Open
Cached
·
38m ago
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=lacittadigitale.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 30, 2026
Valid Until
July 29, 2026
47 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
29:20:56:AF:59:5C:6C:D9:5D:91:17:E8:AC:C0:62:F3:EF:40:28:C4:0D:74:E2:8A:33:8D:ED:A3:2A:95:9D:D7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
racist.live
*.racist.live
*.map.racist.live
991e514ac24cbc5e.com
*.991e514ac24cbc5e.com
*.vpn.991e514ac24cbc5e.com
cadcommunity.asia
*.cadcommunity.asia
*.mysql.cadcommunity.asia
couponfa.xyz
*.couponfa.xyz
*.delivery-yandex.couponfa.xyz
*.kvviivl7.couponfa.xyz
*.moneygram.couponfa.xyz
*.aff.cuevana19.online
*.afftrk.cuevana19.online
cuevana19.online
*.cuevana19.online
*.rfk.cuevana19.online
*.signup.cuevana19.online
*.ww38.cuevana19.online
diontaejohnson.com
*.diontaejohnson.com
*.m.diontaejohnson.com
fromtiernet.net
*.fromtiernet.net
*.mail.fromtiernet.net
*.nullmx.fromtiernet.net
*.www.fromtiernet.net
*.aeo.jokerlu.bar
*.eae.jokerlu.bar
*.eio.jokerlu.bar
jokerlu.bar
*.jokerlu.bar
*.ooo.jokerlu.bar
*.backup.keiryu.com
*.beta.keiryu.com
*.blog.keiryu.com
*.crm.keiryu.com
*.demo.keiryu.com
*.forum.keiryu.com
*.hostmaster.keiryu.com
keiryu.com
*.keiryu.com
*.m.keiryu.com
*.remote.keiryu.com
*.vpn.keiryu.com
*.wildcard.keiryu.com
*.ww1.keiryu.com
*.ww16.keiryu.com
*.ww17.keiryu.com
*.ww25.keiryu.com
*.ww38.keiryu.com
*.ww5.keiryu.com
kqyeu.town
*.kqyeu.town
*.town.kqyeu.town
lacittadigitale.it
*.lacittadigitale.it
*.mailserver.meshing.com.au
meshing.com.au
*.meshing.com.au
*.test.meshing.com.au
*.cashwalk.oasisfeed.com
*.flipfocus.oasisfeed.com
*.healingcashpc.oasisfeed.com
*.news.oasisfeed.com
oasisfeed.com
*.oasisfeed.com
*.rinasoft.oasisfeed.com
*.smtbus.oasisfeed.com
*.ww38.oasisfeed.com
*.m.rebateoncar.com
rebateoncar.com
*.rebateoncar.com
*.wp.rebateoncar.com
*.random.shoujoscans.com
shoujoscans.com
*.shoujoscans.com
societemaven.com
*.societemaven.com
*.2zv.spikethechef.com
*.3aq.spikethechef.com
*.h1v.spikethechef.com
*.jingying.spikethechef.com
*.random.spikethechef.com
spikethechef.com
*.spikethechef.com
*.ueu.spikethechef.com
Other domains in certificate