Open
Cached
·
just now
75/100
SECURITY SCORE
Certificate Information
Subject
CN=dpromo.abarth.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 12, 2026
Valid Until
April 12, 2026
70 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AB:0E:F5:6D:B0:EE:5B:2A:F2:A6:3A:9A:1C:7D:51:1C:E4:30:66:7F:D0:FC:C2:B5:76:78:86:D1:EB:56:CC:75
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
98 domains
settings.spacemdw.com
settings.int.spacemdw.com
settings.prep.spacemdw.com
arviewer.abarth.com
myuconnect.abarth.com
stage-arviewer.abarth.com
www.abarth.com.ar
dpromo.abarth.it
www.alfaromeo-bahrain.com
www.alfaromeo-bd.com
www.alfaromeo-jp.com
www.alfaromeo-kuwait.com
www.alfaromeo-lebanon.com
www.alfaromeo-official.ba
www.alfaromeo-official.ge
www.alfaromeo-official.md
www.alfaromeo-pf.com
www.alfaromeo-qatar.com
www.alfaromeo-saudi.com
www.alfaromeo-uae.com
www.alfaromeo-uz.com
www.alfaromeo.al
www.alfaromeo.cl
www.alfaromeo.cn
www.alfaromeo.com.au
www.alfaromeo.do
www.alfaromeo.gp
www.alfaromeo.is
www.alfaromeo.mq
www.alfaromeo.mx
www.alfaromeo.nc
www.alfaromeocz.com
www.alfaromeokz.com
my.citroen.com
myfr.citroen.com
www.alfaromeo.com.bn
ami.citroen.com.mt
www.alfaromeo.com.sg
configurador.dsautomobiles.cl
my.dsautomobiles.com
myfr.dsautomobiles.com
konfigurator.dsautomobiles.cz
konfiguraattori.dsautomobiles.fi
configurator.dsautomobiles.gr
www.dsautomobiles.hr
configurateur.dsautomobiles.ma
configurator.dsautomobiles.ro
konfigurator.dsautomobiles.sk
promo.contentservices.fcagroup.com
www.fiat-auto.co.jp
www.fiat-kz.com
www.fiat-official.md
www.fiat-official.uz
www.fiat-saudi.com
arviewer.fiat.com
staticpromo.fiat.com
www.fiat.com.au
www.fiat.dz
market-research-privacy.fiatauto.com
ncbs.fiatauto.com
quality.fiatauto.com
www.fiatpr.com
www.fiatsk.com
brand.lancia.com
myuconnect.lancia.com
connectservice.leapmotor-international.com
eu.goldmain-link.leapmotor-international.com
eu.link.leapmotor-international.com
goldmain-linkentry-euro.leapmotor-international.com
goldmain-linkentry.leapmotor-international.com
linkentry-euro.leapmotor-international.com
linkentry.leapmotor-international.com
privacy.leapmotor-international.com
www.leapmotor.com
www.leapmotor.net
corporate.leasys.com
www.leasys.com
www.oman-alfaromeo.com
id-dcr-cdn.opel.com
my.opel.com
my.peugeot.com
myfr.peugeot.com
www.peugeotvietnam.vn
assetscc.stellantis.com
exve.stellantis.com
privacy.stellantis.com
stage-web3dvisualizer.stellantis.com
stage.thedealerexperience.stellantis.com
test-cntry.stellantis.com
thedealerexperience.stellantis.com
townhall.stellantis.com
web3dvisualizer.stellantis.com
www.milanocortina2026.stellantis.com
www.stellantisdesignstudio.com
www.stellantisheritage.com
www.stellantiswindtunnels.com
www.teksid.com
my.vauxhall.com
Other domains in certificate