Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=mondale.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 25, 2026
Valid Until
July 24, 2026 52 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5F:37:EA:F3:C7:A5:E6:88:41:64:1A:B7:80:6F:AD:92:63:70:C6:D7:B3:6E:36:D2:10:CE:E4:17:AD:2C:59:8D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
yoma.it *.yoma.it *.atac.yoma.it *.backend.yoma.it *.remote.yoma.it

Other domains in certificate

4nsxj0q.top *.4nsxj0q.top *.www.4nsxj0q.top
745937-coinbase.com *.745937-coinbase.com *.comww16.745937-coinbase.com *.comww25.745937-coinbase.com *.comww38.745937-coinbase.com *.ww25.745937-coinbase.com
aigiardini.com *.aigiardini.com
downloadspaces.co *.downloadspaces.co *.ww25.downloadspaces.co
*.applejacks.estjakarta.com estjakarta.com *.estjakarta.com
findinganswers.org *.findinganswers.org *.ssl.findinganswers.org *.www.findinganswers.org
liquidstart.xyz *.liquidstart.xyz *.www.liquidstart.xyz
*.analytics.mondale.it *.api.mondale.it *.backend.mondale.it *.board.mondale.it *.data.mondale.it *.dev.mondale.it *.hostmaster.mondale.it mondale.it *.mondale.it *.preprod.mondale.it *.remote.mondale.it *.staging.mondale.it *.superset.mondale.it *.www.mondale.it
mossland.co *.mossland.co *.old.mossland.co *.staging.mossland.co
*.api.namorada.it *.dev.namorada.it namorada.it *.namorada.it *.staging.namorada.it
*.com.oestado.online oestado.online *.oestado.online *.publicacoes.oestado.online
*.hostmaster.oggidomani.it *.ieri.oggidomani.it *.mx.oggidomani.it oggidomani.it *.oggidomani.it *.remote.oggidomani.it *.www.oggidomani.it
*.backup.olonail.info *.m.olonail.info olonail.info *.olonail.info
*.go.unblocksource.net unblocksource.net *.unblocksource.net
vuianime.club *.vuianime.club *.ww25.vuianime.club
*.1846m.websitegila138.cfd *.1yme1.websitegila138.cfd *.3nxyc.websitegila138.cfd *.fdy0p.websitegila138.cfd *.ip4i2.websitegila138.cfd *.j2zfz.websitegila138.cfd *.niw2v.websitegila138.cfd *.nktjv.websitegila138.cfd *.q2s8t.websitegila138.cfd *.vizaseq.websitegila138.cfd *.wakkl.websitegila138.cfd websitegila138.cfd *.websitegila138.cfd *.wsct4.websitegila138.cfd *.xbh6h.websitegila138.cfd *.y9zz2.websitegila138.cfd