Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=noteworthy.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 01, 2026
Valid Until
July 30, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:FD:E0:A3:5C:06:26:28:69:64:EA:36:9B:36:A2:D1:D9:ED:6F:B6:2C:46:92:33:F4:63:3F:75:B4:CB:3D:4B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
85 domains
firsthorizom.com
*.firsthorizom.com
*.5003.firsthorizom.com
*.security.firsthorizom.com
*.shop.firsthorizom.com
alistwraps.com
*.alistwraps.com
*.zoom.alistwraps.com
anconascantelrammish.sbs
*.anconascantelrammish.sbs
b333ku.click
*.b333ku.click
*.m.b333ku.click
cryptodrop.store
*.cryptodrop.store
*.ww25.cryptodrop.store
*.access.domailn.com
domailn.com
*.domailn.com
g4l.com
*.g4l.com
*.www.g4l.com
hallbrotherswine.com
*.hallbrotherswine.com
*.webdisk.hallbrotherswine.com
karachiessencehouse.com
*.karachiessencehouse.com
*.ww25.karachiessencehouse.com
keepground5.xyz
*.keepground5.xyz
*.random.keepground5.xyz
*.ww25.keepground5.xyz
*.ww38.keepground5.xyz
*.wwww.keepground5.xyz
koynonya.com
*.koynonya.com
*.act.lxware.de
lxware.de
*.lxware.de
*.office.lxware.de
*.hostmaster.noteworthy.it
noteworthy.it
*.noteworthy.it
*.notexistsadmin.noteworthy.it
nuvexon.ai
*.nuvexon.ai
*.comww38.ojkdem.com
ojkdem.com
*.ojkdem.com
*.bi.outlinesrubberstamp.com
outlinesrubberstamp.com
*.outlinesrubberstamp.com
parkleiloes.com.br
*.parkleiloes.com.br
razlozhi.pro
*.razlozhi.pro
rwulzuaqsafn.com
*.rwulzuaqsafn.com
sagame1688creditfree.com
*.sagame1688creditfree.com
*.appserver.sattvastore.com
*.artofliving-app.sattvastore.com
*.pp1-admin-aol.sattvastore.com
*.qronwapi.sattvastore.com
sattvastore.com
*.sattvastore.com
*.m.stablecoinlaw.com
stablecoinlaw.com
*.stablecoinlaw.com
*.www.stablecoinlaw.com
uplay168.bet
*.uplay168.bet
*.ww38.uplay168.bet
vmstorebrasil.com.br
*.vmstorebrasil.com.br
*.ww25.vmstorebrasil.com.br
*.ww38.vmstorebrasil.com.br
webchild.com.au
*.webchild.com.au
wint88.bet
*.wint88.bet
*.new.xn--rlsx8k.net
*.remote.xn--rlsx8k.net
xn--rlsx8k.net
*.xn--rlsx8k.net
Other domains in certificate