Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=energiaefuturo.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2F:D5:50:58:37:C9:6C:DA:1F:85:17:42:4A:89:1E:CD:52:73:C7:58:4C:DC:78:9F:21:FF:7D:AF:DD:AC:E6:B4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
kiwco.com
*.kiwco.com
50132.locker
*.50132.locker
797346.loan
*.797346.loan
90903.locker
*.90903.locker
bestusaluxuryweddingvenueprices202178117.icu
*.bestusaluxuryweddingvenueprices202178117.icu
canadamanufacturing.com
*.canadamanufacturing.com
dohasnob.com
*.dohasnob.com
energiaefuturo.com
*.energiaefuturo.com
fdsag.pro
*.fdsag.pro
formatodigitale.com
*.formatodigitale.com
freebackgroundreports.com
*.freebackgroundreports.com
g73wlym0bztcku9.com
*.g73wlym0bztcku9.com
giuggianello.net
*.giuggianello.net
gjnqo.pro
*.gjnqo.pro
golfcreditcard.com
*.golfcreditcard.com
guaritori.com
*.guaritori.com
hotelkanishka.com
*.hotelkanishka.com
hotelregis.com
*.hotelregis.com
hotelreviewsireland.com
*.hotelreviewsireland.com
hundio.com
*.hundio.com
ignitepassion.com
*.ignitepassion.com
ilcondor.com
*.ilcondor.com
imonili.com
*.imonili.com
iniziali.com
*.iniziali.com
iokje.pro
*.iokje.pro
ippodromosansiro.com
*.ippodromosansiro.com
itsj.pro
*.itsj.pro
jsjtn.shop
*.jsjtn.shop
k1dc2w8k.com
*.k1dc2w8k.com
kingbet42.net
*.kingbet42.net
ku11.sc
*.ku11.sc
lafamiglianelcuore.com
*.lafamiglianelcuore.com
libronero.com
*.libronero.com
localfurniture.com
*.localfurniture.com
ly01.io
*.ly01.io
maccheronicini.com
*.maccheronicini.com
manovali.com
*.manovali.com
marketmakerbot.com
*.marketmakerbot.com
maschere.com
*.maschere.com
mistralventures.com
*.mistralventures.com
musac.com
*.musac.com
saunabath.net
*.saunabath.net
secondarete.com
*.secondarete.com
webtoonhatti.me
*.webtoonhatti.me
xihansoft.cn
*.xihansoft.cn
Other domains in certificate