76/100 SECURITY SCORE

Certificate Information

Subject
CN=nipi.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:4A:F8:89:F7:77:4A:96:16:54:89:AB:73:E6:90:21:6E:86:02:D6:15:D5:70:52:83:0C:2B:78:6F:83:44:52
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
shieldcrypt-united.com *.shieldcrypt-united.com

Other domains in certificate

affittoimmobili.com *.affittoimmobili.com *.mail.affittoimmobili.com
*.9b3d5d957c93.alisavipdk.com alisavipdk.com *.alisavipdk.com *.dc-74a9f36f89bf.alisavipdk.com *.mail.alisavipdk.com *.random.alisavipdk.com *.www.alisavipdk.com
andmoreheslth.com *.andmoreheslth.com
cbt.tv *.cbt.tv *.secure.cbt.tv
*.admin.diuct.cc diuct.cc *.diuct.cc *.insight.diuct.cc *.sitemaps.diuct.cc *.ww25.diuct.cc *.ww38.diuct.cc *.wwww.diuct.cc
eggsplant.com *.eggsplant.com *.origin.eggsplant.com
*.comune.gmyil.com *.comw25.gmyil.com *.dakbrahim267.gmyil.com *.gmail.gmyil.com gmyil.com *.gmyil.com *.im.gmyil.com *.wsmtp.gmyil.com *.ww25.gmyil.com
*.auth.ican.co *.azcjqe.ican.co *.bqelmc.ican.co *.fvlzix.ican.co *.gvaich.ican.co *.gxefbc.ican.co ican.co *.ican.co *.mtofxs.ican.co *.ncbapm.ican.co *.qxgihu.ican.co *.rupihv.ican.co *.ruxcmd.ican.co *.thuxjg.ican.co *.ubzomh.ican.co *.uvdpis.ican.co *.vcenter.ican.co *.wildcard.ican.co *.wxbmtc.ican.co
innocent-girls.top *.innocent-girls.top *.ww25.innocent-girls.top
*.gpt.levelovictoria.co levelovictoria.co *.levelovictoria.co
morango777br.com *.morango777br.com
*.diu.nipi.it nipi.it *.nipi.it *.studenti.nipi.it *.stydenti.nipi.it
radiantcosmetics.org *.radiantcosmetics.org *.www.radiantcosmetics.org
*.mx.thedukelive.com thedukelive.com *.thedukelive.com *.www.thedukelive.com
*.business.thinkfwd.com.au *.legion.thinkfwd.com.au *.techtoday.thinkfwd.com.au thinkfwd.com.au *.thinkfwd.com.au
*.api.veshreny.com veshreny.com *.veshreny.com *.ww25.veshreny.com
*.random.webglsample.org webglsample.org *.webglsample.org *.ww25.webglsample.org