76/100 SECURITY SCORE

Certificate Information

Subject
CN=incontrodamore.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 06, 2026
Valid Until
July 05, 2026 45 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
78:57:23:52:34:F6:E5:4D:6D:EE:E2:CB:C5:4F:19:DD:C6:98:9E:6C:F6:8E:3C:5C:93:E3:22:87:8E:CC:B7:9B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
plasmadrum.com *.plasmadrum.com *.cloud.plasmadrum.com *.mobil.plasmadrum.com *.mobile.plasmadrum.com *.random.plasmadrum.com

Other domains in certificate

*.ads.bidderfordblankets.com bidderfordblankets.com *.bidderfordblankets.com *.ci.bidderfordblankets.com *.cicd.bidderfordblankets.com *.faq.bidderfordblankets.com *.jenkins.bidderfordblankets.com *.nsk.bidderfordblankets.com *.pipeline.bidderfordblankets.com *.radio.bidderfordblankets.com *.s.bidderfordblankets.com *.survey.bidderfordblankets.com *.ww25.bidderfordblankets.com
biennale3000saopaulo.org *.biennale3000saopaulo.org *.ww16.biennale3000saopaulo.org *.ww25.biennale3000saopaulo.org
blusenbody.de *.blusenbody.de
chinatax.au *.chinatax.au *.jiangsu.chinatax.au *.random.chinatax.au *.tpass.chinatax.au *.ww25.chinatax.au *.ww38.chinatax.au
crimsonbluffs.org *.crimsonbluffs.org *.ww16.crimsonbluffs.org *.www.crimsonbluffs.org
fadmoney.club *.fadmoney.club
findadeal.com *.findadeal.com *.ww25.findadeal.com
*.ai.freedomhyundai.com *.cicd.freedomhyundai.com freedomhyundai.com *.freedomhyundai.com *.jc.freedomhyundai.com *.specials.freedomhyundai.com *.ww16.freedomhyundai.com
herculeskeule.de *.herculeskeule.de
*.admin.incontrodamore.it *.api.incontrodamore.it incontrodamore.it *.incontrodamore.it *.wwww.incontrodamore.it
*.hab.inschriften.de inschriften.de *.inschriften.de
konj.de *.konj.de
krx.de *.krx.de
kxi.de *.kxi.de
movierulz.bio *.movierulz.bio
mynail.fr *.mynail.fr
onde.au *.onde.au *.ww25.onde.au
removalswollongong.com.au *.removalswollongong.com.au
rurallandsales.com.au *.rurallandsales.com.au
sandwichchocslices.com *.sandwichchocslices.com *.wordpress.sandwichchocslices.com
stussyus.cc *.stussyus.cc
tanganjika.com *.tanganjika.com
walelolelo.click *.walelolelo.click *.ww25.walelolelo.click
wonhwagen.de *.wonhwagen.de
x-base.eu *.x-base.eu