76/100 SECURITY SCORE

Certificate Information

Subject
CN=houseconstruction.it
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 05, 2026
Valid Until
September 03, 2026 75 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
60:9F:C6:C7:43:80:94:CA:5D:D8:3F:77:A0:A2:1F:F7:11:71:7B:EA:15:A3:1E:2D:BE:3B:27:CC:9E:DC:87:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
noolhar.com *.noolhar.com *.adm.noolhar.com *.banner.noolhar.com *.corp.noolhar.com *.ww25.noolhar.com

Other domains in certificate

aka678.xyz *.aka678.xyz *.osc36.aka678.xyz
anesthesie.de *.anesthesie.de
*.activity.balau.com *.an.balau.com balau.com *.balau.com
conferencecallservice.it *.conferencecallservice.it
cozyvanta.com *.cozyvanta.com *.kbim9f.cozyvanta.com
*.academy.futone.com.br *.app.futone.com.br *.aquecimento.futone.com.br *.avaliacao.futone.com.br *.backend.futone.com.br *.br.futone.com.br *.comunidade.futone.com.br *.ct.futone.com.br *.dev.futone.com.br *.esporteplus.futone.com.br futone.com.br *.futone.com.br *.gofit.futone.com.br *.jornada.futone.com.br *.livetv.futone.com.br *.llunar.futone.com.br *.materiais.futone.com.br *.mkt.futone.com.br *.online.futone.com.br *.peneira.futone.com.br *.peneiraxperience.futone.com.br *.presconto.futone.com.br *.sandbox.futone.com.br *.sub.futone.com.br *.testes.futone.com.br *.thunkable.futone.com.br *.tools.futone.com.br *.tv.futone.com.br *.urbanz.futone.com.br *.vps-4964998.futone.com.br *.ww25.futone.com.br *.ww38.futone.com.br
hotelexpedia-con.com *.hotelexpedia-con.com *.sitemaps.hotelexpedia-con.com *.ww25.hotelexpedia-con.com
*.admin.houseconstruction.it *.agent.houseconstruction.it *.api.houseconstruction.it *.autodiscover.houseconstruction.it *.backend.houseconstruction.it *.ci.houseconstruction.it *.dashboard.houseconstruction.it *.demo.houseconstruction.it *.email.houseconstruction.it *.exchange.houseconstruction.it houseconstruction.it *.houseconstruction.it *.intelligence.houseconstruction.it *.login.houseconstruction.it *.outlook.houseconstruction.it *.remote.houseconstruction.it *.staging.houseconstruction.it *.superset.houseconstruction.it *.webmail.houseconstruction.it
*.admin.neben.it *.analyze.neben.it *.auth.neben.it *.backend.neben.it *.dev.neben.it *.intelligence.neben.it neben.it *.neben.it *.report.neben.it *.research.neben.it *.staging.neben.it *.superset.neben.it
nively.it *.nively.it