Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=gotovisit.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CD:E4:9F:84:4F:89:70:A4:C4:9B:8F:2D:5C:78:92:46:B1:ED:5A:0B:6C:B8:AE:BA:3D:C5:F0:71:7F:DF:B5:4C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
faqmatic.com
*.faqmatic.com
hbyjk.co.in
*.hbyjk.co.in
einbeckernullbock.com
*.einbeckernullbock.com
ethereum-basic.com
*.ethereum-basic.com
europeanaircharter.com
*.europeanaircharter.com
exoticfoodhorizons.food
*.exoticfoodhorizons.food
farabutto.it
*.farabutto.it
farhang.it
*.farhang.it
farizonauto.us
*.farizonauto.us
farm-toys-815115694.click
*.farm-toys-815115694.click
fenix-vision.mobi
*.fenix-vision.mobi
feyldw6qt4nk.com
*.feyldw6qt4nk.com
fitnessgleamquest.run
*.fitnessgleamquest.run
fp39.vip
*.fp39.vip
getoutboundemal.top
*.getoutboundemal.top
getpaidtoopenabankaccounts.icu
*.getpaidtoopenabankaccounts.icu
gotovisit.it
*.gotovisit.it
grrfind.top
*.grrfind.top
gzljgjg.cn
*.gzljgjg.cn
haklimisin.com
*.haklimisin.com
hernanbits.com
*.hernanbits.com
hg-hf.com
*.hg-hf.com
hmbet.live
*.hmbet.live
hshse.com
*.hshse.com
hslff.bid
*.hslff.bid
inference-team.com
*.inference-team.com
jamielogistics.com
*.jamielogistics.com
jivanhospital.in
*.jivanhospital.in
jrxac.com
*.jrxac.com
sleepbettertogether.com
*.sleepbettertogether.com
southlandvs.com
*.southlandvs.com
sptraderamgai.com
*.sptraderamgai.com
sxllhczx.com
*.sxllhczx.com
targpro.xyz
*.targpro.xyz
teddybearsonthego.com
*.teddybearsonthego.com
terokver.com
*.terokver.com
tl03.icu
*.tl03.icu
toollyezz.xyz
*.toollyezz.xyz
tradetalentexchange.cfd
*.tradetalentexchange.cfd
twqdaswq99567wqewq0d5eqw.vip
*.twqdaswq99567wqewq0d5eqw.vip
tws-live.com
*.tws-live.com
ultrawarrior859.top
*.ultrawarrior859.top
usdoa.us
*.usdoa.us
usdt.shopping
*.usdt.shopping
vahdeals.com
*.vahdeals.com
Other domains in certificate