76/100 SECURITY SCORE

Certificate Information

Subject
CN=manatoki315.net
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 03, 2026
Valid Until
July 02, 2026 50 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:3B:81:8F:BE:57:B0:25:3D:FB:6B:3B:F9:8B:B3:00:D6:1D:E5:9D:23:22:73:01:37:DB:5D:63:08:56:25:9C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
temperaturecontrols.it *.temperaturecontrols.it *.demo.temperaturecontrols.it *.reports.temperaturecontrols.it *.stats.temperaturecontrols.it

Other domains in certificate

albergoitaliano.it *.albergoitaliano.it
ce-dassault-merignac.com *.ce-dassault-merignac.com *.gestion.ce-dassault-merignac.com
datatrade.com.au *.datatrade.com.au *.ww25.datatrade.com.au
*.admin.facialcleansing.shop *.api.facialcleansing.shop *.app.facialcleansing.shop *.assets.facialcleansing.shop *.blog.facialcleansing.shop *.c699fbed-0227-461d-88a7-6b0ef7a22b05.facialcleansing.shop *.demo.facialcleansing.shop *.dev.facialcleansing.shop facialcleansing.shop *.facialcleansing.shop *.hostmaster.facialcleansing.shop *.landing.facialcleansing.shop *.m.facialcleansing.shop *.members.facialcleansing.shop *.preprod.facialcleansing.shop *.rustore.facialcleansing.shop *.shop.facialcleansing.shop *.staging.facialcleansing.shop *.test.facialcleansing.shop *.www.facialcleansing.shop *.ydkwtm.facialcleansing.shop
maghsad.io *.maghsad.io
manatoki315.net *.manatoki315.net *.ww17.manatoki315.net
myglasswasher.com *.myglasswasher.com
myruralproperty.online *.myruralproperty.online
*.backend.napolinotizie.it napolinotizie.it *.napolinotizie.it
*.cpanel.omonaijamag.com *.cpcalendars.omonaijamag.com *.mail.omonaijamag.com omonaijamag.com *.omonaijamag.com *.webdisk.omonaijamag.com *.webmail.omonaijamag.com *.www.omonaijamag.com
*.984f64b7-7590-4da6-a40c-81df74739521.reve.chat *.korvdprod.reve.chat *.m.reve.chat *.mail.reve.chat *.prod.reve.chat reve.chat *.reve.chat *.rustore.reve.chat *.test.reve.chat *.www.reve.chat
sexsubs.me *.sexsubs.me
*.info.silveryol.com silveryol.com *.silveryol.com
*.members.state-fillings.com state-fillings.com *.state-fillings.com *.ww25.state-fillings.com
supnla.town *.supnla.town
*.api.tropicalresort.it *.hostmaster.tropicalresort.it *.staging.tropicalresort.it tropicalresort.it *.tropicalresort.it *.www.tropicalresort.it
ukrposhta.cc *.ukrposhta.cc *.ww25.ukrposhta.cc *.ww38.ukrposhta.cc
*.job.xonlysevenx.com xonlysevenx.com *.xonlysevenx.com
zika.bet *.zika.bet