Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=calcolamutui.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026
76 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
ED:8E:D1:66:92:A4:B6:60:DB:73:65:34:E0:43:CF:02:AD:D0:42:A3:55:B6:A3:3C:4D:C6:8A:21:FD:34:69:6D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
lapolena.com
*.lapolena.com
bet365it.cloud
*.bet365it.cloud
biztruaroniiosdalre.cyou
*.biztruaroniiosdalre.cyou
bootruaroniiosdalaven.shop
*.bootruaroniiosdalaven.shop
bzxmb.net
*.bzxmb.net
calcolamutui.com
*.calcolamutui.com
careersolutionsexpert.live
*.careersolutionsexpert.live
chesapeakesci.org
*.chesapeakesci.org
chinataxicaller.com
*.chinataxicaller.com
domain-pool.com
*.domain-pool.com
dvglsidvgetghffrgato.com
*.dvglsidvgetghffrgato.com
e05a9xp.top
*.e05a9xp.top
euromoto.net
*.euromoto.net
exwbjl.pro
*.exwbjl.pro
fruzaqlagisttreatment204404.icu
*.fruzaqlagisttreatment204404.icu
gesundheits-netzwerk.info
*.gesundheits-netzwerk.info
gltrkv.pro
*.gltrkv.pro
goodmorningimages.club
*.goodmorningimages.club
hobtruaroniiosdalhub.cyou
*.hobtruaroniiosdalhub.cyou
houses-for-sale-near-me.info
*.houses-for-sale-near-me.info
ibiissante.org
*.ibiissante.org
ilifw.pro
*.ilifw.pro
impiantosolaretermico.com
*.impiantosolaretermico.com
incomeprotection.in
*.incomeprotection.in
iokih.pro
*.iokih.pro
kindlebowl.com
*.kindlebowl.com
kneedriveglide.com
*.kneedriveglide.com
lhwlcp.top
*.lhwlcp.top
longtermcareervision.live
*.longtermcareervision.live
lorighittas.com
*.lorighittas.com
lqsbq.net
*.lqsbq.net
mapofseoul.com
*.mapofseoul.com
mdou145.com
*.mdou145.com
mjync.cn
*.mjync.cn
monogramdogshows.com
*.monogramdogshows.com
mstzx.cn
*.mstzx.cn
mustangadmin.org
*.mustangadmin.org
newwineskinsassociation.org
*.newwineskinsassociation.org
nqfct.bid
*.nqfct.bid
partheniae.com
*.partheniae.com
partofholy.com
*.partofholy.com
penelopecruz.net
*.penelopecruz.net
phonehomo.com
*.phonehomo.com
ppgbet.info
*.ppgbet.info
puckdw.nl
*.puckdw.nl
Other domains in certificate