Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=intermountains.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
83 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
12:7C:E2:9D:55:5C:BF:B2:D6:50:CF:C0:2F:95:62:94:CC:9E:DD:59:87:53:A2:95:D9:15:FF:F5:26:E0:B3:59
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
joannis.it
*.joannis.it
elas.life
*.elas.life
*.loja.elas.life
*.make.elas.life
*.seguro.elas.life
icradairesi.org
*.icradairesi.org
*.admin.ilovebrands.it
ilovebrands.it
*.ilovebrands.it
intermountains.com
*.intermountains.com
interplay.it
*.interplay.it
iquadri.it
*.iquadri.it
italianartphotography.it
*.italianartphotography.it
itsupportspecialistsohio.com
*.itsupportspecialistsohio.com
iused.it
*.iused.it
jimmychinphotography.com
*.jimmychinphotography.com
jnageq.pro
*.jnageq.pro
jsoygukd.xyz
*.jsoygukd.xyz
jumnyrah.cfd
*.jumnyrah.cfd
jxmaz.net
*.jxmaz.net
kansai-renovation-565052273.click
*.kansai-renovation-565052273.click
*.analytics.kavi.it
kavi.it
*.kavi.it
kklift.com
*.kklift.com
klinikbehandlungdepressionen.click
*.klinikbehandlungdepressionen.click
knowbeforeyougrow.com
*.knowbeforeyougrow.com
kreojuxi.xyz
*.kreojuxi.xyz
krusty.it
*.krusty.it
kule.us
*.kule.us
ky63.ac
*.ky63.ac
laconsole.it
*.laconsole.it
lala4dslot.com
*.lala4dslot.com
laser-eye-567521878.click
*.laser-eye-567521878.click
lc9876.top
*.lc9876.top
lcds.it
*.lcds.it
learningtechnology.it
*.learningtechnology.it
lectiones.it
*.lectiones.it
lemmings.it
*.lemmings.it
letsget.it
*.letsget.it
lightway.my
*.lightway.my
livegirl.it
*.livegirl.it
lootinglegends.com
*.lootinglegends.com
loveempire.it
*.loveempire.it
lovejourneyceremony.beauty
*.lovejourneyceremony.beauty
lpqevhis.xyz
*.lpqevhis.xyz
lucianamartins.com
*.lucianamartins.com
*.exchange.txtnow.me
*.mail3.txtnow.me
txtnow.me
*.txtnow.me
*.ww25.txtnow.me
Other domains in certificate