Check DNS, Urls + Redirects, Certificates and Content of your Website
0 in Queue, 1 of max. 4 Checks (23:25:58)
Why should you only use Prefix - Cookies?
|
Hall of Fame -
A+
and
A
Short FAQ
show
How do I use that tool?
Insert a valid domain name, without http:// or https://, without www:
yourdomain.com
If you check a domain name, non-www and www (if defined), http and https is checked.
Add a port or / and a file and path:
yourdomain.com:5001
yourdomain.com/subfolder-of-your-domain
yourdomain.com/subfolder/file-to-check.html
yourdomain.com:5001/subfolder/file-to-check.html
Insert a valid / public ipv4- or ipv6-address:
1.1.1.1
2a01:238:301b::1226
ipv6 with port:
[2a01:238:301b::1226]:443
If you check an ip address, you may add your domain name in the "hostname" field.
That's helpful if your domain has an ipv4-address and if you want to add an ipv6-address.
You can check your ipv6-address without having an AAAA-record in your DNS.
Checking ip addresses no DNS-checks are done -> that's very short and helpful, if your name server is buggy / slow.
Sample:
https://check-your-website.server-daten.de/?q=2a01:238:301b::1226&h=www.server-daten.de
- Grade A.
If you check a port, normally one check (http or https) is wrong. Ignore that wrong result. Typical programs use only one protocol with one port. There are some programs (Ookla Speedtest, VestaCP, WebMin) who are able to use one port with both protocols http/https.
Insert a valid
Internationalized Domain Name
(IDN)
First click: The IDN is transformed to the xn-- version.
Second click: The check starts with the xn-- version.
The result of an IDN-check shows both versions.
Sometimes special code parts are updated. That requires, that no check is running. So new jobs are added to the
Queue
, but not executed (max. 0 Checks). Wait some minutes.
QR Code of your domain name required? Double-click in the text box.
Which Grade should I have, if the domain name has a website?
If it is your first certificate: Grade
B
without HSTS
and without Cookie errors. Yes, without HSTS, don't add HSTS if it's your first certificate.
If your certificate renew works: Grade
A
with HSTS. If your certificate renew
really works
, you may add the domain to the Google Preload list. Then browsers use always https to connect your domain. That's Grade
A+
.
Short:
Fatal:
Domain doesn't end with a public suffix, isn't registered, private ip addresses are defined (
Z
,
U
,
Y
).
Port 80 and port 443 must answer, no TCP-errors (
V
,
W
), Timeouts (
T
), Server Errors (
S
)
No global SSL error or only Tls.1.3 (
P
), http over port 443 or https over port 80 (
Q
)
All certificates are valid (no
N
), no misconfiguration (
M
), no wrong redirects (
R
)
No old/weak connection or insecure Cipher Suites (
O
), no Loop (
L
), no different ip addresses of the same domain name with different answers (
K
)
No mixed content / missing resources, errors in svg definitions etc. (
I
)
If you have one of these errors, users may have problems using your site.
Better:
No http result (
H
)
Correct redirects (no
F
,
E
,
D
)
If non-www + www is defined: One destination (no
C
)
No cookies via http or cookie errors, all https cookies secure, SameSite-Attribute (
B
without warnings)
If HSTS is defined: No HSTS-parse errors
If you use HSTS and your certificate is invalid (wrong domain name, expired, revoked), visitors can't create an exception in their browser. So it's impossible to visit your site. HSTS requires an
always valid certificate
, so you shouldn't add HSTS if you don't know your certificate renew works.
But if the certificate renew works, HSTS + Preload is an amazing feature. Browsers connect your domain
only
via https, so it's impossible to add cookies via http.
If your domain is preloaded: That means, your domain is in the alpha source code of Chrome included. Beta follows, then the stable version, two months. Check chrome://net-internals/#hsts - there "Query HSTS/PKP domain". Use server-daten.de to see the output of a preloaded domain, compare it with your domain. If you see "Not found", you have to wait some weeks.
I dont't run a website, I want to check my mail server ...
May be you have a pure mail server without a website. Then check it.
All standard mail ports are checked: 25, 110, 143, 465, 587, 993, 995. With their certificates, port 25 / 587 via STARTTLS.
See the Connections- and the Portcheck-Part.
Check your mail server Cipher Suites: Port 25, 465, 587, 993, 995.
Port 25 / 587 have an additional Open-Relay-Check. That's tested
after
switching to TLS via STARTTLS.
Some informations are domain-specific. If you check mail.yourdomain.net, you won't see a MX-result (because you don't have own MX entries with mail.yourdomain.net). Instead check yourdomain.net.
The result-calculation is website-specific. If you check a pure mail server without port 80 / 443, ignore the grade.
Cipher Suites...
219 Cipher Suites are checked with an own-compiled OpenSsl-Version 1.1.1 (started 2022-08-09). That works with ipv4 and ipv6
That version checks some old and normally deactivated ciphers: RC4, -NULL-, anonymous ciphers.
15 additional Ciphers are checked with the old OpenSsl 0.9.8. Ciphers with MD5, Export-Ciphers. That doesn't work with IPv6. These Ciphers are removed in OpenSsl 1.0.2.
Official versions: 1.1.1 doesn't check weak ciphers, 1.0.2 doesn't work with ipv6. Using these official versions it was impossible to check ipv6 with RC4 / -NULL- / anon.
Check of one combination Domain + IP + Port: Max. 60 - 120 seconds. Longer: Your configuration is too slow or you use too much Cipher Suites. Max. 10 - 20 are required. Half of all Cipher Checks need max. 120 seconds, 2 checks per second.
Ssl2 / Ssl3 active, insecure Ciphers or missing FS (Forward Secrecy) - Grade O. That's a global server configuration, so all ports are used to calculate the result.
Older results are not recalculated, so you may see results Grade B + no FS etc.
Check
Find
...
skip EDNS-Check
skip Content-Check
check links
Find
∑
A+
Top + Preload
662
A
Top
2687
B
no HSTS, unsecure Cookies
11948
C
Many http status 200
6438
D
redir http ⇒ http
611
E
http ⇒ https other domain
6011
F
https ⇒ http
931
H
result http
7371
I
Content problems
18910
J
General Configuration
1969
K
ip addresses with diff. status
182
L
Loop - fatal
3620
M
Misconfiguration
6206
N
Certificate not trusted
77798
O
old connection
6285
P
Tls-Protocol error
5044
Q
http sent over port 443
5207
R
redir not existing domain
994
S
Server error (500)
9588
T
Timeout
43858
U
Unknown - no dns / wrong IDN
14613
V
Connect failure
37644
W
wrong Web-Response
8510
X
DNS-problem Nameserver
51950
Y
private IP
6363
Z
private, tld not in PSL
3423
⁕
running jobs
1
⁂
Queue
0
#
error
0
started
2018-10-27
1,800 days
Domains
188.24 / day
338,825
last 24 h
Dom./Checks
72/107
Checks
281.91 / day
507,437
Current
nc.raflu.ch (35%)
⁕
xnxx.sxs.com
P
xnxx.sex
F
144.76.61.55
N
gafitvapp.win:8080
W
robins.com.ua
X
xnxx.net
X
enzoimun.bg
X
rss.mindwise.nl
X
traefik.myprivatezone.net
V
148.122.164.253
T
webmail.brani.org
U
techdoc-at-home.com
O
_acme-challenge.techdoc-at-home.com
U
abhilanka.duckdns.org
T
shaarli.mountains.nl
Y
esbo.ddns.net
X
mipsicologa.com.uy
X
mipsicologa.uy
X
app.motorlot.com
X
app1.motorlot.com
X
nextcloudbm.tplinkdns.com
U
server.yayinda.net
V
m.cryptocom.me
N
aussie24.com
L
onelove.al
O
minecraft.weerda.de
T
5sensors.co.za
X
tplinkdns.com
T
test.family-rtbpeg.dynv6.net
S
Good
attoch.org
A+
server-daten.de
A+
gorgerine.com
A
vodafone.com/business
B
xnxx.com
E
xnxx.sex
F
dhis2.nih.org.pk
I
13screens.net
I
aussie24.com
L
craft.soleimanylab.com
L
api.phira.cn
M
144.76.61.55
N
m.cryptocom.me
N
modalshopp.ir
N
pocket-book.online
N
hr.alliance.net.my
N
rafaelcalvo.work
N
forelle-suedstadt.at
N
frinstitute.com
N
techdoc-at-home.com
O
onelove.al
O
test.ganas.id
O
happycow.net
O
snapchat.com/add/n20n28
O
whatsapp.com
O
a10.rukoluo.com
O
mkdautosales.com/loan/
O
xnxx.sxs.com
P
pokemon-stinkdown.glitch.me-80.psim.us
P
test.family-rtbpeg.dynv6.net
S
Worst
shaarli.mountains.nl
Y
kdocs.appchain.solutions
Y
robins.com.ua
X
xnxx.net
X
enzoimun.bg
X
rss.mindwise.nl
X
esbo.ddns.net
X
mipsicologa.com.uy
X
mipsicologa.uy
X
app.motorlot.com
X
app1.motorlot.com
X
5sensors.co.za
X
cslsiderurgica.com
X
karthikdoes.tech
X
anarhist.net
X
userside.saimatelecom.kg
X
kontraksjs.com
X
cramica.logstr.io
X
host.sunkendreamsproductions.com
X
gafitvapp.win:8080
W
hdch.io
W
traefik.myprivatezone.net
V
server.yayinda.net
V
stalker.trinity-tv.net/stalker_portal
V
154.19.187.149
V
greve.dev
V
dev.brandapp.horae.watch
V
jahataa.com
V
webmail.brani.org
U
_acme-challenge.techdoc-at-home.com
U
Do you like this page? Support this tool, add a link on your page:
<a href="https://check-your-website.server-daten.de/" target="_blank">Check your Website</a>
Copy to Clipboard
Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro
I agree
By clicking on the button you agree that cookies are stored in your browser.
I don't agree
Information on the stored cookies can be found at
data protection#Cookies
.