76/100 SECURITY SCORE

Certificate Information

Subject
CN=enpublicidad.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 07, 2026
Valid Until
May 08, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
24:8A:B8:70:39:BA:F5:A4:01:F3:34:C2:F5:BB:C8:BD:C0:1B:78:C7:54:E8:AF:6F:F3:1A:73:DF:7E:8C:9B:2E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
schuylkillriver.com *.schuylkillriver.com *.api.schuylkillriver.com *.dev.schuylkillriver.com *.mail.schuylkillriver.com *.test.schuylkillriver.com *.ww38.schuylkillriver.com

Other domains in certificate

boardu.com *.boardu.com *.hostmaster.boardu.com
*.api.brightpathservices.org *.app.brightpathservices.org brightpathservices.org *.brightpathservices.org *.dev.brightpathservices.org *.marketing.brightpathservices.org *.qa.brightpathservices.org *.secure.brightpathservices.org *.staging.brightpathservices.org *.stg.brightpathservices.org *.test.brightpathservices.org *.web.brightpathservices.org
enpublicidad.com *.enpublicidad.com *.ww17.enpublicidad.com *.ww38.enpublicidad.com
*.ad.gogo77.one *.adblock.gogo77.one *.adg.gogo77.one *.adguard1.gogo77.one *.app.gogo77.one *.auth.gogo77.one *.beta.gogo77.one *.blog.gogo77.one *.dns1.gogo77.one *.doh1.gogo77.one *.extranet.gogo77.one gogo77.one *.gogo77.one *.intranet.gogo77.one *.mail.gogo77.one *.wildcard.gogo77.one *.www.gogo77.one
goldenprimerinc.biz *.goldenprimerinc.biz *.new.goldenprimerinc.biz *.www.goldenprimerinc.biz
*.admin.guardianmortageonline.com guardianmortageonline.com *.guardianmortageonline.com *.localhost.guardianmortageonline.com *.marketing.guardianmortageonline.com *.mk.guardianmortageonline.com *.portal.guardianmortageonline.com *.sitemap.guardianmortageonline.com *.v1.guardianmortageonline.com
hotdownblouse.com *.hotdownblouse.com
*.demo.ka8.bet ka8.bet *.ka8.bet
*.acceso.occhiuzzi.com *.app.occhiuzzi.com *.citrix.occhiuzzi.com *.cloud.occhiuzzi.com *.comsusan.occhiuzzi.com *.connect.occhiuzzi.com *.desktopstudent.occhiuzzi.com *.emi.occhiuzzi.com *.fhzcsmail.occhiuzzi.com *.gateway.occhiuzzi.com *.m.occhiuzzi.com *.materiais.occhiuzzi.com occhiuzzi.com *.occhiuzzi.com *.online.occhiuzzi.com *.portal.occhiuzzi.com *.receiver.occhiuzzi.com *.remoto.occhiuzzi.com *.sitemap.occhiuzzi.com *.sitemaps.occhiuzzi.com *.sslvpn.occhiuzzi.com *.virtualstudent.occhiuzzi.com *.vpn.occhiuzzi.com *.vpnssl.occhiuzzi.com *.webvpn.occhiuzzi.com *.workspace.occhiuzzi.com
paulsebastian.com *.paulsebastian.com *.superset.paulsebastian.com