76/100 SECURITY SCORE

Certificate Information

Subject
CN=rtpvivahoki.live
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 03, 2026
Valid Until
July 02, 2026 48 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A9:FC:07:C3:28:BC:DF:C3:78:85:20:E8:5B:1B:07:A5:E9:CD:CB:39:11:A6:59:00:D9:ED:A3:0B:28:59:6E:4C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
questionedisoldi.it *.questionedisoldi.it *.hostmaster.questionedisoldi.it *.reporting.questionedisoldi.it *.w.questionedisoldi.it

Other domains in certificate

covermystory.com *.covermystory.com *.forums.covermystory.com
*.apl.craca.it *.astelmail.craca.it *.clientesvpn.craca.it craca.it *.craca.it *.hostmaster.craca.it *.mail.craca.it *.mx.craca.it *.pvc.craca.it *.status.craca.it *.vpnma.craca.it
e-spolszczenia.pl *.e-spolszczenia.pl *.wildcard.e-spolszczenia.pl
fatum.it *.fatum.it *.www.fatum.it
flickonn.club *.flickonn.club
*.91b15ce9-77a6-4b92-9061-afcb6e772171.gaigoihanoi.xyz gaigoihanoi.xyz *.gaigoihanoi.xyz
jme.com.pl *.jme.com.pl
luckydays.bet *.luckydays.bet *.mobile.luckydays.bet *.www.luckydays.bet
ozoope.online *.ozoope.online
piapi.co *.piapi.co *.tinkoff.piapi.co
*.help.pizzadominoeshtehard.com *.order.pizzadominoeshtehard.com pizzadominoeshtehard.com *.pizzadominoeshtehard.com
pizzeria111-muenchen.de *.pizzeria111-muenchen.de
*.budweiser.resqworkplace.com *.ibplc.resqworkplace.com *.patricia.resqworkplace.com *.pepsi.resqworkplace.com resqworkplace.com *.resqworkplace.com *.simulator.resqworkplace.com *.vrs.resqworkplace.com
*.a.rickard.it *.mail.rickard.it *.notexistsshop.rickard.it rickard.it *.rickard.it *.t.rickard.it
*.bi.royalthaicafe.com *.careers.royalthaicafe.com *.demo.royalthaicafe.com *.dev.royalthaicafe.com *.flow.royalthaicafe.com *.flowise.royalthaicafe.com *.mm.royalthaicafe.com royalthaicafe.com *.royalthaicafe.com *.sa.royalthaicafe.com *.superset.royalthaicafe.com *.webmail.royalthaicafe.com
rtpvivahoki.live *.rtpvivahoki.live
seuacordofacil.com.br *.seuacordofacil.com.br
sinplyhealthcareplans.com *.sinplyhealthcareplans.com
studyspace.online *.studyspace.online
*.49.thetime.it *.hostmaster.thetime.it *.mx.thetime.it thetime.it *.thetime.it *.www.thetime.it
*.ws.zonaleros.net zonaleros.net *.zonaleros.net