Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=offsalemk.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 22, 2026
Valid Until
July 21, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4D:9C:40:A8:95:0C:B6:1F:F1:0F:AA:FA:87:39:D9:33:8F:1E:A0:38:E5:AF:24:7E:96:10:E3:14:64:E1:83:63
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
videotopolis.com *.videotopolis.com *.demo.videotopolis.com *.www.videotopolis.com

Other domains in certificate

*.admin.avvocatidomiciliatari.it *.analytic.avvocatidomiciliatari.it *.analytics.avvocatidomiciliatari.it *.analyze.avvocatidomiciliatari.it *.api.avvocatidomiciliatari.it *.app.avvocatidomiciliatari.it avvocatidomiciliatari.it *.avvocatidomiciliatari.it *.bi.avvocatidomiciliatari.it *.board.avvocatidomiciliatari.it *.data.avvocatidomiciliatari.it *.forecast.avvocatidomiciliatari.it *.notexistsbackend.avvocatidomiciliatari.it *.notexistsdemo.avvocatidomiciliatari.it *.remote.avvocatidomiciliatari.it *.reporting.avvocatidomiciliatari.it *.research.avvocatidomiciliatari.it *.status.avvocatidomiciliatari.it
*.cloud.erecaidpump.com erecaidpump.com *.erecaidpump.com *.help.erecaidpump.com
*.demo.gazetapraca.com gazetapraca.com *.gazetapraca.com
*.a.offsalemk.com offsalemk.com *.offsalemk.com
*.aa653858-7841-45f3-a927-5e6348fbfdd5.polkadot-qr-code.com *.backup.polkadot-qr-code.com *.git.polkadot-qr-code.com *.hostmaster.polkadot-qr-code.com *.members.polkadot-qr-code.com *.new.polkadot-qr-code.com polkadot-qr-code.com *.polkadot-qr-code.com *.staging.polkadot-qr-code.com
*.0925998e-9147-41f3-a9a9-732b855d4bcd.taxmed.ch *.099cbda9-d406-43c9-a925-39cbe0e2b689.taxmed.ch *.09cc7ef8-8f99-41b1-8231-200969be031f.taxmed.ch *.110f83dc-df54-4e19-882f-c7f76e553277.taxmed.ch *.69538a6e-5170-44ab-84f8-588c9534e8df.taxmed.ch *.948efb40-c483-42b5-9e52-7f9cad73dff9.taxmed.ch *.a57f92c7-8db7-4a24-b609-e3f0a8db1605.taxmed.ch *.account.taxmed.ch *.admin.taxmed.ch *.ae24068b-1a9e-460a-89d3-415425ae74e2.taxmed.ch *.agent.taxmed.ch *.analytics-preview.taxmed.ch *.api.taxmed.ch *.app.taxmed.ch *.client.taxmed.ch *.customer.taxmed.ch *.dashboard.taxmed.ch *.dev.taxmed.ch *.help.taxmed.ch *.home.taxmed.ch *.intranet.taxmed.ch *.kunde.taxmed.ch *.kunden.taxmed.ch *.kundenportal.taxmed.ch *.m.taxmed.ch *.mobile.taxmed.ch *.my.taxmed.ch *.news.taxmed.ch *.nextcloud.taxmed.ch *.partner.taxmed.ch *.portal.taxmed.ch *.qa.taxmed.ch *.rds.taxmed.ch *.rdweb.taxmed.ch *.shop.taxmed.ch *.staging.taxmed.ch *.store.taxmed.ch taxmed.ch *.taxmed.ch *.user.taxmed.ch *.users.taxmed.ch *.wap.taxmed.ch *.web.taxmed.ch *.webmail.taxmed.ch *.www.taxmed.ch
*.fb9ff9e8-663a-46cc-8bc1-b8c905cdd6c2.tdxflixx.clinic *.investors.tdxflixx.clinic tdxflixx.clinic *.tdxflixx.clinic