Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=47it88.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 14, 2026
Valid Until
September 12, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CE:FD:FD:FF:C7:A4:51:0E:43:A7:49:4E:9E:6D:29:E9:81:D7:CC:0E:4E:4E:EE:C1:40:42:9E:86:89:E9:49:79
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
schumm.info *.schumm.info

Other domains in certificate

47it88.com *.47it88.com
60win.live *.60win.live
898848h.cc *.898848h.cc
banhdy.com *.banhdy.com
barnsfinancial.com *.barnsfinancial.com
birthdaycards.us *.birthdaycards.us
bjornsolarpower.com *.bjornsolarpower.com
boischauffagedirect.com *.boischauffagedirect.com
boreagroup.com *.boreagroup.com
boutiques-dofus.online *.boutiques-dofus.online
broadbite.com *.broadbite.com
californiaassetprotectionlawyer.com *.californiaassetprotectionlawyer.com
canflightmuseum.org *.canflightmuseum.org
cbvznxmqwoeir0983alskdjfugye23.top *.cbvznxmqwoeir0983alskdjfugye23.top
cervisense.com *.cervisense.com
cgrobrttwq.net *.cgrobrttwq.net
chashanshan.cn *.chashanshan.cn
clarityfit.run *.clarityfit.run
clearfitway.run *.clearfitway.run
codemanmodz.com *.codemanmodz.com
communedebangangte.net *.communedebangangte.net
ctnyfamlaw.com *.ctnyfamlaw.com
dealsonfashion.com *.dealsonfashion.com
dealyjokensai.pro *.dealyjokensai.pro
lettorent.com *.lettorent.com *.limnvshop.lettorent.com
litrofxmarket.com *.litrofxmarket.com
moderne-methode.com *.moderne-methode.com
phicocktailbar.com *.phicocktailbar.com
poeticlicensenews.com *.poeticlicensenews.com
pqsttuv.top *.pqsttuv.top
professionaltravelpath.qpon *.professionaltravelpath.qpon
px3-med-team.com *.px3-med-team.com
qualitycorrectionalcare.com *.qualitycorrectionalcare.com
quickks.com *.quickks.com
quintessentialweddings.beauty *.quintessentialweddings.beauty
sagog.com *.sagog.com
tnocapital.com *.tnocapital.com
tokenah.com *.tokenah.com
tokentopoff.com *.tokentopoff.com
travelvaluepro.qpon *.travelvaluepro.qpon
triggerduck.com *.triggerduck.com
trustednatureguidance.live *.trustednatureguidance.live
usemayaapp.com *.usemayaapp.com