Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=checkout-payment-account.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026
69 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
78:1C:ED:4F:D9:C1:3E:CB:80:D9:22:CD:29:6F:AD:33:C5:4C:4F:EE:48:86:CE:A7:D9:C1:D1:70:F9:38:B7:C8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
isswave.org
*.isswave.org
bpmib.net
*.bpmib.net
calzoncelli.com
*.calzoncelli.com
carclassic.net
*.carclassic.net
ccb57.top
*.ccb57.top
checkout-payment-account.com
*.checkout-payment-account.com
cinemaitaliani.com
*.cinemaitaliani.com
collegi.com
*.collegi.com
comprensione.com
*.comprensione.com
consigliereregionale.com
*.consigliereregionale.com
dalram.com
*.dalram.com
dmty11.vip
*.dmty11.vip
eikvj.academy
*.eikvj.academy
elaborata.com
*.elaborata.com
estremooriente.com
*.estremooriente.com
fantasy-football.com
*.fantasy-football.com
feticista.com
*.feticista.com
fhtcu.academy
*.fhtcu.academy
fyrof.tv
*.fyrof.tv
ganzf.pro
*.ganzf.pro
gxttm.pro
*.gxttm.pro
h-s.in
*.h-s.in
hdjug.pro
*.hdjug.pro
hotelinsardegna.com
*.hotelinsardegna.com
hotelwhite.com
*.hotelwhite.com
ijnuh.gdn
*.ijnuh.gdn
immunitario.com
*.immunitario.com
improvvisazioni.com
*.improvvisazioni.com
istruiti.com
*.istruiti.com
journale.net
*.journale.net
juliewardmep.eu
*.juliewardmep.eu
kiepenkerlprofi.com
*.kiepenkerlprofi.com
ku11.soy
*.ku11.soy
kyv33.top
*.kyv33.top
lagga.com
*.lagga.com
lifesasport.com
*.lifesasport.com
ltszms.pro
*.ltszms.pro
luciddreamm.xyz
*.luciddreamm.xyz
matusa.com
*.matusa.com
mxdkr.pro
*.mxdkr.pro
obblighi.com
*.obblighi.com
offertedioggi.com
*.offertedioggi.com
okhxl.academy
*.okhxl.academy
olavw.academy
*.olavw.academy
opyqo.academy
*.opyqo.academy
Other domains in certificate