Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=digitalwatch.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
45:93:5F:CD:1A:9F:AE:C7:B7:08:2F:AF:17:53:3E:AF:67:08:D8:E7:77:0A:A5:46:C8:CC:DA:FA:0B:81:E4:20
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
mhd411.com
*.mhd411.com
digitalwatch.it
*.digitalwatch.it
directmarket.it
*.directmarket.it
dogout.it
*.dogout.it
dostatokua.com
*.dostatokua.com
dreamyweddingatmosphere.beauty
*.dreamyweddingatmosphere.beauty
dropservicing.it
*.dropservicing.it
dumti.shop
*.dumti.shop
e5456727.vip
*.e5456727.vip
e5465011.vip
*.e5465011.vip
echotranslator.com
*.echotranslator.com
efatura-turkcell.com
*.efatura-turkcell.com
exclusiveoffers.it
*.exclusiveoffers.it
f64123750.com
*.f64123750.com
f64976204.com
*.f64976204.com
f64985967.com
*.f64985967.com
facedesign.it
*.facedesign.it
filmyhunt.in
*.filmyhunt.in
findwork.it
*.findwork.it
mediation.it.com
*.mediation.it.com
llhjd.pro
*.llhjd.pro
lliyz.net
*.lliyz.net
lurchingfully.com
*.lurchingfully.com
maryle.it
*.maryle.it
mauriziosarri.it
*.mauriziosarri.it
mindfulfoodtales.food
*.mindfulfoodtales.food
mmq.it
*.mmq.it
motorcycle-accident-lawyer-882.click
*.motorcycle-accident-lawyer-882.click
mpo99betvip.pro
*.mpo99betvip.pro
musicdownload.it
*.musicdownload.it
mutatio.it
*.mutatio.it
nexhome.co
*.nexhome.co
nhjcdyrw.xyz
*.nhjcdyrw.xyz
nutrizioni.it
*.nutrizioni.it
occhialiditendenza.it
*.occhialiditendenza.it
ofis.it
*.ofis.it
openarmstravel.xyz
*.openarmstravel.xyz
openmenu.it
*.openmenu.it
panglima77port.com
*.panglima77port.com
paymyparkingnotice.co
*.paymyparkingnotice.co
pedemonte.it
*.pedemonte.it
pet-funeral-eng-88.click
*.pet-funeral-eng-88.click
phimo-sissurgery-jpp.click
*.phimo-sissurgery-jpp.click
plau.it
*.plau.it
play-guardian-voyage.xyz
*.play-guardian-voyage.xyz
Other domains in certificate