76/100 SECURITY SCORE

Certificate Information

Subject
CN=sossano.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 13, 2026
Valid Until
August 11, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EB:AB:96:4D:99:EA:67:F5:03:E4:EC:3D:07:9F:4B:66:B3:3B:FE:77:34:81:20:4A:86:90:C1:B9:7F:E6:78:67
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
mintkush.com *.mintkush.com *.admin.mintkush.com *.api.mintkush.com *.app.mintkush.com *.insight.mintkush.com *.intranet.mintkush.com *.mx.mintkush.com *.portal.mintkush.com *.shop.mintkush.com *.store.mintkush.com *.www.mintkush.com *.wwww.mintkush.com

Other domains in certificate

backhoe.au *.backhoe.au
buildforfree.com *.buildforfree.com *.m.buildforfree.com
*.api.crpt.qpon *.app.crpt.qpon *.assets.crpt.qpon *.backup.crpt.qpon crpt.qpon *.crpt.qpon *.dashboard.crpt.qpon *.demo.crpt.qpon *.dev.crpt.qpon *.egyptpost.crpt.qpon *.f92c6d2b-cd9c-4333-b252-7439823a31a3.crpt.qpon *.mail.crpt.qpon *.mailer.crpt.qpon *.marketing.crpt.qpon *.members.crpt.qpon *.qa.crpt.qpon *.secure.crpt.qpon *.staging.crpt.qpon *.stg.crpt.qpon *.test.crpt.qpon *.uat.crpt.qpon *.v1.crpt.qpon *.v2.crpt.qpon *.web.crpt.qpon *.www.crpt.qpon
*.app.itomic.ai itomic.ai *.itomic.ai
*.autodiscover.lessontag.com lessontag.com *.lessontag.com *.m.lessontag.com *.sitemap.lessontag.com *.webdisk.lessontag.com
*.comune.sossano.it *.hostmaster.sossano.it sossano.it *.sossano.it
*.09c4c606-a14d-4edf-898e-c5e76d0aee18.valentuseurope.net *.admin.valentuseurope.net *.api.valentuseurope.net *.autodiscover.valentuseurope.net *.blog.valentuseurope.net *.cpanel.valentuseurope.net *.demo.valentuseurope.net *.dev.valentuseurope.net *.dns.valentuseurope.net *.einaraudur.valentuseurope.net *.ftp.valentuseurope.net *.gulliarason.valentuseurope.net *.hostmaster.valentuseurope.net *.imap.valentuseurope.net *.info.valentuseurope.net *.jira.valentuseurope.net *.kristin.valentuseurope.net *.kristingunn.valentuseurope.net *.m.valentuseurope.net *.mail.valentuseurope.net *.outlook.valentuseurope.net *.pop.valentuseurope.net *.postmaster.valentuseurope.net *.remote.valentuseurope.net *.smtp.valentuseurope.net *.snilldarkaffi.valentuseurope.net *.stage.valentuseurope.net valentuseurope.net *.valentuseurope.net *.w1.valentuseurope.net *.wap.valentuseurope.net *.webmail.valentuseurope.net *.ww2.valentuseurope.net *.www.valentuseurope.net