Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=altrolocale.pl
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 17, 2026
Valid Until
July 16, 2026
54 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BA:A9:6A:0D:9E:A9:7C:FC:B4:A4:60:8B:62:90:E2:98:35:85:F7:98:36:9F:09:73:48:51:01:E2:EA:71:DA:61
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
shined.it.com
*.shined.it.com
45092.co
*.45092.co
altrolocale.pl
*.altrolocale.pl
*.website.altrolocale.pl
antarcticabar.com
*.antarcticabar.com
*.ffffffffffff.antarcticabar.com
*.ww38.antarcticabar.com
anticipation2017.org
*.anticipation2017.org
*.ww38.anticipation2017.org
associationdesentrepreneurs.com
*.associationdesentrepreneurs.com
blancobox.com
*.blancobox.com
careerbuffet.com
*.careerbuffet.com
complete-weldingservices.sbs
*.complete-weldingservices.sbs
exclusivism.com
*.exclusivism.com
*.geo.exclusivism.com
*.m.exclusivism.com
*.wildcard.exclusivism.com
*.ww17.exclusivism.com
*.ww25.exclusivism.com
*.chi.firstkimono.com
*.cit.firstkimono.com
*.en.firstkimono.com
firstkimono.com
*.firstkimono.com
*.ww12.firstkimono.com
*.comune.lamon.it
*.hostmaster.lamon.it
lamon.it
*.lamon.it
*.abc.loigmein123.com
*.ci.loigmein123.com
*.co.loigmein123.com
*.foto.loigmein123.com
loigmein123.com
*.loigmein123.com
*.panel.loigmein123.com
*.s1.loigmein123.com
*.social.loigmein123.com
*.users.loigmein123.com
*.video.loigmein123.com
lowcarbonpeergroup.com
*.lowcarbonpeergroup.com
memorylayer.xyz
*.memorylayer.xyz
meyerundmeyer.com
*.meyerundmeyer.com
mmzln.consulting
*.mmzln.consulting
natmanaquaticservices.com
*.natmanaquaticservices.com
*.help.opangl.click
opangl.click
*.opangl.click
*.sitemap.opangl.click
*.ww38.opangl.click
psagentic.com
*.psagentic.com
qualigence-team.com
*.qualigence-team.com
qualigencehq.com
*.qualigencehq.com
qufase.pro
*.qufase.pro
quintessentialvacations.live
*.quintessentialvacations.live
qwert.nexus
*.qwert.nexus
qyc65.com
*.qyc65.com
*.mail.radabeaute.com
radabeaute.com
*.radabeaute.com
thriveenginehub.com
*.thriveenginehub.com
timelesslessons.com
*.timelesslessons.com
torontoweddingband.info
*.torontoweddingband.info
tradiestax.com.au
*.tradiestax.com.au
Other domains in certificate