|
|
| 1. General Results, most used to calculate the result |
| A | name "4.243.59.114" is ipv4 address, public suffix is not defined
|
| A | Good: All ip addresses are public addresses
|
| A | Good: destination is https
|
| A | Good - only one version with Http-Status 200
|
| A | Good: Every cookie has a SameSite Attribute with a correct value Strict/Lax/None
|
| A | Good: every https has a Strict Transport Security Header
|
| A | Good: HSTS max-age is long enough, 31536000 seconds = 365 days
|
| A | Good: HSTS has includeSubdomains - directive
|
| A | Good: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):0 complete Content-Type - header (2 urls)
|
| https://4.243.59.114/ 4.243.59.114
|
| Url with incomplete Content-Type - header - missing charset
|
| https://4.243.59.114/ 4.243.59.114
|
| Url with incomplete Content-Type - header - missing charset
|
| B | https://4.243.59.114/ 4.243.59.114
| ASP.NET_SessionId=coynoyz0p5wrlfuq4wxfpfow; path=/; HttpOnly; SameSite=Lax
| Cookie sent via https, but not marked as secure
|
| N | https://4.243.59.114/ 4.243.59.114
|
| Error - Certificate isn't trusted, RemoteCertificateNameMismatch
|
| B | No _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.4.243.59.114
|
| 2. Header-Checks |
| A | 4.243.59.114 4.243.59.114
| X-Content-Type-Options
| Ok: Header without syntax errors found: nosniff
|
| F | 4.243.59.114 4.243.59.114
| Content-Security-Policy
| Critical: Missing Header:
|
| F | 4.243.59.114 4.243.59.114
| Referrer-Policy
| Critical: Missing Header:
|
| F | 4.243.59.114 4.243.59.114
| Permissions-Policy
| Critical: Missing Header:
|
| B | 4.243.59.114 4.243.59.114
| Cross-Origin-Embedder-Policy
| Info: Missing Header
|
| B | 4.243.59.114 4.243.59.114
| Cross-Origin-Opener-Policy
| Info: Missing Header
|
| B | 4.243.59.114 4.243.59.114
| Cross-Origin-Resource-Policy
| Info: Missing Header
|
| 3. DNS- and NameServer - Checks |
| 4. Content- and Performance-critical Checks |
| http://4.243.59.114/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 4.243.59.114
|
| Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
|
| A | Good: No https + http status 200 with inline CSS / JavaScript found
|
| https://4.243.59.114/ 4.243.59.114
|
| Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
|
| https://4.243.59.114/ 4.243.59.114
|
| Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
|
| A | Good: Every https connection via port 443 supports the http/2 protocol via ALPN.
|
| A | Info: No img element found, no alt attribute checked
|
| A | Duration: 60084 milliseconds, 60.084 seconds
|