Check DNS, Urls + Redirects, Certificates and Content of your Website





1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
aruba.it
A
62.149.188.200
Arezzo/Tuscany/Italy (IT) - Aruba S.p.A. Network
No Hostname found
yes
1
0

AAAA

yes


www.aruba.it
CNAME
www.aruba.it.cdn.cloudflare.net
yes
1
0

A
104.22.0.79
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.
No Hostname found
yes



A
104.22.1.79
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.
No Hostname found
yes



A
172.67.20.213
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.
No Hostname found
yes



AAAA
2606:4700:10::6816:4f
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.

yes



AAAA
2606:4700:10::6816:14f
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.

yes



AAAA
2606:4700:10::ac43:14d5
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.

yes


*.aruba.it
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 46780, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.12.2023, 00:00:00 +, Signature-Inception: 10.11.2023, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: it
it
1 DS RR in the parent zone found



DS with Algorithm 10, KeyTag 41901, DigestType 2 and Digest R/f3uiHkhZH2Fy7tE+NbZrk62fKID8m62mT2jOKOu5A=



1 RRSIG RR to validate DS RR found



RRSIG-Owner it., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 25.11.2023, 17:00:00 +, Signature-Inception: 12.11.2023, 16:00:00 +, KeyTag 46780, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46780 used to validate the DS RRSet in the parent zone



2 DNSKEY RR found



Public Key with Algorithm 10, KeyTag 18395, Flags 256



Public Key with Algorithm 10, KeyTag 41901, Flags 257 (SEP = Secure Entry Point)



2 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner it., Algorithm: 10, 1 Labels, original TTL: 10800 sec, Signature-expiration: 13.12.2023, 00:04:48 +, Signature-Inception: 13.11.2023, 00:04:48 +, KeyTag 18395, Signer-Name: it



RRSIG-Owner it., Algorithm: 10, 1 Labels, original TTL: 10800 sec, Signature-expiration: 13.12.2023, 00:04:48 +, Signature-Inception: 13.11.2023, 00:04:48 +, KeyTag 41901, Signer-Name: it



Status: Good - Algorithmus 10 and DNSKEY with KeyTag 18395 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 10 and DNSKEY with KeyTag 41901 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 10, KeyTag 41901, DigestType 2 and Digest "R/f3uiHkhZH2Fy7tE+NbZrk62fKID8m62mT2jOKOu5A=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: aruba.it
aruba.it
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "3b4n0qgh4fulm6hjgfcet2tnnknse8b0" between the hashed NSEC3-owner "3b2eebf1r9fot0epn1rmm36fv5uler7n" and the hashed NextOwner "3b6br20gdeujcljo8st6ke99cet3lm5p". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 3b2eebf1r9fot0epn1rmm36fv5uler7n.it., Algorithm: 10, 2 Labels, original TTL: 3600 sec, Signature-expiration: 13.12.2023, 00:04:48 +, Signature-Inception: 13.11.2023, 00:04:48 +, KeyTag 18395, Signer-Name: it



DS-Query in the parent zone sends valid NSEC3 RR with the Hash "rs1n3n7m54pdem5eunv9npkh3b6cgpjc" as Owner. That's the Hash of "it" with the NextHashedOwnerName "rs45884srcl7kjjiep3cu8c925t3vlvn". So that domain name is the Closest Encloser of "aruba.it". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner rs1n3n7m54pdem5eunv9npkh3b6cgpjc.it., Algorithm: 10, 2 Labels, original TTL: 3600 sec, Signature-expiration: 13.12.2023, 00:04:48 +, Signature-Inception: 13.11.2023, 00:04:48 +, KeyTag 18395, Signer-Name: it



0 DNSKEY RR found




Zone: www.aruba.it
www.aruba.it
0 DS RR in the parent zone found

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 46780, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.12.2023, 00:00:00 +, Signature-Inception: 10.11.2023, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: net
net
1 DS RR in the parent zone found



DS with Algorithm 13, KeyTag 37331, DigestType 2 and Digest LwvsLW95370dCP0ho6+S0OOaS57x4/QRH/8oJJDaRTs=



1 RRSIG RR to validate DS RR found



RRSIG-Owner net., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 25.11.2023, 17:00:00 +, Signature-Inception: 12.11.2023, 16:00:00 +, KeyTag 46780, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46780 used to validate the DS RRSet in the parent zone



4 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 35886, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 13, KeyTag 37331, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 13, KeyTag 44222, Flags 256



Public Key with Algorithm 8, KeyTag 51464, Flags 256



2 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner net., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.11.2023, 15:10:35 +, Signature-Inception: 09.11.2023, 15:05:35 +, KeyTag 35886, Signer-Name: net



RRSIG-Owner net., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.11.2023, 15:10:35 +, Signature-Inception: 09.11.2023, 15:05:35 +, KeyTag 37331, Signer-Name: net



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 35886 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 13 and DNSKEY with KeyTag 37331 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 37331, DigestType 2 and Digest "LwvsLW95370dCP0ho6+S0OOaS57x4/QRH/8oJJDaRTs=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: cloudflare.net
cloudflare.net
1 DS RR in the parent zone found



DS with Algorithm 13, KeyTag 2371, DigestType 2 and Digest kPcQoQfaUe14El0wpocEzzwDCK/QG/zXBX1L0Dtixos=



2 RRSIG RR to validate DS RR found



RRSIG-Owner cloudflare.net., Algorithm: 13, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.11.2023, 08:11:51 +, Signature-Inception: 09.11.2023, 07:01:51 +, KeyTag 44222, Signer-Name: net



RRSIG-Owner cloudflare.net., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.11.2023, 08:11:51 +, Signature-Inception: 09.11.2023, 07:01:51 +, KeyTag 51464, Signer-Name: net



Status: Good - Algorithmus 13 and DNSKEY with KeyTag 44222 used to validate the DS RRSet in the parent zone



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 51464 used to validate the DS RRSet in the parent zone



2 DNSKEY RR found



Public Key with Algorithm 13, KeyTag 2371, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 13, KeyTag 34505, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner cloudflare.net., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.12.2023, 08:02:54 +, Signature-Inception: 29.10.2023, 08:02:54 +, KeyTag 2371, Signer-Name: cloudflare.net



Status: Good - Algorithmus 13 and DNSKEY with KeyTag 2371 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 2371, DigestType 2 and Digest "kPcQoQfaUe14El0wpocEzzwDCK/QG/zXBX1L0Dtixos=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: cdn.cloudflare.net
cdn.cloudflare.net
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "cdn.cloudflare.net" and the NextOwner "\000.cdn.cloudflare.net". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA



0 DNSKEY RR found




Zone: it.cdn.cloudflare.net
it.cdn.cloudflare.net
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "it.cdn.cloudflare.net" and the NextOwner "\000.it.cdn.cloudflare.net". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA



0 DNSKEY RR found




Zone: aruba.it.cdn.cloudflare.net
aruba.it.cdn.cloudflare.net
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "aruba.it.cdn.cloudflare.net" and the NextOwner "\000.aruba.it.cdn.cloudflare.net". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA



0 DNSKEY RR found




Zone: www.aruba.it.cdn.cloudflare.net
www.aruba.it.cdn.cloudflare.net
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "www.aruba.it.cdn.cloudflare.net" and the NextOwner "\000.www.aruba.it.cdn.cloudflare.net". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA



0 DNSKEY RR found






RRSIG Type 1 validates the A - Result: 104.22.0.79 104.22.1.79 172.67.20.213
Validated: RRSIG-Owner www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 6 Labels, original TTL: 300 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



RRSIG Type 28 validates the AAAA - Result: 2606:4700:0010:0000:0000:0000:6816:004F 2606:4700:0010:0000:0000:0000:6816:014F 2606:4700:0010:0000:0000:0000:AC43:14D5
Validated: RRSIG-Owner www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 6 Labels, original TTL: 300 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



CNAME-Query sends a valid NSEC RR as result with the query name "www.aruba.it.cdn.cloudflare.net" equal the NSEC-owner "www.aruba.it.cdn.cloudflare.net" and the NextOwner "\000.www.aruba.it.cdn.cloudflare.net". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA Validated: RRSIG-Owner www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 6 Labels, original TTL: 1800 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



Status: Good. NoData-Proof required and found.



TXT-Query sends a valid NSEC RR as result with the query name "www.aruba.it.cdn.cloudflare.net" equal the NSEC-owner "www.aruba.it.cdn.cloudflare.net" and the NextOwner "\000.www.aruba.it.cdn.cloudflare.net". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, 13, MX, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI, CAA Validated: RRSIG-Owner www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 6 Labels, original TTL: 1800 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



Status: Good. NoData-Proof required and found.



TLSA-Query (_443._tcp.www.aruba.it.cdn.cloudflare.net) sends a valid NSEC RR as result with the query name "_443._tcp.www.aruba.it.cdn.cloudflare.net" equal the NSEC-owner "_443._tcp.www.aruba.it.cdn.cloudflare.net" and the NextOwner "\000._443._tcp.www.aruba.it.cdn.cloudflare.net". So the zone confirmes the not-existence of that TLSA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, 53, HIP, 61, 64, 65, URI, CAA Validated: RRSIG-Owner _443._tcp.www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 8 Labels, original TTL: 1800 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



Status: Good. NoData-Proof required and found.



CAA-Query sends a valid NSEC RR as result with the query name "www.aruba.it.cdn.cloudflare.net" equal the NSEC-owner "www.aruba.it.cdn.cloudflare.net" and the NextOwner "\000.www.aruba.it.cdn.cloudflare.net". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, 13, MX, TXT, AAAA, LOC, SRV, NAPTR, CERT, SSHFP, RRSIG, NSEC, TLSA, 53, HIP, 61, 64, 65, URI Validated: RRSIG-Owner www.aruba.it.cdn.cloudflare.net., Algorithm: 13, 6 Labels, original TTL: 1800 sec, Signature-expiration: 14.11.2023, 02:08:54 +, Signature-Inception: 12.11.2023, 00:08:54 +, KeyTag 34505, Signer-Name: cloudflare.net



Status: Good. NoData-Proof required and found.


3. Name Servers

DomainNameserverNS-IP
aruba.it
  arudns1.aruba.it
94.177.210.15
Arezzo/Tuscany/Italy (IT) - Aruba S.p.A. Network


  arudns2.aruba.it
95.110.136.13
Ponte San Pietro/Lombardy/Italy (IT) - Aruba S.p.A.


  arudns3.aruba.it
95.110.220.15
Ponte San Pietro/Lombardy/Italy (IT) - Aruba S.p.A. Network


  arudns4.aruba.it
81.2.199.101
Prague/Czechia (CZ) - INTERNET CZ

it
  a.dns.it


  d.dns.it


  dns.nic.it


  m.dns.it


  nameserver.cnr.it


  r.dns.it


www.aruba.it.cdn.cloudflare.net
  ns1.cloudflare.net
173.245.59.31
San Francisco/California/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3b1f
San Francisco/California/United States (US) - CLOUDFLARE

aruba.it.cdn.cloudflare.net
  ns1.cloudflare.net
173.245.59.31
San Francisco/California/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3b1f
San Francisco/California/United States (US) - CLOUDFLARE

it.cdn.cloudflare.net
  ns1.cloudflare.net
173.245.59.31
San Francisco/California/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3b1f
San Francisco/California/United States (US) - CLOUDFLARE

cdn.cloudflare.net
  ns1.cloudflare.net
173.245.59.31
San Francisco/California/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3b1f
San Francisco/California/United States (US) - CLOUDFLARE

cloudflare.net
  ns1.cloudflare.net
173.245.59.31
San Francisco/California/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3b1f
San Francisco/California/United States (US) - CLOUDFLARE


  ns2.cloudflare.net
198.41.222.131
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::c629:de83
San Francisco/California/United States (US) - CLOUDFLARE


  ns3.cloudflare.net
198.41.222.31
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::c629:de1f
San Francisco/California/United States (US) - CLOUDFLARE


  ns4.cloudflare.net
198.41.223.131
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::c629:df83
San Francisco/California/United States (US) - CLOUDFLARE


  ns5.cloudflare.net
198.41.223.31
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::c629:df1f
San Francisco/California/United States (US) - CLOUDFLARE

net
  a.gtld-servers.net


  b.gtld-servers.net


  c.gtld-servers.net


  d.gtld-servers.net


  e.gtld-servers.net


  f.gtld-servers.net


  g.gtld-servers.net


  h.gtld-servers.net


  i.gtld-servers.net


  j.gtld-servers.net


  k.gtld-servers.net


  l.gtld-servers.net


  m.gtld-servers.net


4. SOA-Entries


Domain:it
Zone-Name:it
Primary:dns.nic.it
Mail:hostmaster.nic.it
Serial:2023111302
Refresh:10800
Retry:900
Expire:604800
TTL:3600
num Entries:6


Domain:aruba.it
Zone-Name:aruba.it
Primary:arudns1.aruba.it
Mail:hostmaster.aruba.it
Serial:76462678
Refresh:86400
Retry:7200
Expire:2592000
TTL:3600
num Entries:4



Domain:net
Zone-Name:net
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1699837689
Refresh:1800
Retry:900
Expire:604800
TTL:86400
num Entries:13


Domain:cloudflare.net
Zone-Name:cloudflare.net
Primary:ns1.cloudflare.net
Mail:dns.cloudflare.com
Serial:2324138674
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:10


Domain:cdn.cloudflare.net
Zone-Name:cloudflare.net
Primary:ns1.cloudflare.net
Mail:dns.cloudflare.com
Serial:2324138674
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:2


Domain:it.cdn.cloudflare.net
Zone-Name:cloudflare.net
Primary:ns1.cloudflare.net
Mail:dns.cloudflare.com
Serial:2324138674
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:2


Domain:aruba.it.cdn.cloudflare.net
Zone-Name:cloudflare.net
Primary:ns1.cloudflare.net
Mail:dns.cloudflare.com
Serial:2324138674
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:2


Domain:www.aruba.it.cdn.cloudflare.net
Zone-Name:cloudflare.net
Primary:ns1.cloudflare.net
Mail:dns.cloudflare.com
Serial:2324138674
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:2


5. Screenshots

Startaddress: https://www.aruba.it/home.aspx, address used: https://www.aruba.it/home.aspx, Screenshot created 2023-11-13 02:12:04 +00:0

Mobil (412px x 732px)

661 milliseconds

Screenshot mobile - https://www.aruba.it/home.aspx
Mobil + Landscape (732px x 412px)

763 milliseconds

Screenshot mobile landscape - https://www.aruba.it/home.aspx
Screen (1280px x 1680px)

1368 milliseconds

Screenshot Desktop - https://www.aruba.it/home.aspx

Mobile- and other Chrome-Checks

widthheight
visual Viewport396732
content Size3967147

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://aruba.it/
62.149.188.200
301
http://www.aruba.it/
Html is minified: 100.00 %
0.097
D
Content-Type: text/html; charset=UTF-8
Location: http://www.aruba.it/
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Mon, 13 Nov 2023 01:09:38 GMT
Connection: close
Content-Length: 143

• http://www.aruba.it/
104.22.0.79
301
https://www.aruba.it/
0.047
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 825321670861fbd6-WAW

• http://www.aruba.it/
104.22.1.79
301
https://www.aruba.it/
0.046
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 825321674bd770b7-WAW

• http://www.aruba.it/
172.67.20.213
301
https://www.aruba.it/
0.047
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 8253216798de34b0-WAW

• http://www.aruba.it/
2606:4700:10::6816:4f
301
https://www.aruba.it/
0.047
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 825321685cbb65a5-FRA

• http://www.aruba.it/
2606:4700:10::6816:14f
301
https://www.aruba.it/
0.046
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 82532167fa25bb3d-FRA

• http://www.aruba.it/
2606:4700:10::ac43:14d5
301
https://www.aruba.it/
0.063
A
Date: Mon, 13 Nov 2023 01:09:39 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 13 Nov 2023 02:09:39 GMT
Location: https://www.aruba.it/
Vary: Accept-Encoding
Server: cloudflare
CF-RAY: 82532168bf992bf8-FRA

• https://aruba.it/
62.149.188.200
301
http://www.aruba.it/
Html is minified: 100.00 %
3.423
F
Content-Type: text/html; charset=UTF-8
Location: http://www.aruba.it/
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Mon, 13 Nov 2023 01:09:39 GMT
Connection: close
Content-Length: 143

• https://www.aruba.it/
104.22.0.79
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
2.764
B
Date: Mon, 13 Nov 2023 01:09:43 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:43 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 82532184ef885025-WAW

• https://www.aruba.it/
104.22.1.79
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
2.716
B
Date: Mon, 13 Nov 2023 01:09:47 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:47 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 8253219afc3434b2-WAW

• https://www.aruba.it/
172.67.20.213
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
2.734
B
Date: Mon, 13 Nov 2023 01:09:51 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:51 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 825321b12ff4500c-WAW

• https://www.aruba.it/
2606:4700:10::6816:4f
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
3.326
B
Date: Mon, 13 Nov 2023 01:09:58 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:58 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 825321e0ae353736-FRA

• https://www.aruba.it/
2606:4700:10::6816:14f
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
3.250
B
Date: Mon, 13 Nov 2023 01:09:54 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:54 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 825321c79d169968-FRA

• https://www.aruba.it/
2606:4700:10::ac43:14d5
301
https://www.aruba.it/home.aspx
Html is minified: 100.00 %
3.310
B
Date: Mon, 13 Nov 2023 01:10:03 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
location: /home.aspx
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:10:03 GMT; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 825321fd09033835-FRA

• https://www.aruba.it/home.aspx
GZip used - 60459 / 243020 - 75.12 %
200

Html is minified: 126.70 %
3.467
B
Date: Mon, 13 Nov 2023 01:11:26 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
cache-control: no-cache, must-revalidate
pragma: no-cache
expires: -1
set-cookie: CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:11:26 GMT; path=/; secure; HttpOnly,CMSCsrfCookie=A7oU7f832zoMp5/ZTvGfkMhCq75xm7LzyUtRKjlF; path=/; secure; HttpOnly
strict-transport-security: max-age=31536000; includeSubDomains
x-frame-options: deny
x-content-type-options: nosniff
content-security-policy: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
x-permitted-cross-domain-policies: none
referrer-policy: strict-origin-when-cross-origin
cross-origin-opener-policy: same-origin
permissions-policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
cross-origin-embedder-policy: unsafe-none
cross-origin-resource-policy: same-origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 82532406bef99bbe-FRA
Content-Encoding: gzip

• http://aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
62.149.188.200
301
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.00 %
0.096
D
Visible Content: Object Moved This document may be found here
Content-Type: text/html; charset=UTF-8
Location: http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Mon, 13 Nov 2023 01:10:06 GMT
Connection: close
Content-Length: 212

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
104.22.0.79
-14

10.046
T
Timeout - The operation has timed out
Visible Content:

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
104.22.1.79
-14

10.044
T
Timeout - The operation has timed out
Visible Content:

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
172.67.20.213
-14

10.046
T
Timeout - The operation has timed out
Visible Content:

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2606:4700:10::6816:4f
-14

10.044
T
Timeout - The operation has timed out
Visible Content:

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2606:4700:10::6816:14f
-14

10.060
T
Timeout - The operation has timed out
Visible Content:

• http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2606:4700:10::ac43:14d5
-14

10.046
T
Timeout - The operation has timed out
Visible Content:

• https://104.22.0.79/
104.22.0.79
-10

0.047
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://104.22.1.79/
104.22.1.79
-10

0.063
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://172.67.20.213/
172.67.20.213
-10

0.030
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://62.149.188.200/
62.149.188.200
404

Html is minified: 103.96 %
3.437
N
Not Found
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
small visible content (num chars: 162)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"> Not Found Not Found HTTP Error 404. The requested resource is not found.
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Mon, 13 Nov 2023 01:11:07 GMT
Connection: close
Content-Length: 315

• https://[2606:4700:0010:0000:0000:0000:6816:004f]/
2606:4700:10::6816:4f
-10

0.060
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://[2606:4700:0010:0000:0000:0000:6816:014f]/
2606:4700:10::6816:14f
-10

0.060
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://[2606:4700:0010:0000:0000:0000:ac43:14d5]/
2606:4700:10::ac43:14d5
-10

0.063
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

7. Comments


1. General Results, most used to calculate the result

Aname "aruba.it" is domain, public suffix is ".it", top-level-domain is ".it", top-level-domain-type is "country-code", Country is Italy, tld-manager is "IIT - CNR", num .it-domains preloaded: 1890 (complete: 231048)
AGood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: www.aruba.it has 6 different ip addresses (authoritative).
AGood: Ipv4 and Ipv6 addresses per domain name found: www.aruba.it has 3 ipv4, 3 ipv6 addresses
Warning: Only one ip address found: aruba.it has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: aruba.it has no ipv6 address.
AGood: No asked Authoritative Name Server had a timeout
Ahttps://www.aruba.it/ 104.22.0.79
301
https://www.aruba.it/home.aspx
Correct redirect https to https
Ahttps://www.aruba.it/ 104.22.1.79
301
https://www.aruba.it/home.aspx
Correct redirect https to https
Ahttps://www.aruba.it/ 172.67.20.213
301
https://www.aruba.it/home.aspx
Correct redirect https to https
Ahttps://www.aruba.it/ 2606:4700:10::6816:4f
301
https://www.aruba.it/home.aspx
Correct redirect https to https
Ahttps://www.aruba.it/ 2606:4700:10::6816:14f
301
https://www.aruba.it/home.aspx
Correct redirect https to https
Ahttps://www.aruba.it/ 2606:4700:10::ac43:14d5
301
https://www.aruba.it/home.aspx
Correct redirect https to https
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: www is preferred
AGood: No cookie sent via http.
AGood: every cookie sent via https is marked as secure
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: All urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset)
Ahttp://www.aruba.it/ 104.22.0.79
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Ahttp://www.aruba.it/ 104.22.1.79
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Ahttp://www.aruba.it/ 172.67.20.213
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Ahttp://www.aruba.it/ 2606:4700:10::6816:4f
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Ahttp://www.aruba.it/ 2606:4700:10::6816:14f
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Ahttp://www.aruba.it/ 2606:4700:10::ac43:14d5
301
https://www.aruba.it/
Correct redirect http - https with the same domain name
Bhttps://aruba.it/ 62.149.188.200
301

Missing HSTS-Header
Bhttps://www.aruba.it/ 104.22.0.79
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:43 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/ 104.22.1.79
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:47 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/ 172.67.20.213
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:51 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/ 2606:4700:10::6816:4f
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:58 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/ 2606:4700:10::6816:14f
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:09:54 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/ 2606:4700:10::ac43:14d5
301
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:10:03 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/home.aspx
200
CMSPreferredCulture=it-IT; expires=Wed, 13-Nov-2024 01:11:26 GMT; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.aruba.it/home.aspx
200
CMSCsrfCookie=A7oU7f832zoMp5/ZTvGfkMhCq75xm7LzyUtRKjlF; path=/; secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Dhttp://aruba.it/ 62.149.188.200
301
http://www.aruba.it/
Wrong redirect one domain http to other domain http. First redirect to https without changing the domain, so no new dns query is required. So the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Dhttp://aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 62.149.188.200
301
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Wrong redirect one domain http to other domain http. First redirect to https without changing the domain, so no new dns query is required. So the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Fhttps://aruba.it/ 62.149.188.200
301
http://www.aruba.it/
Wrong redirect https - http - never redirect https to http
Mhttps://62.149.188.200/ 62.149.188.200
404

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://62.149.188.200/ 62.149.188.200
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Phttps://104.22.0.79/ 104.22.0.79
-10

Error creating a TLS-Connection: No more details available.
Phttps://104.22.1.79/ 104.22.1.79
-10

Error creating a TLS-Connection: No more details available.
Phttps://172.67.20.213/ 172.67.20.213
-10

Error creating a TLS-Connection: No more details available.
Phttps://[2606:4700:0010:0000:0000:0000:6816:004f]/ 2606:4700:10::6816:4f
-10

Error creating a TLS-Connection: No more details available.
Phttps://[2606:4700:0010:0000:0000:0000:6816:014f]/ 2606:4700:10::6816:14f
-10

Error creating a TLS-Connection: No more details available.
Phttps://[2606:4700:0010:0000:0000:0000:ac43:14d5]/ 2606:4700:10::ac43:14d5
-10

Error creating a TLS-Connection: No more details available.
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain www.aruba.it, 6 ip addresses.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain aruba.it, 1 ip addresses.
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain www.aruba.it, 6 ip addresses.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.aruba.it

2. Header-Checks

Awww.aruba.it
Content-Security-Policy
Ok: Header without syntax errors found: frame-ancestors 'self' http://wa.aruba.it https://wa.aruba.it
F

Bad: Missing default-src directive. A default-src directive is used if one of the specialized fetch directives (child-src, connect-src, font-src, frame-src, img-src, manifest-src, media-src, object-src, prefetch-src, script-src, style-src, worker-src) isn't defined. Missing default-src, all sources are allowed, that's bad. A default-src with 'none' or 'self' blocks that.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
A

Good: frame-ancestors directive found. That limits pages who are allowed to use this page in a frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
E

Bad: No base-uri directive found. Use one to limit the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
F

Critical: No object-src and no default-src as fallback defined. So object / embed / applet can load every resource. That's fatal.
F

Critical: No script-src and no default-src as fallback defined. So scripts are unlimited. That's fatal.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: strict-origin-when-cross-origin
A
Permissions-Policy
Ok: Header without syntax errors found: accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()
A
X-Frame-Options
Ok: Header without syntax errors found: deny
B

Info: Header is deprecated. May not longer work in modern browsers. deny. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.

3. DNS- and NameServer - Checks

AInfo:: 2 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 4 Name Servers.
AInfo:: 2 Queries complete, 2 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.arudns1.aruba.it (94.177.210.15), arudns2.aruba.it (95.110.136.13), arudns3.aruba.it (95.110.220.15), arudns4.aruba.it (81.2.199.101)
AGood (1 - 3.0):: An average of 0.5 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 4 different Name Servers found: arudns1.aruba.it, arudns2.aruba.it, arudns3.aruba.it, arudns4.aruba.it, 4 Name Servers included in Delegation: arudns1.aruba.it, arudns2.aruba.it, arudns3.aruba.it, arudns4.aruba.it, 4 Name Servers included in 1 Zone definitions: arudns1.aruba.it, arudns2.aruba.it, arudns3.aruba.it, arudns4.aruba.it, 1 Name Servers listed in SOA.Primary: arudns1.aruba.it.
AGood: Only one SOA.Primary Name Server found.: arudns1.aruba.it.
AGood: SOA.Primary Name Server included in the delegation set.: arudns1.aruba.it.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: arudns1.aruba.it, arudns2.aruba.it, arudns3.aruba.it, arudns4.aruba.it
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 4 different Name Servers found
Warning: No Name Server IPv6 address found. IPv6 is the future, so your name servers should be visible via IPv6.: 4 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 4 Name Servers, 1 Top Level Domain: it
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: aruba.it
AGood: Name servers with different Country locations found: 4 Name Servers, 2 Countries: CZ, IT
AInfo: Ipv4-Subnet-list: 4 Name Servers, 3 different subnets (first Byte): 81., 94., 95., 3 different subnets (first two Bytes): 81.2., 94.177., 95.110., 4 different subnets (first three Bytes): 81.2.199., 94.177.210., 95.110.136., 95.110.220.
AGood: Name Server IPv4-addresses from different subnet found:
AGood: Nameserver supports TCP connections: 4 good Nameserver
AGood: Nameserver supports Echo Capitalization: 4 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 4 good Nameserver
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

4. Content- and Performance-critical Checks

http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 104.22.0.79
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 104.22.1.79
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 172.67.20.213
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2606:4700:10::6816:4f
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2606:4700:10::6816:14f
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.aruba.it/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2606:4700:10::ac43:14d5
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 supports GZip.
https://www.aruba.it/home.aspx
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
AGood: Every https connection via port 443 supports the http/2 protocol via ALPN.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://62.149.188.200/ 62.149.188.200
404
3.437 seconds
Warning: 404 needs more then one second
AInfo: Different Server-Headers found
ADuration: 229633 milliseconds, 229.633 seconds


8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
aruba.it
62.149.188.200
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
aruba.it
62.149.188.200
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
www.aruba.it
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
www.aruba.it
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
104.22.0.79
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
104.22.0.79
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
104.22.1.79
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
104.22.1.79
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
172.67.20.213
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
172.67.20.213
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
2606:4700:10::6816:4f
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
2606:4700:10::6816:4f
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
2606:4700:10::6816:14f
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
2606:4700:10::6816:14f
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


www.aruba.it
2606:4700:10::ac43:14d5
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

www.aruba.it
2606:4700:10::ac43:14d5
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


62.149.188.200
62.149.188.200
443
Certificate/chain invalid and wrong name
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

62.149.188.200
62.149.188.200
443
Certificate/chain invalid and wrong name
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)
1CN=*.aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo

2CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo


9. Certificates

1.
1.
CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
15.03.2023
15.03.2024
expires in 101 days
aruba.it - 1 entry
1.
1.
CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
15.03.2023

15.03.2024
expires in 101 days
aruba.it - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:75248B6242D6B28F7A39A89631965B71
Thumbprint:379131994C84EE263492A82D38A97728E89888A7
SHA256 / Certificate:U8HXaDXaTrtR1s4T0usRwqN8sJXpc3ln/wZ1lrjXzp4=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):861757f981dbbd2b20b03de54468e929d9d3bfcd4e5d3de14721cdf30e3edd4d
SHA256 hex / Subject Public Key Information (SPKI):861757f981dbbd2b20b03de54468e929d9d3bfcd4e5d3de14721cdf30e3edd4d (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp09.actalis.it/VA/AUTHOV-G3
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020
22.09.2030
expires in 2483 days


2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:5C3B3F37ADFC28FE0FCFD3ABF83F8551
Thumbprint:BAD74F4D7AB128A49460692416540B5AEAA6B46A
SHA256 / Certificate:kxqqHsmyug+lmoIwL0+DBijIbZstKlCk0bLOiVxMxkg=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SHA256 hex / Subject Public Key Information (SPKI):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp05.actalis.it/VA/AUTH-ROOT
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011
22.09.2030
expires in 2483 days


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:570A119742C4E3CC
Thumbprint:F373B387065A28848AF2F34ACE192BDDC78E9CAC
SHA256 / Certificate:VZJghOyWOmS5biq+Ac4LqGpk+/68x6q1r8FVs3/XYGY=
SHA256 hex / Cert (DANE * 0 1):55926084ec963a64b96e2abe01ce0ba86a64fbfebcc7aab5afc155b37fd76066
SHA256 hex / PublicKey (DANE * 1 1):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SHA256 hex / Subject Public Key Information (SPKI):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:


2.
1.
CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
28.02.2023
28.02.2024
expires in 85 days
*.serverdedicati.aruba.it, serverdedicati.aruba.it, hosting.aruba.it, *.aruba.it, *.hosting.aruba.it, ws.aruba.it, *.ws.aruba.it, aruba.it, netwhois.tol.aruba.it - 9 entries
2.
1.
CN=aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
28.02.2023

28.02.2024
expires in 85 days
*.serverdedicati.aruba.it, serverdedicati.aruba.it, hosting.aruba.it, *.aruba.it, *.hosting.aruba.it, ws.aruba.it, *.ws.aruba.it, aruba.it, netwhois.tol.aruba.it - 9 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0415BCB9FE7BC8474439F7DCE1DEEBDB
Thumbprint:45E9AA0CCCF3BB3C4EAD579415853C3ACA900CCA
SHA256 / Certificate:cIE/kqT/ghtzUcq4w+tjZxRQlHktbH4CsOH6yYMklxU=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):d63060c0292b1c93d6424c343b7a2b4979ddcfd7cbcf76fe73dd3bd6a7f1aae4
SHA256 hex / Subject Public Key Information (SPKI):d63060c0292b1c93d6424c343b7a2b4979ddcfd7cbcf76fe73dd3bd6a7f1aae4 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp09.actalis.it/VA/AUTHOV-G3
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020
22.09.2030
expires in 2483 days


2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:5C3B3F37ADFC28FE0FCFD3ABF83F8551
Thumbprint:BAD74F4D7AB128A49460692416540B5AEAA6B46A
SHA256 / Certificate:kxqqHsmyug+lmoIwL0+DBijIbZstKlCk0bLOiVxMxkg=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SHA256 hex / Subject Public Key Information (SPKI):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp05.actalis.it/VA/AUTH-ROOT
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011
22.09.2030
expires in 2483 days


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:570A119742C4E3CC
Thumbprint:F373B387065A28848AF2F34ACE192BDDC78E9CAC
SHA256 / Certificate:VZJghOyWOmS5biq+Ac4LqGpk+/68x6q1r8FVs3/XYGY=
SHA256 hex / Cert (DANE * 0 1):55926084ec963a64b96e2abe01ce0ba86a64fbfebcc7aab5afc155b37fd76066
SHA256 hex / PublicKey (DANE * 1 1):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SHA256 hex / Subject Public Key Information (SPKI):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:


3.
1.
CN=*.aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
11.05.2021
11.05.2022
573 days expired
*.aruba.it, aruba.it - 2 entries
3.
1.
CN=*.aruba.it, O=Aruba S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
11.05.2021

11.05.2022
573 days expired
*.aruba.it, aruba.it - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:27C8C5FEFDF214556BEDAA4192319A2D
Thumbprint:11D169772490F55CB8FC99386220D32DBB3A28D8
SHA256 / Certificate:3EPjyLhrl0WhRvWOehHqFz2721kkMMoGoGgGbIhnP3g=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):745fe7bc04fe342df8dde6a9b612f04979b29ff9ac73133f99d0ae0987973361
SHA256 hex / Subject Public Key Information (SPKI):745fe7bc04fe342df8dde6a9b612f04979b29ff9ac73133f99d0ae0987973361
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp09.actalis.it/VA/AUTHOV-G3
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)

NotTimeValid: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020
22.09.2030
expires in 2483 days


2.
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, S=Bergamo, C=IT
06.07.2020

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:5C3B3F37ADFC28FE0FCFD3ABF83F8551
Thumbprint:BAD74F4D7AB128A49460692416540B5AEAA6B46A
SHA256 / Certificate:kxqqHsmyug+lmoIwL0+DBijIbZstKlCk0bLOiVxMxkg=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SHA256 hex / Subject Public Key Information (SPKI):6d7d918ba973e14a82758767b666c54eba66bf4cd5c44aa18021c2bbd415dbbf
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp05.actalis.it/VA/AUTH-ROOT
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011
22.09.2030
expires in 2483 days


3.
CN=Actalis Authentication Root CA, O=Actalis S.p.A./03358520967, L=Milan, C=IT
22.09.2011

22.09.2030
expires in 2483 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:570A119742C4E3CC
Thumbprint:F373B387065A28848AF2F34ACE192BDDC78E9CAC
SHA256 / Certificate:VZJghOyWOmS5biq+Ac4LqGpk+/68x6q1r8FVs3/XYGY=
SHA256 hex / Cert (DANE * 0 1):55926084ec963a64b96e2abe01ce0ba86a64fbfebcc7aab5afc155b37fd76066
SHA256 hex / PublicKey (DANE * 1 1):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SHA256 hex / Subject Public Key Information (SPKI):25d4913cf587097414d29d26f6c1b1942cd6d64eaf45d0fcf81526adba96d324
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:



10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo
0
0
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
4316770156
precert
CN=Actalis Organization Validated Server CA G3, O=Actalis S.p.A., L=Ponte San Pietro, C=IT, ST=Bergamo
2022-10-19 12:20:09
2023-10-19 12:20:09
*.aruba.it, aruba.it - 2 entries



2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

No CRT - CT-Log entries found


11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404


12. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: arudns1.aruba.it, arudns2.aruba.it, arudns3.aruba.it, arudns4.aruba.it

QNr.DomainTypeNS used
1
it
NS
b.root-servers.net (2001:500:200::b)

Answer: a.dns.it, d.dns.it, dns.nic.it, m.dns.it, nameserver.cnr.it, r.dns.it
2
arudns1.aruba.it: 94.177.210.15
NS
a.dns.it (2001:678:12:0:194:0:16:215)

Answer: arudns2.aruba.it
95.110.136.13

Answer: arudns3.aruba.it
95.110.220.15

Answer: arudns4.aruba.it
81.2.199.101


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.aruba.it.cdn.cloudflare.net
0

no CAA entry found
1
0
aruba.it.cdn.cloudflare.net
0

no CAA entry found
1
0
it.cdn.cloudflare.net
0

no CAA entry found
1
0
cdn.cloudflare.net
0

no CAA entry found
1
0
cloudflare.net
0

no CAA entry found
1
0
www.aruba.it



1
0
aruba.it
0

no CAA entry found
1
0
net
0

no CAA entry found
1
0
it
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
aruba.it

ok
1
0
www.aruba.it


1
0
_acme-challenge.aruba.it


1
0
_acme-challenge.www.aruba.it

Name Error - The domain name does not exist
1
0
www.aruba.it.cdn.cloudflare.net

ok
1
0
_acme-challenge.aruba.it.aruba.it

Name Error - The domain name does not exist
1
0
_acme-challenge.www.aruba.it.aruba.it

Name Error - The domain name does not exist
1
0
_acme-challenge.www.aruba.it.www.aruba.it

Name Error - The domain name does not exist
1
0
_acme-challenge.www.aruba.it.cdn.cloudflare.net

missing entry or wrong length
1
0
_acme-challenge.www.aruba.it.cdn.cloudflare.net.aruba.it.cdn.cloudflare.net

perhaps wrong
1
0
_acme-challenge.www.aruba.it.cdn.cloudflare.net.www.aruba.it.cdn.cloudflare.net

perhaps wrong
1
0


15. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

aruba.it
10
mailfree.aruba.it

0
1
ok


A


94.177.209.28

0
1
ok


CNAME



0
0
ok

_dmarc
TXT
_dmarc.aruba.it

v=DMARC1; p=none; sp=none; fo=1; rua=mailto:dmarcreport@aruba.it

0
1
ok



16. Cipher Suites

DomainIPPortCipher (OpenSsl / IANA)



Skipped, CDN used or too many ip addresses






17. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.



Permalink: https://check-your-website.server-daten.de/?i=4d12df7f-3f99-486b-b60a-d6d9eb0e6b28


Last Result: https://check-your-website.server-daten.de/?q=aruba.it - 2023-11-13 02:08:24


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=aruba.it" target="_blank">Check this Site: aruba.it</a>

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro