76/100 SECURITY SCORE

Certificate Information

Subject
CN=citem.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026 78 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F1:BA:DB:75:63:CB:26:20:C3:81:FB:55:8F:0D:2C:BF:A9:B8:8F:7F:A5:54:A7:86:10:95:05:2F:58:3D:67:B4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
itmal.com *.itmal.com *.baijialesuanpai.itmal.com *.landunguojiyulecheng.itmal.com *.shijiebeiaomen.itmal.com

Other domains in certificate

*.ad.citem.com *.admin.citem.com *.admission.citem.com *.amr.citem.com *.app.citem.com citem.com *.citem.com *.club.citem.com *.dzjt.citem.com *.ffffffffffff.citem.com *.gjc.citem.com *.huodong.citem.com *.jsjgc.citem.com *.kazan.citem.com *.letter.citem.com *.list.citem.com *.mx.citem.com *.pl.citem.com *.play.citem.com *.remote.citem.com *.retired.citem.com *.rlsbj.citem.com *.social.citem.com *.stage.citem.com *.tumour.citem.com *.vsdg.citem.com *.ww25.citem.com *.ww38.citem.com *.yjj.citem.com *.zsj.citem.com
clearance-car.com *.clearance-car.com
cosmeticoslulu.com *.cosmeticoslulu.com *.random.cosmeticoslulu.com *.ww25.cosmeticoslulu.com
dulin.com *.dulin.com *.secureaccess.dulin.com
freelocaldating.com *.freelocaldating.com
*.admin.freshpicking.com freshpicking.com *.freshpicking.com *.remote.freshpicking.com
hercules-shop.com *.hercules-shop.com *.ww25.hercules-shop.com *.www.hercules-shop.com
imortgageguide.com *.imortgageguide.com *.random.imortgageguide.com
*.ioannis.katsoulis.com katsoulis.com *.katsoulis.com *.wildcard.katsoulis.com
nutsa.com *.nutsa.com *.ww17.nutsa.com
pbnc.net *.pbnc.net
pusatbetawi.com *.pusatbetawi.com *.www.pusatbetawi.com
*.17.tdx.gold *.1j.tdx.gold *.5gn26v0buqzzl2t2aq9q2nv5s.tdx.gold *.m.tdx.gold *.mail.tdx.gold *.mailer.tdx.gold *.stg.tdx.gold tdx.gold *.tdx.gold *.udavwz.tdx.gold *.v1.tdx.gold *.web.tdx.gold *.www.tdx.gold *.x.tdx.gold *.y.tdx.gold
tokyoiishina.net *.tokyoiishina.net *.ww25.tokyoiishina.net
ukbusinesslist.co *.ukbusinesslist.co