76/100 SECURITY SCORE

Certificate Information

Subject
CN=noviolence.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 22, 2026
Valid Until
May 23, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
52:E2:1E:A1:CC:44:EA:90:BE:72:4E:60:6E:77:BC:90:80:0D:12:E9:71:FB:7B:22:22:8F:9B:76:C8:E7:C8:6B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
holidayvavations.com *.holidayvavations.com *.2bc97eac-f105-403f-a91b-6b819a427fca.holidayvavations.com *.admin.holidayvavations.com *.api.holidayvavations.com *.app.holidayvavations.com *.backend.holidayvavations.com *.backup.holidayvavations.com *.blog.holidayvavations.com *.cloud.holidayvavations.com *.demo.holidayvavations.com *.dev.holidayvavations.com *.ecunnrdweb.holidayvavations.com *.email.holidayvavations.com *.ftp.holidayvavations.com *.guestportal.holidayvavations.com *.localhost.holidayvavations.com *.m.holidayvavations.com *.mail.holidayvavations.com *.portal.holidayvavations.com *.rd.holidayvavations.com *.rdp.holidayvavations.com *.rds.holidayvavations.com *.rdweb.holidayvavations.com *.remote.holidayvavations.com *.secure.holidayvavations.com *.staging.holidayvavations.com *.test.holidayvavations.com *.uat.holidayvavations.com *.vpn.holidayvavations.com *.webvpn.holidayvavations.com *.wmlrjdtlbh.holidayvavations.com *.www.holidayvavations.com *.ynskozhmupecunnrdweb.holidayvavations.com

Other domains in certificate

3m75.com *.3m75.com *.sandbox.3m75.com *.sitemaps.3m75.com *.www.3m75.com
foodstartupindonesia.com *.foodstartupindonesia.com *.mail.foodstartupindonesia.com *.webmail.foodstartupindonesia.com *.www.foodstartupindonesia.com
hanaevent.com *.hanaevent.com *.m.hanaevent.com *.mail.hanaevent.com *.ns.hanaevent.com
*.admin.insureifly.com *.api.insureifly.com *.app.insureifly.com insureifly.com *.insureifly.com *.portal.insureifly.com *.store.insureifly.com
*.gitlab.johnsflowers.com johnsflowers.com *.johnsflowers.com
*.bk.noviolence.it *.bm.noviolence.it *.cg.noviolence.it *.dc.noviolence.it *.de.noviolence.it *.dm.noviolence.it *.ei.noviolence.it *.ej.noviolence.it noviolence.it *.noviolence.it *.www.noviolence.it
*.c3yvt32.repellendus.com repellendus.com *.repellendus.com
*.ovjm.v-buhvzm.net v-buhvzm.net *.v-buhvzm.net
*.audioclub.warez-audio.club *.hostmaster.warez-audio.club *.mail.warez-audio.club *.sunshineinsaigon.warez-audio.club warez-audio.club *.warez-audio.club *.warez-audio.warez-audio.club *.wildcard.warez-audio.club *.ww38.warez-audio.club *.www.warez-audio.club
*.ftp.xn--5gq95i8wdp7jlz6bbuae55g.com *.pop.xn--5gq95i8wdp7jlz6bbuae55g.com xn--5gq95i8wdp7jlz6bbuae55g.com *.xn--5gq95i8wdp7jlz6bbuae55g.com