76/100 SECURITY SCORE

Certificate Information

Subject
CN=puzzleonline.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 26, 2026
Valid Until
May 27, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7F:20:D1:7C:60:B2:D1:33:53:EE:79:E9:3C:C5:6F:9D:47:C8:04:56:61:43:4C:AA:6F:0D:6C:85:A9:5E:9F:16
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
broadus.com *.broadus.com *.api.broadus.com *.app.broadus.com *.connect.broadus.com *.emv1.broadus.com *.hostmaster.broadus.com *.lyncdiscover.broadus.com *.m.broadus.com *.mail.broadus.com *.outlook.broadus.com *.owa.broadus.com *.remote.broadus.com *.secure.broadus.com *.sitemap.broadus.com *.sitemaps.broadus.com *.webmail.broadus.com *.ww11.broadus.com *.ww16.broadus.com *.ww25.broadus.com *.ww38.broadus.com

Other domains in certificate

angkorboutiquevilla.com *.angkorboutiquevilla.com *.autodiscover.angkorboutiquevilla.com
*.home.instadownload.click instadownload.click *.instadownload.click
*.admin.maxcondevelopment.com *.app.maxcondevelopment.com *.blog.maxcondevelopment.com *.brzyogph.maxcondevelopment.com *.demo.maxcondevelopment.com *.dev.maxcondevelopment.com *.fjalyxep.maxcondevelopment.com *.hdwlousz.maxcondevelopment.com *.hostmaster.maxcondevelopment.com *.magento.maxcondevelopment.com maxcondevelopment.com *.maxcondevelopment.com *.mbagzefp.maxcondevelopment.com *.sqkxzapp.maxcondevelopment.com *.test.maxcondevelopment.com *.www.maxcondevelopment.com
*.hostmaster.pettinicchi.com pettinicchi.com *.pettinicchi.com *.rustore.pettinicchi.com *.ww1.pettinicchi.com *.www.pettinicchi.com
*.dev.puzzleonline.it puzzleonline.it *.puzzleonline.it
*.0e3f569c-60fd-4403-b7c4-d9aa87061933.spotlessspace.co *.10eec0fb-8c22-42c8-b291-6ff2782b3bc8.spotlessspace.co *.admin.spotlessspace.co *.api.spotlessspace.co *.app.spotlessspace.co *.assets.spotlessspace.co *.bc7700d4-0497-440d-8559-5dfcb63386d6.spotlessspace.co *.cpanel.spotlessspace.co *.demo.spotlessspace.co *.dev.spotlessspace.co *.localhost.spotlessspace.co spotlessspace.co *.spotlessspace.co *.test.spotlessspace.co
*.3e374ba2-ce09-4473-93ea-4b05b52f7a88.taxicdmx.app *.api.taxicdmx.app *.blog.taxicdmx.app *.dev.taxicdmx.app *.docs.taxicdmx.app *.external.taxicdmx.app *.f691b186-b7c3-4c7c-ac48-171aeba7909a.taxicdmx.app *.forms.taxicdmx.app *.hostmaster.taxicdmx.app *.m.taxicdmx.app *.mail.taxicdmx.app *.my.taxicdmx.app *.news.taxicdmx.app *.portal.taxicdmx.app *.share.taxicdmx.app *.sms.taxicdmx.app taxicdmx.app *.taxicdmx.app *.taxicdmxappdev.taxicdmx.app *.taxicdmxappmovil.taxicdmx.app *.taxicdmxappmovildev.taxicdmx.app *.webmail.taxicdmx.app *.www.taxicdmx.app