Check DNS, Urls + Redirects, Certificates and Content of your Website




N

No trusted Certificate

Checked:
11.07.2019 18:20:46


Older results


1. IP-Addresses

HostTIP-Addressis auth.∑ Queries∑ Timeout
carpetatributaria.noain.es
A
213.27.254.204
Barcelona/Catalonia/Spain (ES) - Colt Technology Services
No Hostname found
yes
1
0

AAAA

yes


www.carpetatributaria.noain.es

Name Error
yes
1
0


2. DNSSEC

Zone (*)DNSSEC - Informations (beta)

Zone: (root)
(root)
1 DS RR published



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 59944, Flags 256



1 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.08.2019, 00:00:00, Signature-Inception: 11.07.2019, 00:00:00, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: es
es
2 DS RR in the parent zone found



1 RRSIG RR to validate DS RR found



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.07.2019, 05:00:00, Signature-Inception: 11.07.2019, 04:00:00, KeyTag 59944, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59944 used to validate the DS RRSet in the parent zone



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 3753, Flags 256



Public Key with Algorithm 8, KeyTag 29450, Flags 257 (SEP = Secure Entry Point)



1 RRSIG RR to validate DNSKEY RR found



Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 25.07.2019, 03:45:28, Signature-Inception: 11.07.2019, 07:08:59, KeyTag 29450, Signer-Name: es



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 29450 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 29450, DigestType 1 and Digest "QXvq+0ar80MLdcXCmu94XUdrYOE=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 29450, DigestType 2 and Digest "i+wyosnP5C45O6+B/+cbUh0+lAYSpFkLR2OtxTnktWM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: noain.es
noain.es
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed domain name between the hashed NSEC3-owner and the hashed NextOwner. So the parent zone confirmes the non-existence of a DS RR.



0 DNSKEY RR found





Zone: carpetatributaria.noain.es
carpetatributaria.noain.es
0 DS RR in the parent zone found



0 DNSKEY RR found





Zone: www.carpetatributaria.noain.es
www.carpetatributaria.noain.es
0 DS RR in the parent zone found


3. Name Servers

DomainNameserverNS-IP
www.carpetatributaria.noain.es
  ps1.hostinet.com

carpetatributaria.noain.es
  ps1.hostinet.com / redirecciones
31.193.224.61
Bilbao/Basque Country/Spain (ES) - Hostinet

noain.es
  ps1.hostinet.com / redirecciones


  ps2.hostinet.com / redirecciones2

es
  a.nic.es


  f.nic.es


  g.nic.es / 1.ber.pch


  h.nic.es / ns-2.es.de8.bind


  ns1.cesca.es


  ns-es.nic.fr / dns.fra.nic.fr


  ns-ext.nic.cl / ns-ext.nic.cl 1


  sns-pb.isc.org / pb-ams-ns2.sns.isc.org


4. SOA-Entries


Domain:es
Primary:ns1.nic.es
Mail:hostmaster.nic.es
Serial:2019071104
Refresh:7200
Retry:7200
Expire:2592000
TTL:86400
num Entries:2


Domain:es
Primary:ns1.nic.es
Mail:hostmaster.nic.es
Serial:2019071105
Refresh:7200
Retry:7200
Expire:2592000
TTL:86400
num Entries:6


Domain:noain.es
Primary:ps1.hostinet.com
Mail:hostmaster.hostinet.com
Serial:2019070301
Refresh:28800
Retry:3600
Expire:604800
TTL:600
num Entries:2


Domain:carpetatributaria.noain.es
Primary:ps1.hostinet.com
Mail:hostmaster.hostinet.com
Serial:2019070301
Refresh:28800
Retry:3600
Expire:604800
TTL:600
num Entries:1


5. Url-Checks


:

:
Domainname Http-StatusredirectSec.G
• http://carpetatributaria.noain.es/
213.27.254.204
200

0.110
H
Date: Thu, 11 Jul 2019 16:21:03 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_jk/1.2.42
Last-Modified: Fri, 04 Nov 2016 13:06:37 GMT
ETag: "2d-54079581bf140"
Accept-Ranges: bytes
Content-Length: 45
Connection: close
Content-Type: text/html

• https://carpetatributaria.noain.es/
213.27.254.204
200

0.483
N
Certificate error: RemoteCertificateChainErrors
Date: Thu, 11 Jul 2019 16:21:03 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_jk/1.2.42
Last-Modified: Fri, 04 Nov 2016 13:06:37 GMT
ETag: "2d-54079581bf140"
Accept-Ranges: bytes
Content-Length: 45
Connection: close
Content-Type: text/html

• http://carpetatributaria.noain.es/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
213.27.254.204
404

0.110
A
Not Found
Visible Content:
Date: Thu, 11 Jul 2019 16:21:04 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_jk/1.2.42
Content-Length: 267
Connection: close
Content-Type: text/html; charset=iso-8859-1

6. Comments (GZip / Html minfied / Cache-Control is beta)

Aname "carpetatributaria.noain.es" is subdomain, public suffix is "es", top-level-domain-type is "country-code", Country is Spain, tld-manager is "Red.es"
Agood: All ip addresses are public addresses
Agood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
Agood: one preferred version: non-www is preferred
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):1 complete Content-Type - header (3 urls)
http://carpetatributaria.noain.es/ 213.27.254.204


Url with incomplete Content-Type - header - missing charset
https://carpetatributaria.noain.es/ 213.27.254.204


Url with incomplete Content-Type - header - missing charset
Bhttps://carpetatributaria.noain.es/ 213.27.254.204
200

Missing HSTS-Header
CError - more then one version with Http-Status 200. After all redirects, all users (and search engines) should see the same https url: Non-www or www, but not both with http status 200.
HFatal error: http result with http-status 200, no encryption. Add a redirect http ⇒ https, so every connection is secure. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop.
Nhttps://carpetatributaria.noain.es/ 213.27.254.204
200

Error - Certificate isn't trusted, RemoteCertificateChainErrors
AGood: Nameserver supports TCP connections: 1 good Nameserver
AGood: Nameserver supports Echo Capitalization: 1 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 1 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 1 good Nameserver
Nameserver doesn't pass all EDNS-Checks: ns-es.nic.fr: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: ok (dns.fra.nic.fr). COOKIE: SOA expected, but NOT found, NOERR expected, BADVER found, Version 0 expectend and found. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: ps1.hostinet.com: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: sns-pb.isc.org: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found (pb-ams-ns2.sns.isc.org). COOKIE: fatal timeout. CLIENTSUBNET: ok.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.
AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 34094 milliseconds, 34.094 seconds


7. Connections (http/2 - check is BETA)

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
carpetatributaria.noain.es
213.27.254.204
443
Certificate/chain invalid
Tls12
ECDH Ephermal
256
Aes256
256
Sha384
error checking OCSP stapling
ok
carpetatributaria.noain.es
213.27.254.204
443
Certificate/chain invalid
Tls12

ECDH Ephermal
256
Aes256
256
Sha384
error checking OCSP stapling
ok
Self signed certificate
1CN=carpetatributaria.noain.es, OU=Sistemas, O=Ayuntamiento de Noain, L=Noain, C=ES, ST=Navarra


8. Certificates

1.
1.
CN=carpetatributaria.noain.es, OU=Sistemas, O=Ayuntamiento de Noain, L=Noain, S=Navarra, C=ES
10.07.2019
09.08.2019
99 days expired

1.
1.
CN=carpetatributaria.noain.es, OU=Sistemas, O=Ayuntamiento de Noain, L=Noain, S=Navarra, C=ES
10.07.2019

09.08.2019
99 days expired


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:00EFFCDB7234A259F3
Thumbprint:1FA509122078815F7E5BC3F7771ECB7AEE4D69C4
SHA256 / Certificate:DNz39luRNaqZ5u5S6UcnHsCJu1xhhVK92kjXJcuxJjE=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):73918cc3828b67b4c454b19a72d02b2434979404a75edf357442056b068e2251
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no

UntrustedRoot: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.


9. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates

Issuerlast 7 daysactivenum Certs
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
0
2
2

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
1011719368
precert
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
2019-07-11 00:00:00
2020-07-10 12:00:00
carpetatributaria.noain.es - 1 entries


998730471
precert
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
2019-07-03 00:00:00
2020-07-02 12:00:00
carpetatributaria.noain.es - 1 entries



2. Source crt.sh - old and new certificates, sometimes very slow.

Issuerlast 7 daysactivenum Certs
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
0
2
2

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
1660540972
precert
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
2019-07-10 22:00:00
2020-07-10 10:00:00
carpetatributaria.noain.es
1 entries


1636215159
precert
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US
2019-07-02 22:00:00
2020-07-02 10:00:00
carpetatributaria.noain.es
1 entries



10. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404


11. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
carpetatributaria.noain.es
0

no CAA entry found
1
0
noain.es
0

no CAA entry found
1
0
es
0

no CAA entry found
1
0


12. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
noain.es
v=spf1 include:spf.protection.outlook.com -all
ok
1
0
noain.es
www.noain.es– 13766469
ok
1
0
carpetatributaria.noain.es

ok
1
0
_acme-challenge.carpetatributaria.noain.es

Name Error - The domain name does not exist
1
0
_acme-challenge.carpetatributaria.noain.es.noain.es

Name Error - The domain name does not exist
1
0
_acme-challenge.carpetatributaria.noain.es.carpetatributaria.noain.es

Name Error - The domain name does not exist
1
0


13. Portchecks (BETA)

Domain or IPPortDescriptionResultAnswer
carpetatributaria.noain.es
21




carpetatributaria.noain.es
21




carpetatributaria.noain.es
22




carpetatributaria.noain.es
22




carpetatributaria.noain.es
25




carpetatributaria.noain.es
25




carpetatributaria.noain.es
53




carpetatributaria.noain.es
53




carpetatributaria.noain.es
110




carpetatributaria.noain.es
110




carpetatributaria.noain.es
143




carpetatributaria.noain.es
143




carpetatributaria.noain.es
465




carpetatributaria.noain.es
465




carpetatributaria.noain.es
587




carpetatributaria.noain.es
587




carpetatributaria.noain.es
993




carpetatributaria.noain.es
993




carpetatributaria.noain.es
995




carpetatributaria.noain.es
995




carpetatributaria.noain.es
1433




carpetatributaria.noain.es
1433




carpetatributaria.noain.es
2082




carpetatributaria.noain.es
2082




carpetatributaria.noain.es
2083




carpetatributaria.noain.es
2083




carpetatributaria.noain.es
2086




carpetatributaria.noain.es
2086




carpetatributaria.noain.es
2087




carpetatributaria.noain.es
2087




carpetatributaria.noain.es
2089




carpetatributaria.noain.es
2089




carpetatributaria.noain.es
3306




carpetatributaria.noain.es
3306




carpetatributaria.noain.es
5224




carpetatributaria.noain.es
5224




carpetatributaria.noain.es
5432




carpetatributaria.noain.es
5432




carpetatributaria.noain.es
8443




carpetatributaria.noain.es
8443




carpetatributaria.noain.es
8447




carpetatributaria.noain.es
8447




carpetatributaria.noain.es
8880




carpetatributaria.noain.es
8880




213.27.254.204
21




213.27.254.204
21




213.27.254.204
22




213.27.254.204
22




213.27.254.204
25




213.27.254.204
25




213.27.254.204
53




213.27.254.204
53




213.27.254.204
110




213.27.254.204
110




213.27.254.204
143




213.27.254.204
143




213.27.254.204
465




213.27.254.204
465




213.27.254.204
587




213.27.254.204
587




213.27.254.204
993




213.27.254.204
993




213.27.254.204
995




213.27.254.204
995




213.27.254.204
1433




213.27.254.204
1433




213.27.254.204
2082




213.27.254.204
2082




213.27.254.204
2083




213.27.254.204
2083




213.27.254.204
2086




213.27.254.204
2086




213.27.254.204
2087




213.27.254.204
2087




213.27.254.204
2089




213.27.254.204
2089




213.27.254.204
3306




213.27.254.204
3306




213.27.254.204
5224




213.27.254.204
5224




213.27.254.204
5432




213.27.254.204
5432




213.27.254.204
8443




213.27.254.204
8443




213.27.254.204
8447




213.27.254.204
8447




213.27.254.204
8880




213.27.254.204
8880






Permalink: https://check-your-website.server-daten.de/?i=c7bf0b94-5b39-4214-a188-5e52e3c48fcf


Last Result: https://check-your-website.server-daten.de/?q=carpetatributaria.noain.es - 2019-07-11 18:20:46


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=carpetatributaria.noain.es" target="_blank">Check this Site: carpetatributaria.noain.es</a>