Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=airplanetickets.it
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 05, 2026
Valid Until
September 03, 2026
86 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
70:A3:74:77:62:CA:FF:F4:D4:D1:B4:60:2D:40:62:27:D7:65:0D:6E:F8:21:5D:52:67:4A:FE:75:C7:22:93:FB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
60 domains
foundtheatre.org
*.foundtheatre.org
*.fund.foundtheatre.org
*.ww.foundtheatre.org
airplanetickets.it
*.airplanetickets.it
albastuz3.net
*.albastuz3.net
*.ww25.albastuz3.net
babypictures.it
*.babypictures.it
bcbms.com
*.bcbms.com
*.member.bcbms.com
deeplyinlove.it
*.deeplyinlove.it
exdesaparecidos.org
*.exdesaparecidos.org
*.mail.exdesaparecidos.org
*.ww25.exdesaparecidos.org
julianweather.com
*.julianweather.com
*.tj.julianweather.com
mobarrangi.com
*.mobarrangi.com
*.ww25.mobarrangi.com
northernvirginia.it
*.northernvirginia.it
northline.it
*.northline.it
northlondon.it
*.northlondon.it
potem.site
*.potem.site
powerplayer.it
*.powerplayer.it
puroiphone.it
*.puroiphone.it
risparmiati.it
*.risparmiati.it
russians.it
*.russians.it
solid-thinking.com
*.solid-thinking.com
*.ww38.solid-thinking.com
stockpick.au
*.stockpick.au
stopaborto.it
*.stopaborto.it
styleout.it
*.styleout.it
telecamerewireless.it
*.telecamerewireless.it
transfertoitaly.it
*.transfertoitaly.it
trustedcurriculum.it
*.trustedcurriculum.it
ultraviewar.net
*.ultraviewar.net
*.ww25.ultraviewar.net
Other domains in certificate