Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=iscream.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
49:83:A8:52:50:F4:F3:9D:3B:A1:B3:75:9C:EF:64:26:7E:86:94:2C:68:F8:4D:08:BF:B4:4F:BC:5A:A9:76:F2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
tipus.it
*.tipus.it
iscream.it
*.iscream.it
jewqirecter.com
*.jewqirecter.com
jobs-abroad-africa-5.click
*.jobs-abroad-africa-5.click
jodhpurssingular.com
*.jodhpurssingular.com
johnclassick.com
*.johnclassick.com
justswipe.it
*.justswipe.it
kqu34.top
*.kqu34.top
lacamiciasumisura.it
*.lacamiciasumisura.it
leverages.it
*.leverages.it
liberdy.io
*.liberdy.io
linklearntaxescertifcation.com
*.linklearntaxescertifcation.com
lovefinancialfreedom.com
*.lovefinancialfreedom.com
maku.it
*.maku.it
manclub.guide
*.manclub.guide
marriage-consultation.click
*.marriage-consultation.click
mediatorsarizona.com
*.mediatorsarizona.com
mejof.pro
*.mejof.pro
mercewise.com
*.mercewise.com
mevia.it
*.mevia.it
mnemotechny.com
*.mnemotechny.com
mortarella.it
*.mortarella.it
rmvuw.gdn
*.rmvuw.gdn
safety-cylinder.com
*.safety-cylinder.com
salesexperience.it
*.salesexperience.it
sanah.it
*.sanah.it
satpalmaharaj.com
*.satpalmaharaj.com
sharkgrrl.com
*.sharkgrrl.com
shibuya-medical-478174888.click
*.shibuya-medical-478174888.click
shjyy.net
*.shjyy.net
shminjing.cn
*.shminjing.cn
showtearillos.com
*.showtearillos.com
shreh.pro
*.shreh.pro
sicurezzacantieri.it
*.sicurezzacantieri.it
snclud539.icu
*.snclud539.icu
southernlinkec.com
*.southernlinkec.com
taichibci.com
*.taichibci.com
taliequali.it
*.taliequali.it
taule.it
*.taule.it
thecrawler.it
*.thecrawler.it
thesecretbooks.it
*.thesecretbooks.it
tinyzero.xyz
*.tinyzero.xyz
travelyoung.it
*.travelyoung.it
ukr-agroprom.com
*.ukr-agroprom.com
upmove.it
*.upmove.it
Other domains in certificate