Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=thewhite.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:A9:AC:AF:68:F9:9E:1A:7D:FA:FE:12:C4:DD:12:1E:77:00:0C:1E:95:63:0C:87:48:A0:EB:72:92:07:5E:88
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
replicant.it *.replicant.it

Other domains in certificate

*.app.phoneprotection.it phoneprotection.it *.phoneprotection.it
prodottipugliesitipici.it *.prodottipugliesitipici.it
publiser.it *.publiser.it
redlineapp.com *.redlineapp.com
resellerhostingaccount.com *.resellerhostingaccount.com
rideraroniiosdalmart.shop *.rideraroniiosdalmart.shop
rieletto.it *.rieletto.it
riparazionestampanti.it *.riparazionestampanti.it
ritrattidigitali.it *.ritrattidigitali.it
rivuletsteward.com *.rivuletsteward.com
rkjnv.bid *.rkjnv.bid
rkl6my.org *.rkl6my.org
rmcwc.bid *.rmcwc.bid
rnvwu.net *.rnvwu.net
roboinvesting950673.icu *.roboinvesting950673.icu
ropelock.it *.ropelock.it
rosetta.it *.rosetta.it
salesgoals.it *.salesgoals.it
samplesmartco.com *.samplesmartco.com
sctxn.pro *.sctxn.pro
sebastiani.it *.sebastiani.it
serialcominstruments.com *.serialcominstruments.com
slots769.com *.slots769.com
smartyparty.it *.smartyparty.it
solarthermal.it *.solarthermal.it
sonobello.it *.sonobello.it
spaghettiallevongole.it *.spaghettiallevongole.it
spazioscommesse.it *.spazioscommesse.it
spenip.com *.spenip.com
sprucemail.com *.sprucemail.com *.webmail.sprucemail.com
stopnshop.it *.stopnshop.it
svwzhq.pro *.svwzhq.pro
taiwan-wealth-219710308.click *.taiwan-wealth-219710308.click
telefoniaaziendale.it *.telefoniaaziendale.it
theporndudw.com *.theporndudw.com
thewhite.it *.thewhite.it
topcruise.it *.topcruise.it
towan.tv *.towan.tv
tryoutascendagency.com *.tryoutascendagency.com
tzwvd.tv *.tzwvd.tv
uggtx.pro *.uggtx.pro
vegamovies.tube *.vegamovies.tube
vintagebook.it *.vintagebook.it