Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=lappa.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 03, 2026
Valid Until
July 02, 2026 46 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2D:EA:D3:61:89:51:1C:F9:38:D4:3A:1F:F1:A2:5D:68:21:F8:4E:B2:16:8C:1B:0D:37:55:96:54:69:5B:7E:D2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
lappa.it *.lappa.it *.admin.lappa.it *.agbe.lappa.it *.api.lappa.it *.cdfy.lappa.it *.cooldeals.lappa.it *.mail.lappa.it *.staging.lappa.it *.www.lappa.it

Other domains in certificate

*.33c5f954-5b66-4c3a-b650-06ad0d3bdc9c.newtartcap.com *.8b8e1ac5-2aa7-40c2-a5d1-ba832e526f94.newtartcap.com *.9131f5f4-abfa-447a-bdb1-e667ae200f3e.newtartcap.com *.9af44bd1-718a-4d03-9cb7-0ca73e13586c.newtartcap.com *.accounts.newtartcap.com *.admin.newtartcap.com *.api.newtartcap.com *.app.newtartcap.com *.backup.newtartcap.com *.ce6faf4b-0c23-4ece-b1fc-d02e3d09ccea.newtartcap.com *.cloud.newtartcap.com *.d36d1a22-963c-47c1-befb-5ec3471bcee8.newtartcap.com *.dc53dbe3-5284-44aa-8769-e861193e85d7.newtartcap.com *.dev.newtartcap.com *.ivxvbprod.newtartcap.com *.m.newtartcap.com *.mail.newtartcap.com *.news.newtartcap.com newtartcap.com *.newtartcap.com *.portal.newtartcap.com *.prod.newtartcap.com *.random.newtartcap.com *.rd.newtartcap.com *.rds.newtartcap.com *.rdweb.newtartcap.com *.remote.newtartcap.com *.sitemap.newtartcap.com *.sitemaps.newtartcap.com *.smtp.newtartcap.com *.staging.newtartcap.com *.test.newtartcap.com *.uat.newtartcap.com *.webmail.newtartcap.com *.ww25.newtartcap.com *.www.newtartcap.com
*.hostmaster.ofnude.com ofnude.com *.ofnude.com
*.anyconnect.rancano.com *.clientesvpn.rancano.com *.connect.rancano.com *.gateway.rancano.com *.hostmaster.rancano.com *.mail.rancano.com *.mobileconnect.rancano.com *.officevpn.rancano.com *.owa.rancano.com *.portal.rancano.com rancano.com *.rancano.com *.rds.rancano.com *.rds1.rancano.com *.rdweb.rancano.com *.remote.rancano.com *.remote2.rancano.com *.remoto.rancano.com *.secure.rancano.com *.sitemaps.rancano.com *.ssl.rancano.com *.sslvpn.rancano.com *.sslvpn2.rancano.com *.sslvpn3.rancano.com *.studentsvpn.rancano.com *.vpn.rancano.com *.vpn2.rancano.com *.vpn3.rancano.com *.vpnssl.rancano.com *.webmail.rancano.com *.wildcard.rancano.com *.ww11.rancano.com *.ww16.rancano.com *.ww17.rancano.com *.ww25.rancano.com *.ww38.rancano.com
*.shop.tentennm.com tentennm.com *.tentennm.com *.ww25.tentennm.com