au *.tipsy.com.au *.ww25.tipsy.com.au
*.btc.tokenpla.net *.ln.tokenpla.net *.random.tokenpla.net *.slack.tokenpla.net tokenpla.net *.tokenpla.net *.ww38.tokenpla.net
*.admin.venticello.it *.backend.venticello.it venticello.it *.venticello.it