76/100 SECURITY SCORE

Certificate Information

Subject
CN=lally.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 07, 2026
Valid Until
May 08, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
07:E4:A4:40:CB:25:38:B0:1A:E9:25:58:30:D4:4C:97:30:DF:6B:50:56:32:D7:C6:4D:02:E6:04:0B:85:B8:C9
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
capricho.com *.capricho.com *.dulce.capricho.com *.remote.capricho.com *.www.capricho.com

Other domains in certificate

*.blog.bodyelastic.com bodyelastic.com *.bodyelastic.com *.demo.bodyelastic.com *.sitemaps.bodyelastic.com *.test.bodyelastic.com *.www.bodyelastic.com
*.acquia.buerocenter.info *.app.buerocenter.info *.avbmjapp.buerocenter.info *.babel.buerocenter.info *.blog.buerocenter.info buerocenter.info *.buerocenter.info *.click.buerocenter.info *.dma.buerocenter.info *.hostmaster.buerocenter.info *.imialdma.buerocenter.info *.m.buerocenter.info *.quill.buerocenter.info *.rain.buerocenter.info *.www.buerocenter.info
carbninja.com *.carbninja.com *.mx.carbninja.com *.www.carbninja.com
*.backup.dramanimy.com dramanimy.com *.dramanimy.com
executivemanagementcoaching.com *.executivemanagementcoaching.com *.rdweb.executivemanagementcoaching.com
exploreupalttop.com *.exploreupalttop.com *.store.exploreupalttop.com
flightticketsale.com *.flightticketsale.com *.store.flightticketsale.com
ghwsk.net *.ghwsk.net
*.demo.interactivecatalogs.com *.hostmaster.interactivecatalogs.com interactivecatalogs.com *.interactivecatalogs.com
*.hostmaster.lally.it lally.it *.lally.it
*.app.mpas.it mpas.it *.mpas.it
*.arpa.piemont.it *.mail.piemont.it piemont.it *.piemont.it *.regione.piemont.it
*.autoconfig.plagiarism-detect.com *.backend.plagiarism-detect.com *.cms.plagiarism-detect.com *.com.plagiarism-detect.com *.dash.plagiarism-detect.com *.dev.plagiarism-detect.com *.helpdesk.plagiarism-detect.com *.member.plagiarism-detect.com *.mta-sts.plagiarism-detect.com plagiarism-detect.com *.plagiarism-detect.com *.shop.plagiarism-detect.com *.store.plagiarism-detect.com *.webmail.plagiarism-detect.com *.ww17.plagiarism-detect.com
qualyshotel-beaune.com *.qualyshotel-beaune.com *.www.qualyshotel-beaune.com
*.api.roadless.it roadless.it *.roadless.it
*.bigbadblob.traffikteam.com *.chalkboard-ads.traffikteam.com *.com.traffikteam.com *.dragbushits.traffikteam.com *.highwaymails.traffikteam.com *.mail.traffikteam.com *.pay.traffikteam.com traffikteam.com *.traffikteam.com