Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=modig.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 21, 2026
Valid Until
August 19, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
57:DA:D6:37:3A:2C:F8:B8:28:0E:2A:FE:9A:2B:68:88:11:1F:B9:CA:D4:3E:E4:37:DA:A4:67:E9:D1:0F:92:77
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ucpnm.org *.ucpnm.org *.app.ucpnm.org *.ns1.ucpnm.org *.ww38.ucpnm.org

Other domains in certificate

7starhd.bid *.7starhd.bid *.mail.7starhd.bid *.webdisk.7starhd.bid
cga-ns.org *.cga-ns.org *.random.cga-ns.org *.ww38.cga-ns.org
comisionando.com *.comisionando.com *.es.comisionando.com *.ww38.comisionando.com
*.aaa.howtonews.com *.admin.howtonews.com *.api.howtonews.com *.app.howtonews.com *.assets.howtonews.com *.backup.howtonews.com *.cloud.howtonews.com *.demo.howtonews.com *.dev.howtonews.com howtonews.com *.howtonews.com *.m.howtonews.com *.mail.howtonews.com *.members.howtonews.com *.rd.howtonews.com *.rds.howtonews.com *.rdweb.howtonews.com *.remote.howtonews.com *.staging.howtonews.com *.test.howtonews.com *.uat.howtonews.com *.www.howtonews.com
kandalakha.site *.kandalakha.site
*.cxxgwhostmaster.modig.it *.hostmaster.modig.it modig.it *.modig.it
*.dashboard-uat.moviezwap.club *.data.moviezwap.club *.dc-ea833a44dd1e.moviezwap.club *.mail.moviezwap.club moviezwap.club *.moviezwap.club *.qa-analytic.moviezwap.club *.staging-superset.moviezwap.club *.staging.moviezwap.club *.ww12.moviezwap.club *.www.moviezwap.club
*.comwebinaja.nojin.site nojin.site *.nojin.site *.tapera.nojin.site
*.a.okfetchasquads.com *.admin.okfetchasquads.com *.app.okfetchasquads.com *.demo.okfetchasquads.com *.dev.okfetchasquads.com okfetchasquads.com *.okfetchasquads.com *.phrxzww1.okfetchasquads.com *.rd.okfetchasquads.com *.remote.okfetchasquads.com *.uhrfard.okfetchasquads.com
*.1yme1.paintmotion.xyz *.kwid9.paintmotion.xyz paintmotion.xyz *.paintmotion.xyz
*.f.ryo305.top ryo305.top *.ryo305.top
*.astelmail.thecrawler.it *.hostmaster.thecrawler.it *.mail.thecrawler.it *.mx.thecrawler.it *.secure.thecrawler.it thecrawler.it *.thecrawler.it
*.api.zillowhomes.xyz *.app.zillowhomes.xyz *.dev.zillowhomes.xyz zillowhomes.xyz *.zillowhomes.xyz