76/100 SECURITY SCORE

Certificate Information

Subject
CN=glicotonico.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 12, 2026
Valid Until
April 12, 2026 55 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
99:19:58:06:52:A0:40:CF:91:A3:F0:4F:00:33:2D:49:D9:1D:38:5A:2D:2C:DB:71:A4:44:44:B2:05:66:26:88
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
value-line.us *.value-line.us *.dokoware.value-line.us *.hostmaster.value-line.us *.kingslime.value-line.us *.norimaki.value-line.us *.rottweiler.value-line.us *.wildcard.value-line.us

Other domains in certificate

academiadasteclas.com *.academiadasteclas.com *.mail.academiadasteclas.com *.random.academiadasteclas.com *.webdisk.academiadasteclas.com
americanstaffordshireterrior.com *.americanstaffordshireterrior.com *.ww12.americanstaffordshireterrior.com
awk8.com *.awk8.com *.random.awk8.com *.waterways.awk8.com *.wildcard.awk8.com
echoshoes.com *.echoshoes.com *.random.echoshoes.com *.ww25.echoshoes.com
etlettera.eu *.etlettera.eu *.groesbeek.etlettera.eu *.hank.etlettera.eu
*.cpcalendars.foxburger.pl foxburger.pl *.foxburger.pl *.franczyza.foxburger.pl *.franczyza1.foxburger.pl
glicotonico.com *.glicotonico.com
*.aladnan.greenfinger.pro *.cpanel.greenfinger.pro *.cpcalendars.greenfinger.pro greenfinger.pro *.greenfinger.pro *.lagtaa.greenfinger.pro *.lemachinisteinfo.greenfinger.pro *.quran.greenfinger.pro *.voice.greenfinger.pro *.ww38.greenfinger.pro
herogayab.co *.herogayab.co *.mail.herogayab.co
journeyjumpstart.com *.journeyjumpstart.com *.mail.journeyjumpstart.com
suvlights.com *.suvlights.com *.wildcard.suvlights.com *.ww25.suvlights.com
*.acc.thoughtexperience.com *.cpanel.thoughtexperience.com *.cpcalendars.thoughtexperience.com *.logic.thoughtexperience.com thoughtexperience.com *.thoughtexperience.com *.ww25.thoughtexperience.com
tiendaagranelcr.com *.tiendaagranelcr.com *.www.tiendaagranelcr.com
*.ipv6.truyensex69.net *.owa.truyensex69.net *.sitemap.truyensex69.net truyensex69.net *.truyensex69.net *.www.truyensex69.net
*.blog102.tudis.com *.chat.tudis.com *.client.tudis.com *.crm.tudis.com *.data.tudis.com *.dev.tudis.com *.e.tudis.com *.go.tudis.com *.hostmaster.tudis.com *.staging.tudis.com *.superset.tudis.com *.test.tudis.com tudis.com *.tudis.com *.video.tudis.com *.ww11.tudis.com *.ww16.tudis.com *.ww25.tudis.com