76/100 SECURITY SCORE

Certificate Information

Subject
CN=cleanin.it
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 02, 2026
Valid Until
August 31, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D8:FC:B4:9E:3C:B1:9A:91:9E:62:EF:CC:86:E8:C7:10:D9:6B:81:DA:58:B4:A4:51:43:7C:50:3C:2D:3D:6D:BF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
clashdns.com *.clashdns.com *.resolver.clashdns.com

Other domains in certificate

aifund.capital *.aifund.capital *.assets.aifund.capital *.backup.aifund.capital *.cisco.aifund.capital *.external.aifund.capital *.mailer.aifund.capital *.presale.aifund.capital *.v1.aifund.capital
*.bi.citywinetour.com *.citrix.citywinetour.com citywinetour.com *.citywinetour.com *.crm.citywinetour.com *.ent.citywinetour.com *.myapps.citywinetour.com *.owa.citywinetour.com
*.app.cleanin.it cleanin.it *.cleanin.it *.staging.cleanin.it
*.app.ctrl-alt.art *.bdbskuat.ctrl-alt.art ctrl-alt.art *.ctrl-alt.art *.dashboard.ctrl-alt.art *.dev.ctrl-alt.art *.mail.ctrl-alt.art *.mailer.ctrl-alt.art *.nfdinmailer.ctrl-alt.art *.test.ctrl-alt.art
gay90.xyz *.gay90.xyz *.sitemap.gay90.xyz *.sitemaps.gay90.xyz *.ww38.gay90.xyz
*.aba.himagni.com *.hcp.himagni.com himagni.com *.himagni.com *.ljp.himagni.com *.mag.himagni.com *.map.himagni.com *.muhu.himagni.com *.sld.himagni.com *.talk.himagni.com *.vul.himagni.com *.xcb.himagni.com
ikincieltanoto.com *.ikincieltanoto.com *.movie.ikincieltanoto.com
*.32.powdersvillewaterdistrict.com *.cloud.powdersvillewaterdistrict.com powdersvillewaterdistrict.com *.powdersvillewaterdistrict.com *.www.powdersvillewaterdistrict.com
*.ard.tour.de *.au.tour.de *.aymo.tour.de *.boatbike.tour.de *.busch-on.tour.de *.c4rl.tour.de *.el.tour.de *.fahrrad.tour.de *.frank.tour.de *.in-wald-und-flur-auf.tour.de *.jobs-on.tour.de *.kai-on.tour.de *.la.tour.de *.marin.tour.de *.moi.tour.de *.mon.tour.de *.mut.tour.de *.news-on.tour.de *.notre.tour.de *.on.tour.de *.parti.tour.de *.rio-on.tour.de *.schlinz.tour.de *.streetfood.tour.de *.suedafrika-wildcoast.tour.de *.talebesi.tour.de *.tor.tour.de tour.de *.tour.de *.votre.tour.de