76/100 SECURITY SCORE

Certificate Information

Subject
CN=pointofweb.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 22, 2026
Valid Until
May 23, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BC:CC:9D:72:13:E1:1C:08:F5:45:A4:A4:05:F0:9F:E7:18:B2:E5:2D:F5:AF:34:C0:25:CD:9D:69:20:17:D1:EB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
pointofweb.it *.pointofweb.it *.remote.pointofweb.it

Other domains in certificate

*.admin.annie.best annie.best *.annie.best *.api.annie.best *.app.annie.best *.backup.annie.best *.dan.annie.best *.edit.annie.best *.egryedemo.annie.best *.m.annie.best *.mail.annie.best *.sigqmm.annie.best *.test.annie.best
*.data.doods.bar doods.bar *.doods.bar
*.bos.fullwin.it fullwin.it *.fullwin.it *.hostmaster.fullwin.it *.manutenzione.fullwin.it *.staging-www.fullwin.it *.www.fullwin.it
hashshiny.org *.hashshiny.org *.user.hashshiny.org
*.admin.homeypanda.asia homeypanda.asia *.homeypanda.asia
*.1.l6.com.au *.2021.l6.com.au *.2023.l6.com.au *.ci.l6.com.au *.descargas.l6.com.au *.domaincontrolpanel.l6.com.au *.jenkins.l6.com.au l6.com.au *.l6.com.au *.pipeline.l6.com.au *.preprod.l6.com.au *.service.l6.com.au *.v.l6.com.au
*.74c5f200-9824-485e-ad63-464a1d93435d.minnesotaisrad.com *.app.minnesotaisrad.com minnesotaisrad.com *.minnesotaisrad.com
*.edge.mlfixzzz.click *.lab.mlfixzzz.click mlfixzzz.click *.mlfixzzz.click *.www.mlfixzzz.click
*.196.pall.it *.249.pall.it *.8.pall.it *.bojl.pall.it *.data.pall.it *.irisventricofa.pall.it *.notexists196.pall.it pall.it *.pall.it *.vermeereehaven.pall.it
*.jer.rintel.com rintel.com *.rintel.com
*.4p0la2.runelephant.com *.m.runelephant.com *.o1msd.runelephant.com runelephant.com *.runelephant.com *.vpn.runelephant.com *.w7qv0clp.runelephant.com *.x5pcojj2jk.runelephant.com
*.backend.scarpine.it *.hostmaster.scarpine.it *.postmaster.scarpine.it *.reports.scarpine.it scarpine.it *.scarpine.it *.staging.scarpine.it
*.admin.soupjunkiesf.com *.hostmaster.soupjunkiesf.com soupjunkiesf.com *.soupjunkiesf.com *.www.soupjunkiesf.com
*.admin.toph.life toph.life *.toph.life