Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=guitarstudio.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 05, 2026
Valid Until
May 06, 2026
73 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
49:D6:AF:F0:C7:F3:DC:C1:21:78:D7:D5:EA:65:14:67:08:D4:C4:25:58:9F:5D:C0:BC:00:05:D2:C2:F0:79:EE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
gulzada.com
*.gulzada.com
*.ww16.gulzada.com
barantani.it
*.barantani.it
*.report.barantani.it
guitarstudio.it
*.guitarstudio.it
*.mail3.guitarstudio.it
*.dash.ideazon.it
ideazon.it
*.ideazon.it
*.app.kad.it
kad.it
*.kad.it
*.reporting.kad.it
olimpiche.com
*.olimpiche.com
*.remote.olimpiche.com
pugliadiscovery.it
*.pugliadiscovery.it
pusv6lg.cyou
*.pusv6lg.cyou
pxtv9c51db8d6afdbf8a.xyz
*.pxtv9c51db8d6afdbf8a.xyz
qbborts.com
*.qbborts.com
qrbet.xyz
*.qrbet.xyz
quanqiuguang1.com
*.quanqiuguang1.com
quickheadline.me
*.quickheadline.me
r2-94751123.xyz
*.r2-94751123.xyz
rallykartworld.com
*.rallykartworld.com
ralph-lauren-chile.com
*.ralph-lauren-chile.com
rankfourier.com
*.rankfourier.com
readings.biz
*.readings.biz
realestate.stream
*.realestate.stream
reddfang.com
*.reddfang.com
redditadvertisingservicejoin.com
*.redditadvertisingservicejoin.com
redditbizservice.com
*.redditbizservice.com
redditserviceemailing.com
*.redditserviceemailing.com
redfix.college
*.redfix.college
*.member.relicxy.xyz
relicxy.xyz
*.relicxy.xyz
renkisigi.click
*.renkisigi.click
renshouxingjiao147.buzz
*.renshouxingjiao147.buzz
rhwmjcdf.xyz
*.rhwmjcdf.xyz
risvegliami.it
*.risvegliami.it
*.staging.risvegliami.it
riverrock.it
*.riverrock.it
rkzselmi.xyz
*.rkzselmi.xyz
roadsurferlibertylodge.com
*.roadsurferlibertylodge.com
rockbox.it
*.rockbox.it
roken.it
*.roken.it
rosaventures.com
*.rosaventures.com
royal-trading.pro
*.royal-trading.pro
ruangwd55.net
*.ruangwd55.net
*.link.thecopyelite.com
*.replies.thecopyelite.com
*.sales.thecopyelite.com
thecopyelite.com
*.thecopyelite.com
*.ww25.thecopyelite.com
Other domains in certificate