Check DNS, Urls + Redirects, Certificates and Content of your Website


Update: 2020-03-04 - now 90 days later. All affected Letsencrypt certificates should be renewed. Time to remove that Info.




N

No trusted Certificate

Checked:
25.05.2020 14:37:24


Older results


1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
blog.macybritt.co
C
shops.myshopify.com
yes
1
0

A
23.227.38.64
Chicago/Illinois/United States (US) - Cloudflare, Inc.
Hostname: shops.myshopify.com
yes


www.blog.macybritt.co

Name Error
yes
1
0
*.macybritt.co
A
75.101.134.27
yes



AAAA

yes



CNAME

yes


*.blog.macybritt.co
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 48903, Flags 256



1 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.06.2020, 00:00:00, Signature-Inception: 21.05.2020, 00:00:00, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: co
co
4 DS RR in the parent zone found



1 RRSIG RR to validate DS RR found



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.06.2020, 05:00:00, Signature-Inception: 25.05.2020, 04:00:00, KeyTag 48903, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 48903 used to validate the DS RRSet in the parent zone



4 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 10384, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 43834, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 63993, Flags 256



Public Key with Algorithm 8, KeyTag 64278, Flags 256



4 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 1 Labels, original TTL: 518400 sec, Signature-expiration: 20.06.2020, 04:51:22, Signature-Inception: 21.05.2020, 03:51:42, KeyTag 10384, Signer-Name: co



Algorithm: 8, 1 Labels, original TTL: 518400 sec, Signature-expiration: 20.06.2020, 04:51:22, Signature-Inception: 21.05.2020, 03:51:42, KeyTag 43834, Signer-Name: co



Algorithm: 8, 1 Labels, original TTL: 518400 sec, Signature-expiration: 20.06.2020, 04:51:22, Signature-Inception: 21.05.2020, 03:51:42, KeyTag 63993, Signer-Name: co



Algorithm: 8, 1 Labels, original TTL: 518400 sec, Signature-expiration: 20.06.2020, 04:51:22, Signature-Inception: 21.05.2020, 03:51:42, KeyTag 64278, Signer-Name: co



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 10384 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 43834 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 63993 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 64278 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 10384, DigestType 1 and Digest "3xV4M6rVfzVh86R/F4ukbn5xg9w=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 10384, DigestType 2 and Digest "p2NYtMIulcLEpW24rckjd54IKRQtfFGwTlR2nIZAfXA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 43834, DigestType 1 and Digest "SVfKk+DWAprIv98DmtIumK1yGts=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 43834, DigestType 2 and Digest "poYC7DDE5fXTOmJNNVSaf2osk5OdSyELqPpITzsOCE4=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: macybritt.co
macybritt.co
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "kuit8l57hdr226o0tkkijaler6osnped" between the hashed NSEC3-owner "kuhpbobti66vhqcuoefs3madm0e56755" and the hashed NextOwner "kujr9i62m5e27ivcij4c5a7uk2igki5q". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 20.06.2020, 03:31:56, Signature-Inception: 21.05.2020, 03:01:00, KeyTag 63993, Signer-Name: co



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "kuit8l57hdr226o0tkkijaler6osnped" between the hashed NSEC3-owner "kuhpbobti66vhqcuoefs3madm0e56755" and the hashed NextOwner "kujr9i62m5e27ivcij4c5a7uk2igki5q". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 20.06.2020, 03:31:56, Signature-Inception: 21.05.2020, 03:01:00, KeyTag 64278, Signer-Name: co



0 DNSKEY RR found




Zone: blog.macybritt.co
blog.macybritt.co
0 DS RR in the parent zone found

Zone: www.blog.macybritt.co
www.blog.macybritt.co
0 DS RR in the parent zone found

Zone: (root)
(root)
1 DS RR published



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 48903, Flags 256



1 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.06.2020, 00:00:00, Signature-Inception: 21.05.2020, 00:00:00, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: com
com
1 DS RR in the parent zone found



1 RRSIG RR to validate DS RR found



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.06.2020, 05:00:00, Signature-Inception: 25.05.2020, 04:00:00, KeyTag 48903, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 48903 used to validate the DS RRSet in the parent zone



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 39844, Flags 256



1 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 30.05.2020, 18:24:21, Signature-Inception: 15.05.2020, 18:19:21, KeyTag 30909, Signer-Name: com



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 30.05.2020, 18:24:21, Signature-Inception: 15.05.2020, 18:19:21, KeyTag 30909, Signer-Name: com



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: myshopify.com
myshopify.com
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "mcll6flue2uc2djuon6s8u8omru4k2jl" between the hashed NSEC3-owner "mclk54m2unp3ie58imkjutr8tmrvka26" and the hashed NextOwner "mcllvr1jf1fm6d5c4lnks1ii1kfh39rn". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 30.05.2020, 05:25:28, Signature-Inception: 23.05.2020, 04:15:28, KeyTag 39844, Signer-Name: com



0 DNSKEY RR found




Zone: shops.myshopify.com
shops.myshopify.com
0 DS RR in the parent zone found



0 DNSKEY RR found




3. Name Servers

DomainNameserverNS-IP
www.blog.macybritt.co
  ns-cloud-c1.googledomains.com

macybritt.co
  ns-cloud-c1.googledomains.com
216.239.32.108
Newark/New Jersey/United States (US) - Google LLC


 
2001:4860:4802:32::6c
Ashburn/Virginia/United States (US) - Google LLC


  ns-cloud-c2.googledomains.com
216.239.34.108
Ashburn/Virginia/United States (US) - Google LLC


 
2001:4860:4802:34::6c
Ashburn/Virginia/United States (US) - Google LLC


  ns-cloud-c3.googledomains.com
216.239.36.108
Newark/New Jersey/United States (US) - Google LLC


 
2001:4860:4802:36::6c
Ashburn/Virginia/United States (US) - Google LLC


  ns-cloud-c4.googledomains.com
216.239.38.108
Ashburn/Virginia/United States (US) - Google LLC


 
2001:4860:4802:38::6c
Ashburn/Virginia/United States (US) - Google LLC

co
  ns1.cctld.co


  ns2.cctld.co


  ns3.cctld.co


  ns4.cctld.co


  ns5.cctld.co


  ns6.cctld.co


shops.myshopify.com
  dns1.p06.nsone.net / trexd-fra03-912-5410
198.51.44.6
New York/United States (US) - NSONE Inc


  ns1.dnsimple.com / 67m10
162.159.24.4
Chicago/Illinois/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1804
Columbus/North Carolina/United States (US) - CLOUDFLARE

myshopify.com
  dns1.p06.nsone.net / trexd-fra03-912-5402
198.51.44.6
New York/United States (US) - NSONE Inc


  dns2.p06.nsone.net / trexd-fra03-910-5408
198.51.45.6
New York/United States (US) - NSONE Inc


  dns3.p06.nsone.net / trexd-fra03-911-5401
198.51.44.70
New York/United States (US) - NSONE Inc


  dns4.p06.nsone.net / trexd-fra03-913-5406
198.51.45.70
New York/United States (US) - NSONE Inc


  ns1.dnsimple.com / 67m3
162.159.24.4
Chicago/Illinois/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1804
Columbus/North Carolina/United States (US) - CLOUDFLARE


  ns2.dnsimple.com / 67m28
162.159.25.4
Chicago/Illinois/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1904
Columbus/North Carolina/United States (US) - CLOUDFLARE


  ns3.dnsimple.com / 67m14
162.159.26.4
Chicago/Illinois/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1a04
Columbus/North Carolina/United States (US) - CLOUDFLARE


  ns4.dnsimple.com / 67m2
162.159.27.4
Chicago/Illinois/United States (US) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1b04
Columbus/North Carolina/United States (US) - CLOUDFLARE

com
  a.gtld-servers.net


  b.gtld-servers.net


  c.gtld-servers.net


  d.gtld-servers.net


  e.gtld-servers.net


  f.gtld-servers.net


  g.gtld-servers.net


  h.gtld-servers.net


  i.gtld-servers.net


  j.gtld-servers.net


  k.gtld-servers.net


  l.gtld-servers.net


  m.gtld-servers.net


4. SOA-Entries


Domain:co
Zone-Name:co
Primary:ns1.cctld.co
Mail:hostmaster.neustar.biz
Serial:1590409419
Refresh:900
Retry:900
Expire:604800
TTL:86400
num Entries:6


Domain:macybritt.co
Zone-Name:macybritt.co
Primary:ns-cloud-c1.googledomains.com
Mail:cloud-dns-hostmaster.google.com
Serial:1
Refresh:21600
Retry:3600
Expire:259200
TTL:300
num Entries:8


Domain:www.blog.macybritt.co
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1



Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1590410235
Refresh:1800
Retry:900
Expire:604800
TTL:86400
num Entries:3


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1590410250
Refresh:1800
Retry:900
Expire:604800
TTL:86400
num Entries:10


Domain:myshopify.com
Zone-Name:myshopify.com
Primary:dns1.p06.nsone.net
Mail:hostmaster.nsone.net
Serial:1589337335
Refresh:43200
Retry:7200
Expire:1209600
TTL:3600
num Entries:4


Domain:myshopify.com
Zone-Name:myshopify.com
Primary:ns1.dnsimple.com
Mail:admin.dnsimple.com
Serial:1477075261
Refresh:86400
Retry:7200
Expire:604800
TTL:300
num Entries:8


Domain:shops.myshopify.com
Zone-Name:myshopify.com
Primary:dns1.p06.nsone.net
Mail:hostmaster.nsone.net
Serial:1589337335
Refresh:43200
Retry:7200
Expire:1209600
TTL:3600
num Entries:1


Domain:shops.myshopify.com
Zone-Name:myshopify.com
Primary:ns1.dnsimple.com
Mail:admin.dnsimple.com
Serial:1477075261
Refresh:86400
Retry:7200
Expire:604800
TTL:300
num Entries:2


5. Screenshots

Startaddress: https://macybritt.co, address used: https://macybritt.co/, Screenshot created 2020-05-25 14:39:58 +00:0 url is insecure, certificate invalid

Mobil (412px x 732px)

399 milliseconds

Screenshot mobile - https://macybritt.co/
Mobil + Landscape (732px x 412px)

377 milliseconds

Screenshot mobile landscape - https://macybritt.co/
Screen (1280px x 1680px)

742 milliseconds

Screenshot Desktop - https://macybritt.co/

Mobile- and other Chrome-Checks

widthheight
visual Viewport412732
content Size412732

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

Chrome-Connection: secure. secure connection settings. The connection to this site is encrypted and authenticated using TLS 1.2, ECDHE_RSA with P-256, and AES_256_GCM.

Chrome-Resources : secure. all served securely. All resources on this page are served securely.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://blog.macybritt.co/
23.227.38.64
301
https://macybritt.co/
Html is minified: 100.00 %
0.190
E
Date: Mon, 25 May 2020 12:39:07 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: __cfduid=da7e6e73d399ca22e89fe20d62a3fef581590410347; Path=/; Domain=.blog.macybritt.co; Expires=2020-06-24 14:39:07; HttpOnly
X-Sorting-Hat-PodId: 99
X-Sorting-Hat-ShopId: 27941666916
X-Frame-Options: DENY
X-ShopId: 27941666916
X-ShardId: 99
Location: https://macybritt.co/
X-Request-Id: 0ed0ad72-a79b-4645-95cb-519cf5edaab5
X-Shopify-Stage: production
Content-Security-Policy: frame-ancestors 'none'; report-uri /csp-report?source%5Baction%5D=index&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=0ed0ad72-a79b-4645-95cb-519cf5edaab5
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 1; mode=block; report=/xss-report?source%5Baction%5D=index&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=0ed0ad72-a79b-4645-95cb-519cf5edaab5
X-Dc: gcp-us-east1,gcp-us-east1
NEL: {"report_to":"network-errors","max_age":2592000,"failure_fraction":0.01,"success_fraction":0.0001}
Report-To: {"group":"network-errors","max_age":2592000,"endpoints":[{"url":"https://monorail-edge.shopifycloud.com/v1/reports/nel/20190325/shopify"}]}
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 598f513e9d93d125-TXL
alt-svc: h3-27=":443"; ma=86400, h3-25=":443"; ma=86400, h3-24=":443"; ma=86400, h3-23=":443"; ma=86400
cf-request-id: 02ed711b1f0000d125f2899200000001

• https://blog.macybritt.co/
23.227.38.64
301
https://macybritt.co/
Html is minified: 100.00 %
2.494
B
Date: Mon, 25 May 2020 12:39:07 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: __cfduid=d9b8908dd0e1e9e4ec68a5cd7e52917251590410347; Path=/; Domain=.blog.macybritt.co; Expires=2020-06-24 14:39:07; HttpOnly
X-Sorting-Hat-PodId: 99
X-Sorting-Hat-ShopId: 27941666916
X-Frame-Options: DENY
X-ShopId: 27941666916
X-ShardId: 99
Location: https://macybritt.co/
Strict-Transport-Security: max-age=7889238
X-Request-Id: 4bc001e3-576c-43db-bc46-67bd982093c1
X-Shopify-Stage: production
Content-Security-Policy: block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests; report-uri /csp-report?source%5Baction%5D=index&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=4bc001e3-576c-43db-bc46-67bd982093c1
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 1; mode=block; report=/xss-report?source%5Baction%5D=index&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=4bc001e3-576c-43db-bc46-67bd982093c1
X-Dc: gcp-us-east1,gcp-us-east1
NEL: {"report_to":"network-errors","max_age":2592000,"failure_fraction":0.01,"success_fraction":0.0001}
Report-To: {"group":"network-errors","max_age":2592000,"endpoints":[{"url":"https://monorail-edge.shopifycloud.com/v1/reports/nel/20190325/shopify"}]}
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Server: cloudflare
CF-RAY: 598f5141b9ead11d-TXL
alt-svc: h3-27=":443"; ma=86400, h3-25=":443"; ma=86400, h3-24=":443"; ma=86400, h3-23=":443"; ma=86400
cf-request-id: 02ed711d150000d11da31ed200000001

• https://macybritt.co/

Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/1196
404

Html is minified: 282.77 %
3.574
N
Not Found
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
small visible content (num chars: 219)
Domain Not Configured There is no site setup for this domain, please make sure your site is setup and published. For troubleshooting help, please visit the Showit support website . Is this your website? Login | Get Help
Date: Mon, 25 May 2020 12:39:13 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close

• http://blog.macybritt.co/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
23.227.38.64
404

0.163
A
Not Found
Visible Content:
Date: Mon, 25 May 2020 12:39:10 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Set-Cookie: __cfduid=df620391cddcd63a5c68e087937f8935c1590410350; Path=/; Domain=.blog.macybritt.co; Expires=2020-06-24 14:39:10; HttpOnly
X-Sorting-Hat-PodId: 99
X-Sorting-Hat-ShopId: 27941666916
Vary: Accept-Encoding
X-Frame-Options: DENY
X-ShopId: 27941666916
X-ShardId: 99
X-Request-Id: 261e53fb-3b6b-4d8a-8db4-aee35e973707
X-Shopify-Stage: production
Content-Security-Policy: frame-ancestors 'none'; report-uri /csp-report?source%5Baction%5D=show&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=services%2Fnotary%2Facme_challenge&source%5Bsection%5D=shop_services&source%5Buuid%5D=261e53fb-3b6b-4d8a-8db4-aee35e973707
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 1; mode=block; report=/xss-report?source%5Baction%5D=show&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=services%2Fnotary%2Facme_challenge&source%5Bsection%5D=shop_services&source%5Buuid%5D=261e53fb-3b6b-4d8a-8db4-aee35e973707
X-Dc: gcp-us-east1,gcp-us-east1
Content-Encoding: gzip
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 598f5152f943d125-TXL
alt-svc: h3-27=":443"; ma=86400, h3-25=":443"; ma=86400, h3-24=":443"; ma=86400, h3-23=":443"; ma=86400
cf-request-id: 02ed7127d90000d125ea39a200000001

• https://23.227.38.64/
23.227.38.64
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
403

Html is minified: 110.22 %
2.057
N
Forbidden
Certificate error: RemoteCertificateNameMismatch
small visible content (num chars: 24)
403 Forbidden cloudflare
Server: cloudflare
Date: Mon, 25 May 2020 12:39:10 GMT
Content-Type: text/html
Content-Length: 151
Connection: close
CF-RAY: 598f5154e851d121-TXL
cf-request-id: 02ed7129100000d121b63e5200000001

7. Comments


1. General Results, most used to calculate the result

Aname "blog.macybritt.co" is subdomain, public suffix is "co", top-level-domain-type is "country-code", Country is Colombia, tld-manager is ".CO Internet S.A.S."
Agood: All ip addresses are public addresses
Warning: Only one ip address found: blog.macybritt.co has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: blog.macybritt.co has no ipv6 address.
Agood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
Ahttps://blog.macybritt.co/ 23.227.38.64
301
https://macybritt.co/
correct redirect https to https
Agood: every https has a Strict Transport Security Header
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):0 complete Content-Type - header (3 urls)
https://macybritt.co/


Url with incomplete Content-Type - header - missing charset
http://blog.macybritt.co/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 23.227.38.64


Url with incomplete Content-Type - header - missing charset
https://23.227.38.64/ 23.227.38.64


Url with incomplete Content-Type - header - missing charset
Bwarning: HSTS max-age is too short - minimum 31536000 = 365 days required, 7889238 seconds = 91 days found
Bhttps://blog.macybritt.co/ 23.227.38.64
301
__cfduid=d9b8908dd0e1e9e4ec68a5cd7e52917251590410347; Path=/; Domain=.blog.macybritt.co; Expires=2020-06-24 14:39:07; HttpOnly
Cookie sent via https, but not marked as secure
CError - no version with Http-Status 200
Ehttp://blog.macybritt.co/ 23.227.38.64
301
https://macybritt.co/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Hfatal error: No https - result with http-status 200, no encryption
Mhttps://macybritt.co/
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://23.227.38.64/ 23.227.38.64
403

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://macybritt.co/
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Nhttps://23.227.38.64/ 23.227.38.64
403

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
N23.227.38.64:2083


Error - Certificate isn't trusted, RemoteCertificateNameMismatch
N23.227.38.64:2087


Error - Certificate isn't trusted, RemoteCertificateNameMismatch
N23.227.38.64:2096


Error - Certificate isn't trusted, RemoteCertificateNameMismatch
N23.227.38.64:8443


Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain blog.macybritt.co, 1 ip addresses.

2. DNS- and NameServer - Checks

AInfo:: 13 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 4 Name Servers.
AInfo:: 13 Queries complete, 13 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
Ok (4 - 8):: An average of 3.3 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 4 different Name Servers found: ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, ns-cloud-c3.googledomains.com, ns-cloud-c4.googledomains.com, 4 Name Servers included in Delegation: ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, ns-cloud-c3.googledomains.com, ns-cloud-c4.googledomains.com, 4 Name Servers included in 1 Zone definitions: ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, ns-cloud-c3.googledomains.com, ns-cloud-c4.googledomains.com, 1 Name Servers listed in SOA.Primary: ns-cloud-c1.googledomains.com.
AGood: Only one SOA.Primary Name Server found.: ns-cloud-c1.googledomains.com.
AGood: SOA.Primary Name Server included in the delegation set.: ns-cloud-c1.googledomains.com.
Fatal: Inconsistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone.: dns1.p06.nsone.net (198.51.44.6): Delegation: ns1.dnsimple.com, Zone: dns1.p06.nsone.net
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AInfo: Ipv4-Subnet-list: 4 Name Servers, 1 different subnets (first Byte): 216., 1 different subnets (first two Bytes): 216.239., 4 different subnets (first three Bytes): 216.239.32., 216.239.34., 216.239.36., 216.239.38.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 4 Name Servers with IPv6, 1 different subnets (first block): 2001:, 1 different subnets (first two blocks): 2001:4860:, 1 different subnets (first three blocks): 2001:4860:4802:, 4 different subnets (first four blocks): 2001:4860:4802:0032:, 2001:4860:4802:0034:, 2001:4860:4802:0036:, 2001:4860:4802:0038:
AGood: Name Server IPv6 addresses from different subnets found.
AGood: Nameserver supports TCP connections: 8 good Nameserver
AGood: Nameserver supports Echo Capitalization: 8 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 8 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 8 good Nameserver
Nameserver doesn't pass all EDNS-Checks: ns-cloud-c1.googledomains.com: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
AGood: All SOA have the same Serial Number
Agood: CAA entries found, creating certificate is limited: digicert.com is allowed to create certificates
Agood: CAA entries found, creating certificate is limited: globalsign.com is allowed to create certificates
Agood: CAA entries found, creating certificate is limited: letsencrypt.org is allowed to create certificates

3. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: All CSS / JavaScript files are sent with GZip. That reduces the content of the files. 1 external CSS / JavaScript files found
Warning: CSS / JavaScript files with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 0 external CSS / JavaScript files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 1 with Cache-Control max-age too short (minimum 7 days), 0 with Cache-Control long enough, 1 complete.
AGood: All checked attribute values are enclosed in quotation marks (" or ').
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://macybritt.co/
404
3.574 seconds
Warning: 404 needs more then one second
ADuration: 159723 milliseconds, 159.723 seconds


8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
macybritt.co
macybritt.co
443
Certificate/chain invalid and wrong name
Tls12
ECDH Ephermal
256
Aes256
256
Sha384
error checking OCSP stapling
ok
macybritt.co
macybritt.co
443
Certificate/chain invalid and wrong name
Tls12

ECDH Ephermal
256
Aes256
256
Sha384
error checking OCSP stapling
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Self signed certificate
1CN=ssl-not-available-for-domain


blog.macybritt.co
23.227.38.64
443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok

blog.macybritt.co
23.227.38.64
443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=blog.macybritt.co

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


23.227.38.64
23.227.38.64
443
name does not match
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

23.227.38.64
23.227.38.64
443
name does not match
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, C=US, ST=CA

2CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, C=US, ST=CA


blog.macybritt.co
blog.macybritt.co
2083
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok

blog.macybritt.co
blog.macybritt.co
2083
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=blog.macybritt.co

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


blog.macybritt.co
blog.macybritt.co
2087
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok

blog.macybritt.co
blog.macybritt.co
2087
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=blog.macybritt.co

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


blog.macybritt.co
blog.macybritt.co
2096
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok

blog.macybritt.co
blog.macybritt.co
2096
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=blog.macybritt.co

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


blog.macybritt.co
blog.macybritt.co
8443
ok
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok

blog.macybritt.co
blog.macybritt.co
8443
ok
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
error checking OCSP stapling
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=blog.macybritt.co

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


23.227.38.64
23.227.38.64
2083
name does not match
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

23.227.38.64
23.227.38.64
2083
name does not match
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, C=US, ST=CA

2CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, C=US, ST=CA


23.227.38.64
23.227.38.64
2087
name does not match
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

23.227.38.64
23.227.38.64
2087
name does not match
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, C=US, ST=CA

2CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, C=US, ST=CA


23.227.38.64
23.227.38.64
2096
name does not match
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

23.227.38.64
23.227.38.64
2096
name does not match
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, C=US, ST=CA

2CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, C=US, ST=CA


23.227.38.64
23.227.38.64
8443
name does not match
Tls12
ECDH Ephermal
255
Aes128
128
Sha256
supported
ok

23.227.38.64
23.227.38.64
8443
name does not match
Tls12

ECDH Ephermal
255
Aes128
128
Sha256
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, C=US, ST=CA

2CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, C=US, ST=CA


9. Certificates

1.
1.
CN=blog.macybritt.co
18.05.2020
16.08.2020
expires in 72 days
blog.macybritt.co - 1 entry
1.
1.
CN=blog.macybritt.co
18.05.2020

16.08.2020
expires in 72 days
blog.macybritt.co - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0366495ADAFA9281DF63465757132D86E78B
Thumbprint:DEEF63AF8AF8F4E01EE9DA8C383D7620227E58F6
SHA256 / Certificate:IHN+gfsc2BnWT3juURgfh0dViDKfPZX/07JJtMXzeik=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):5cf24c32fab4069398c8ddd6b6342a63c5bc72d250d88a82d21ac02c6b11fe71
SHA256 hex / Subject Public Key Information (SPKI):ecebbffb27729545bf033a4221063bdba1c14d70e22f9c654741b9d7b3160a7c
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.int-x3.letsencrypt.org
OCSP - must staple:no
Certificate Transparency:yes


2.
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
17.03.2016
17.03.2021
expires in 285 days


2.
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
17.03.2016

17.03.2021
expires in 285 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0A0141420000015385736A0B85ECA708
Thumbprint:E6A3B45B062D509B3382282D196EFE97D5956CCB
SHA256 / Certificate:JYR9Zo608E/dQLErawdAxWfafQJDCOtsLJb+QdneIY0=
SHA256 hex / Cert (DANE * 0 1):25847d668eb4f04fdd40b12b6b0740c567da7d024308eb6c2c96fe41d9de218d
SHA256 hex / PublicKey (DANE * 1 1):60b87575447dcba2a36b7d11ac09fb24a9db406fee12d2cc90180517616e8a18
SHA256 hex / Subject Public Key Information (SPKI):cbb93d32de628874a3ecfb92affadc97f1b795f84cc6f24221a089dee1aa25ad
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://isrg.trustid.ocsp.identrust.com
OCSP - must staple:no
Certificate Transparency:no


3.
CN=DST Root CA X3, O=Digital Signature Trust Co.
30.09.2000
30.09.2021
expires in 482 days


3.
CN=DST Root CA X3, O=Digital Signature Trust Co.
30.09.2000

30.09.2021
expires in 482 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:44AFB080D6A327BA893039862EF8406B
Thumbprint:DAC9024F54D8F6DF94935FB1732638CA6AD77C13
SHA256 / Certificate:BocmAzGnJAPZCfEF5pvPDTLhvSST/8bZIG0RvNZ3Bzk=
SHA256 hex / Cert (DANE * 0 1):0687260331a72403d909f105e69bcf0d32e1bd2493ffc6d9206d11bcd6770739
SHA256 hex / PublicKey (DANE * 1 1):563b3caf8cfef34c2335caf560a7a95906e8488462eb75ac59784830df9e5b2b
SHA256 hex / Subject Public Key Information (SPKI):29cc40db5e2de462a311cbbafaa1dc466960002335ecdf3317f2cd05c1d0bedf
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no


2.
1.
CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, S=CA, C=US
20.04.2020
09.10.2020
expires in 126 days
myshopify.com, *.myshopify.com - 2 entries
2.
1.
CN=*.myshopify.com, O="Cloudflare, Inc.", L=San Francisco, S=CA, C=US
20.04.2020

09.10.2020
expires in 126 days
myshopify.com, *.myshopify.com - 2 entries

KeyalgorithmEC Public Key (256 bit, prime256v1)
Signatur:ECDSA SHA256
Serial Number:0C24A61828A2996721BE1831B3E02CFD
Thumbprint:9988D47679BF3DC3CB5AC3065C9E75DB281C555C
SHA256 / Certificate:OY5C0ZdAUsZRF+w1izuaNDnaal5MW8HqfTcW/Fuwzh8=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):26885590b23967d13b7fd188e41a25eb14ae4fd3778edd4b24dfe10e6cd19408
SHA256 hex / Subject Public Key Information (SPKI):3e53c787f3083342e0e63280f74d7222ad0d6fac615d63469000f8fd7f6c9689
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes


2.
CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US
14.10.2015
09.10.2020
expires in 126 days


2.
CN=CloudFlare Inc ECC CA-2, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US
14.10.2015

09.10.2020
expires in 126 days


KeyalgorithmEC Public Key (256 bit, prime256v1)
Signatur:SHA256 With RSA-Encryption
Serial Number:0FF3E61639AA3D1A1265F41F8B34E5B6
Thumbprint:6B53C3B358CEF368201F8741B9C5AEDEEA3861FA
SHA256 / Certificate:YXLXoZlsvvcaAYLdRLmenANXQqnr0DEapzqkczNExaY=
SHA256 hex / Cert (DANE * 0 1):6172d7a1996cbef71a0182dd44b99e9c035742a9ebd0311aa73aa4733344c5a6
SHA256 hex / PublicKey (DANE * 1 1):de470d27391427546a317273157e19c6ec7959f1132beb8be958aaf6524d9f8a
SHA256 hex / Subject Public Key Information (SPKI):6e1ac9cc83daee79c0c88380664860d703e65f8cb5beaa296bce133e0d1d2614
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no


3.
CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE
12.05.2000
13.05.2025
expires in 1803 days


3.
CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE
12.05.2000

13.05.2025
expires in 1803 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:020000B9
Thumbprint:D4DE20D05E66FC53FE1A50882C78DB2852CAE474
SHA256 / Certificate:Fq9XqfZ2sKsSYJWqXrre8iqzERnWRKyVzUuT2/Pyaus=
SHA256 hex / Cert (DANE * 0 1):16af57a9f676b0ab126095aa5ebadef22ab31119d644ac95cd4b93dbf3f26aeb
SHA256 hex / PublicKey (DANE * 1 1):63d9af9b47b1064d49a10e7b7fd566dbc8caa399459bfc2829c571ad8c6ef34a
SHA256 hex / Subject Public Key Information (SPKI):42a7bca6ba3cafb2f3e1400ba4346bc1db07b9855841258c6d362802e17d1fe0
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no


3.
1.
CN=ssl-not-available-for-domain
23.02.2018
21.02.2028
expires in 2817 days

3.
1.
CN=ssl-not-available-for-domain
23.02.2018

21.02.2028
expires in 2817 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:00CC1378F42D0BC320
Thumbprint:AD61CAAD19F2BF2B3583D461DC8AA184440F71D1
SHA256 / Certificate:k28rzPqDRNV54SBbdXZz+GKh2fhMNV4/GhlXkeXu0nE=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):c59056bcfc70730725816732a14919f2f58ed45225f266ecf964807ad4479694
SHA256 hex / Subject Public Key Information (SPKI):46279dbda66b4e0566a45f62014854a65c52f335b0417950017ae30e79a8e97d
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no

UntrustedRoot: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.


10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
0
3
3

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
1643535036
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-22 18:47:16
2020-08-20 18:47:16
blog.macybritt.co - 1 entries


1635530257
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-19 16:35:01
2020-08-17 16:35:01
blog.macybritt.co - 1 entries


1633346087
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-18 20:16:09
2020-08-16 20:16:09
blog.macybritt.co - 1 entries



2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > 2019 are listed

Issuerlast 7 daysactivenum Certs
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
0 /0 new
3
3

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
2845511662
precert
Leaf-2845511662
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-22 16:47:16
2020-08-20 16:47:16
blog.macybritt.co
1 entries


2830713782
precert
Leaf-2830713782
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-19 14:35:01
2020-08-17 14:35:01
blog.macybritt.co
1 entries


2829220400
precert
Leaf-2829220400
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-05-18 18:16:09
2020-08-16 18:16:09
blog.macybritt.co
1 entries



11. Html-Content - Entries

Summary

Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://macybritt.co/
a

3

0


0
0
0


link
stylesheet
1

0
0
1
1
0
0
-1

meta
other
2

0


0
0
0

Details

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://macybritt.co/

a

http://app.showit.co/


1
ok








a

http://help.showit.co/


2
ok








link
stylesheet
https://fonts.googleapis.com/css?family=Lato:300,400
200

1
ok
text/css; charset=utf-8, X-Content-Type-Options nosniff found

GZip: 222/436 Bytes




Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

sha256-/71MNluGRAdJRZUnntaF8FDCgdva0o9WhrEiwaLVQa4=
sha384-9wl7BhK4yfYljKlK+OuG4RKePE/plpRmcynt9IohsjI6L5OXQUjTeyRQSPT+pVm3
sha512-f10VhAdDO+zLrunwXwFEDI8LGKGhqZjrsak6In80B4bWkmUkDAOmKXL4fLmnhXkvdiVUs1XoN9pokk4FBZ4cbw==

<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Lato:300,400" crossorigin="anonymous" integrity="sha256-/71MNluGRAdJRZUnntaF8FDCgdva0o9WhrEiwaLVQa4=" />



Content loaded via url("...")

https://fonts.gstatic.com/s/lato/v16/S6u9w4BMUTPHh7USSwiPHA.ttf1
https://fonts.gstatic.com/s/lato/v16/S6uyw4BMUTPHjx4wWw.ttf1

meta

UTF-8


1
ok








meta
viewport
width=device-width, initial-scale=1.0


1
ok








12. Nameserver - IP-Adresses (alpha)

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns-cloud-c1.googledomains.com, ns-cloud-c2.googledomains.com, ns-cloud-c3.googledomains.com, ns-cloud-c4.googledomains.com

QNr.DomainTypeNS used
1
com
NS
h.root-servers.net (2001:500:1::53)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
ns-cloud-c1.googledomains.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns5.googledomains.com, ns6.googledomains.com, ns7.googledomains.com, ns8.googledomains.com

Answer: ns5.googledomains.com
2001:4860:4802:32::a, 216.239.32.10

Answer: ns6.googledomains.com
2001:4860:4802:34::a, 216.239.34.10

Answer: ns7.googledomains.com
2001:4860:4802:36::a, 216.239.36.10

Answer: ns8.googledomains.com
2001:4860:4802:38::a, 216.239.38.10
3
ns-cloud-c2.googledomains.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns5.googledomains.com, ns6.googledomains.com, ns7.googledomains.com, ns8.googledomains.com

Answer: ns5.googledomains.com
2001:4860:4802:32::a, 216.239.32.10

Answer: ns6.googledomains.com
2001:4860:4802:34::a, 216.239.34.10

Answer: ns7.googledomains.com
2001:4860:4802:36::a, 216.239.36.10

Answer: ns8.googledomains.com
2001:4860:4802:38::a, 216.239.38.10
4
ns-cloud-c3.googledomains.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns5.googledomains.com, ns6.googledomains.com, ns7.googledomains.com, ns8.googledomains.com

Answer: ns5.googledomains.com
2001:4860:4802:32::a, 216.239.32.10

Answer: ns6.googledomains.com
2001:4860:4802:34::a, 216.239.34.10

Answer: ns7.googledomains.com
2001:4860:4802:36::a, 216.239.36.10

Answer: ns8.googledomains.com
2001:4860:4802:38::a, 216.239.38.10
5
ns-cloud-c4.googledomains.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns5.googledomains.com, ns6.googledomains.com, ns7.googledomains.com, ns8.googledomains.com

Answer: ns5.googledomains.com
2001:4860:4802:32::a, 216.239.32.10

Answer: ns6.googledomains.com
2001:4860:4802:34::a, 216.239.34.10

Answer: ns7.googledomains.com
2001:4860:4802:36::a, 216.239.36.10

Answer: ns8.googledomains.com
2001:4860:4802:38::a, 216.239.38.10
6
ns-cloud-c1.googledomains.com: 216.239.32.108
A
ns5.googledomains.com (2001:4860:4802:32::a)
7
ns-cloud-c1.googledomains.com: 2001:4860:4802:32::6c
AAAA
ns5.googledomains.com (2001:4860:4802:32::a)
8
ns-cloud-c2.googledomains.com: 216.239.34.108
A
ns5.googledomains.com (2001:4860:4802:32::a)
9
ns-cloud-c2.googledomains.com: 2001:4860:4802:34::6c
AAAA
ns5.googledomains.com (2001:4860:4802:32::a)
10
ns-cloud-c3.googledomains.com: 216.239.36.108
A
ns5.googledomains.com (2001:4860:4802:32::a)
11
ns-cloud-c3.googledomains.com: 2001:4860:4802:36::6c
AAAA
ns5.googledomains.com (2001:4860:4802:32::a)
12
ns-cloud-c4.googledomains.com: 216.239.38.108
A
ns5.googledomains.com (2001:4860:4802:32::a)
13
ns-cloud-c4.googledomains.com: 2001:4860:4802:38::6c
AAAA
ns5.googledomains.com (2001:4860:4802:32::a)


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
shops.myshopify.com
5
issue
digicert.com
1
0

5
issue
globalsign.com
1
0

5
issue
letsencrypt.org
1
0
blog.macybritt.co



1
0
myshopify.com
0

no CAA entry found
1
0
macybritt.co
0

no CAA entry found
1
0
com
0

no CAA entry found
1
0
co
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
macybritt.co

ok
1
0
myshopify.com
ca3-9b7d9a06dfbf45a38d25b542ed3710fc
ok
1
0
myshopify.com
v=spf1 -all
ok
1
0
blog.macybritt.co


1
0
shops.myshopify.com

ok
1
0
_acme-challenge.blog.macybritt.co

Name Error - The domain name does not exist
1
0
_acme-challenge.shops.myshopify.com

Name Error - The domain name does not exist
1
0
_acme-challenge.blog.macybritt.co.macybritt.co

Name Error - The domain name does not exist
1
0
_acme-challenge.shops.myshopify.com.myshopify.com


1
0
_acme-challenge.blog.macybritt.co.blog.macybritt.co

Name Error - The domain name does not exist
1
0
_acme-challenge.shops.myshopify.com.shops.myshopify.com

Name Error - The domain name does not exist
1
0


15. Portchecks

Domain or IPPortDescriptionResultAnswer
blog.macybritt.co
21
FTP



blog.macybritt.co
21
FTP



blog.macybritt.co
22
SSH



blog.macybritt.co
22
SSH



blog.macybritt.co
25
SMTP



blog.macybritt.co
25
SMTP



blog.macybritt.co
53
DNS



blog.macybritt.co
53
DNS



blog.macybritt.co
110
POP3



blog.macybritt.co
110
POP3



blog.macybritt.co
143
IMAP



blog.macybritt.co
143
IMAP



blog.macybritt.co
465
SMTP (encrypted)



blog.macybritt.co
465
SMTP (encrypted)



blog.macybritt.co
587
SMTP (encrypted, submission)



blog.macybritt.co
587
SMTP (encrypted, submission)



blog.macybritt.co
993
IMAP (encrypted)



blog.macybritt.co
993
IMAP (encrypted)



blog.macybritt.co
995
POP3 (encrypted)



blog.macybritt.co
995
POP3 (encrypted)



blog.macybritt.co
1433
MS SQL



blog.macybritt.co
1433
MS SQL



blog.macybritt.co
2082
cPanel (http)
open
http://blog.macybritt.co:2082/
Http-Status: 403
Forbidden

blog.macybritt.co
2082
cPanel (http)
open
http://blog.macybritt.co:2082/
Http-Status: 403
Forbidden

blog.macybritt.co
2083
cPanel (https)
open
https://blog.macybritt.co:2083/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2083
cPanel (https)
open
https://blog.macybritt.co:2083/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2086
WHM (http)
open
http://blog.macybritt.co:2086/
Http-Status: 403
Forbidden

blog.macybritt.co
2086
WHM (http)
open
http://blog.macybritt.co:2086/
Http-Status: 403
Forbidden

blog.macybritt.co
2087
WHM (https)
open
https://blog.macybritt.co:2087/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2087
WHM (https)
open
https://blog.macybritt.co:2087/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2089
cPanel Licensing



blog.macybritt.co
2089
cPanel Licensing



blog.macybritt.co
2095
cPanel Webmail (http)
open
http://blog.macybritt.co:2095/
Http-Status: 403
Forbidden

blog.macybritt.co
2095
cPanel Webmail (http)
open
http://blog.macybritt.co:2095/
Http-Status: 403
Forbidden

blog.macybritt.co
2096
cPanel Webmail (https)
open
https://blog.macybritt.co:2096/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2096
cPanel Webmail (https)
open
https://blog.macybritt.co:2096/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
2222
DirectAdmin (http)



blog.macybritt.co
2222
DirectAdmin (http)



blog.macybritt.co
2222
DirectAdmin (https)



blog.macybritt.co
2222
DirectAdmin (https)



blog.macybritt.co
3306
mySql



blog.macybritt.co
3306
mySql



blog.macybritt.co
5224
Plesk Licensing



blog.macybritt.co
5224
Plesk Licensing



blog.macybritt.co
5432
PostgreSQL



blog.macybritt.co
5432
PostgreSQL



blog.macybritt.co
8080
Ookla Speedtest (http)
open
http://blog.macybritt.co:8080/
Http-Status: 403
Forbidden

blog.macybritt.co
8080
Ookla Speedtest (http)
open
http://blog.macybritt.co:8080/
Http-Status: 403
Forbidden

blog.macybritt.co
8080
Ookla Speedtest (https)
open
https://blog.macybritt.co:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

blog.macybritt.co
8080
Ookla Speedtest (https)
open
https://blog.macybritt.co:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

blog.macybritt.co
8083
VestaCP http



blog.macybritt.co
8083
VestaCP http



blog.macybritt.co
8083
VestaCP https



blog.macybritt.co
8083
VestaCP https



blog.macybritt.co
8443
Plesk Administration (https)
open
https://blog.macybritt.co:8443/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
8443
Plesk Administration (https)
open
https://blog.macybritt.co:8443/
Http-Status: 403
Forbidden
Certificate is valid
blog.macybritt.co
8447
Plesk Installer + Updates



blog.macybritt.co
8447
Plesk Installer + Updates



blog.macybritt.co
8880
Plesk Administration (http)
open
http://blog.macybritt.co:8880/
Http-Status: 403
Forbidden

blog.macybritt.co
8880
Plesk Administration (http)
open
http://blog.macybritt.co:8880/
Http-Status: 403
Forbidden

blog.macybritt.co
10000
Webmin (http)



blog.macybritt.co
10000
Webmin (http)



blog.macybritt.co
10000
Webmin (https)



blog.macybritt.co
10000
Webmin (https)



23.227.38.64
21
FTP



23.227.38.64
21
FTP



23.227.38.64
22
SSH



23.227.38.64
22
SSH



23.227.38.64
25
SMTP



23.227.38.64
25
SMTP



23.227.38.64
53
DNS



23.227.38.64
53
DNS



23.227.38.64
110
POP3



23.227.38.64
110
POP3



23.227.38.64
143
IMAP



23.227.38.64
143
IMAP



23.227.38.64
465
SMTP (encrypted)



23.227.38.64
465
SMTP (encrypted)



23.227.38.64
587
SMTP (encrypted, submission)



23.227.38.64
587
SMTP (encrypted, submission)



23.227.38.64
993
IMAP (encrypted)



23.227.38.64
993
IMAP (encrypted)



23.227.38.64
995
POP3 (encrypted)



23.227.38.64
995
POP3 (encrypted)



23.227.38.64
1433
MS SQL



23.227.38.64
1433
MS SQL



23.227.38.64
2082
cPanel (http)
open
http://23.227.38.64:2082/
Http-Status: 403
Forbidden

23.227.38.64
2082
cPanel (http)
open
http://23.227.38.64:2082/
Http-Status: 403
Forbidden

23.227.38.64
2083
cPanel (https)
open
https://23.227.38.64:2083/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2083
cPanel (https)
open
https://23.227.38.64:2083/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2086
WHM (http)
open
http://23.227.38.64:2086/
Http-Status: 403
Forbidden

23.227.38.64
2086
WHM (http)
open
http://23.227.38.64:2086/
Http-Status: 403
Forbidden

23.227.38.64
2087
WHM (https)
open
https://23.227.38.64:2087/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2087
WHM (https)
open
https://23.227.38.64:2087/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2089
cPanel Licensing



23.227.38.64
2089
cPanel Licensing



23.227.38.64
2095
cPanel Webmail (http)
open
http://23.227.38.64:2095/
Http-Status: 403
Forbidden

23.227.38.64
2095
cPanel Webmail (http)
open
http://23.227.38.64:2095/
Http-Status: 403
Forbidden

23.227.38.64
2096
cPanel Webmail (https)
open
https://23.227.38.64:2096/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2096
cPanel Webmail (https)
open
https://23.227.38.64:2096/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
2222
DirectAdmin (http)



23.227.38.64
2222
DirectAdmin (http)



23.227.38.64
2222
DirectAdmin (https)



23.227.38.64
2222
DirectAdmin (https)



23.227.38.64
3306
mySql



23.227.38.64
3306
mySql



23.227.38.64
5224
Plesk Licensing



23.227.38.64
5224
Plesk Licensing



23.227.38.64
5432
PostgreSQL



23.227.38.64
5432
PostgreSQL



23.227.38.64
8080
Ookla Speedtest (http)
open
http://23.227.38.64:8080/
Http-Status: 403
Forbidden

23.227.38.64
8080
Ookla Speedtest (http)
open
http://23.227.38.64:8080/
Http-Status: 403
Forbidden

23.227.38.64
8080
Ookla Speedtest (https)
open
https://23.227.38.64:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

23.227.38.64
8080
Ookla Speedtest (https)
open
https://23.227.38.64:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

23.227.38.64
8083
VestaCP http



23.227.38.64
8083
VestaCP http



23.227.38.64
8083
VestaCP https



23.227.38.64
8083
VestaCP https



23.227.38.64
8443
Plesk Administration (https)
open
https://23.227.38.64:8443/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
8443
Plesk Administration (https)
open
https://23.227.38.64:8443/
Http-Status: 403
Forbidden
Certificate is invalid
23.227.38.64
8447
Plesk Installer + Updates



23.227.38.64
8447
Plesk Installer + Updates



23.227.38.64
8880
Plesk Administration (http)
open
http://23.227.38.64:8880/
Http-Status: 403
Forbidden

23.227.38.64
8880
Plesk Administration (http)
open
http://23.227.38.64:8880/
Http-Status: 403
Forbidden

23.227.38.64
10000
Webmin (http)



23.227.38.64
10000
Webmin (http)



23.227.38.64
10000
Webmin (https)



23.227.38.64
10000
Webmin (https)





Permalink: https://check-your-website.server-daten.de/?i=6a4769ae-8463-42dd-b954-1a174daf67d5


Last Result: https://check-your-website.server-daten.de/?q=blog.macybritt.co - 2020-05-25 14:37:24


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=blog.macybritt.co" target="_blank">Check this Site: blog.macybritt.co</a>