76/100 SECURITY SCORE

Certificate Information

Subject
CN=modernblog.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 02, 2026
Valid Until
July 01, 2026 30 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EF:BD:72:C8:82:B2:4B:05:D7:4B:AE:9A:B4:26:42:86:77:9C:74:B9:80:89:9D:EC:14:B1:B2:4F:19:05:23:4F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
skilly.it *.skilly.it *.email.skilly.it *.intel.skilly.it *.ml.skilly.it *.postmaster.skilly.it *.rds.skilly.it *.staging.skilly.it *.webmail05.skilly.it *.www.skilly.it

Other domains in certificate

0402-warehousejobs01.sbs *.0402-warehousejobs01.sbs
48880.locker *.48880.locker
autokopennl.sbs *.autokopennl.sbs
baijiuwiki.de *.baijiuwiki.de
campogalliano.com *.campogalliano.com *.mail.campogalliano.com
clarcks.com *.clarcks.com
drev7.xyz *.drev7.xyz
dumhqojowtau2oi.top *.dumhqojowtau2oi.top
electricjourney.today *.electricjourney.today
f4ti17w.top *.f4ti17w.top
gceon.trade *.gceon.trade
ge7o1zh.top *.ge7o1zh.top
hh1266666.com *.hh1266666.com
hxdvw.trade *.hxdvw.trade
internet-ge-hause.sbs *.internet-ge-hause.sbs
jewelry-008.sbs *.jewelry-008.sbs
*.api.knifecrafter.com knifecrafter.com *.knifecrafter.com
ladieswholearn.org *.ladieswholearn.org
management-training-sg06.click *.management-training-sg06.click
mangotreeadvisor.com *.mangotreeadvisor.com
meetmozzoerp.com *.meetmozzoerp.com
migconsultants.com *.migconsultants.com
*.autodiscover.modernblog.it modernblog.it *.modernblog.it *.remote.modernblog.it
pjwzh.co *.pjwzh.co
*.meta.quakers.social quakers.social *.quakers.social
roofing-companies-hiring.sbs *.roofing-companies-hiring.sbs
saxesswallet.com *.saxesswallet.com
security-jobs-managed-hiring-apply.sbs *.security-jobs-managed-hiring-apply.sbs
sharedensweetconfections.com *.sharedensweetconfections.com
takingcareofyourhair.com *.takingcareofyourhair.com
trueview.dev *.trueview.dev
vtwih.trade *.vtwih.trade
wendeys.com *.wendeys.com
wonderwoman.me *.wonderwoman.me
xnhcerpsliwjsycnpkpe.com *.xnhcerpsliwjsycnpkpe.com
xypzhl8.cc *.xypzhl8.cc
ybk5gz2.top *.ybk5gz2.top