|
|
| 1. General Results, most used to calculate the result |
A | name "143.179.158.33" is ipv4 address, public suffix is not defined
|
A | Good: All ip addresses are public addresses
|
A | Good: destination is https
|
A | Good - only one version with Http-Status 200
|
A | Good: All urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset)
|
B | https://143.179.158.33:8123/ 143.179.158.33
|
| Missing HSTS-Header
|
N | https://143.179.158.33:8123/ 143.179.158.33
|
| Error - Certificate isn't trusted, RemoteCertificateNameMismatch
|
B | No _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.143.179.158.33
|
| 2. Header-Checks |
A | 143.179.158.33 143.179.158.33
| X-Content-Type-Options
| Ok: Header without syntax errors found: nosniff
|
A |
| Referrer-Policy
| Ok: Header without syntax errors found: no-referrer
|
A |
| X-Frame-Options
| Ok: Header without syntax errors found: SAMEORIGIN
|
B |
|
| Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
|
F | 143.179.158.33 143.179.158.33
| Content-Security-Policy
| Critical: Missing Header:
|
F | 143.179.158.33 143.179.158.33
| Permissions-Policy
| Critical: Missing Header:
|
B | 143.179.158.33 143.179.158.33
| Cross-Origin-Embedder-Policy
| Info: Missing Header
|
B | 143.179.158.33 143.179.158.33
| Cross-Origin-Opener-Policy
| Info: Missing Header
|
B | 143.179.158.33 143.179.158.33
| Cross-Origin-Resource-Policy
| Info: Missing Header
|
| 3. DNS- and NameServer - Checks |
| 4. Content- and Performance-critical Checks |
| http://143.179.158.33:8123/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 143.179.158.33
|
| Fatal: Check of /.well-known/acme-challenge/random-filename is blocked, http connection error. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
|
A | Good: Every https result with status 200 has a minified Html-Content with a quota lower then 110 %.
|
| https://143.179.158.33:8123/ 143.179.158.33
|
| Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
|
| https://143.179.158.33:8123/ 143.179.158.33
|
| Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
|
A | Info: No img element found, no alt attribute checked
|
A | Duration: 30107 milliseconds, 30.107 seconds
|