Check DNS, Urls + Redirects, Certificates and Content of your Website



X

DNS-problem - authoritative Nameserver refused, not defined or timeout

Checked:
10.06.2021 13:31:13


Older results


1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
chimay.science.uva.nl
A
146.50.56.13
Havelte/Drenthe/Netherlands (NL) - Universiteit van Amsterdam
Hostname: chimay.science.uva.nl
yes
1
0

AAAA

yes


www.chimay.science.uva.nl

Name Error
yes
1
0
*.science.uva.nl
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


*.chimay.science.uva.nl
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 14631, Flags 256



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.07.2021, 00:00:00 +, Signature-Inception: 10.06.2021, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: nl
nl
1 DS RR in the parent zone found



DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=



1 RRSIG RR to validate DS RR found



RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 23.06.2021, 05:00:00 +, Signature-Inception: 10.06.2021, 04:00:00 +, KeyTag 14631, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14631 used to validate the DS RRSet in the parent zone



3 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 30171, Flags 256



Public Key with Algorithm 8, KeyTag 34112, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 59668, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 23.06.2021, 03:19:52 +, Signature-Inception: 09.06.2021, 00:08:35 +, KeyTag 34112, Signer-Name: nl



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 34112 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest "PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: uva.nl
uva.nl
1 DS RR in the parent zone found



DS with Algorithm 8, KeyTag 36184, DigestType 2 and Digest jLHVbTryZtMFmmZHl2F8+1SMM2gjyHeDmTtgMTze/Ps=



1 RRSIG RR to validate DS RR found



RRSIG-Owner uva.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 18.06.2021, 05:44:38 +, Signature-Inception: 03.06.2021, 21:09:00 +, KeyTag 59668, Signer-Name: nl



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59668 used to validate the DS RRSet in the parent zone



3 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 13170, Flags 256



Public Key with Algorithm 8, KeyTag 36184, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 60438, Flags 256



2 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner uva.nl., Algorithm: 8, 2 Labels, original TTL: 172800 sec, Signature-expiration: 13.06.2021, 18:19:40 +, Signature-Inception: 09.06.2021, 17:21:14 +, KeyTag 13170, Signer-Name: uva.nl



RRSIG-Owner uva.nl., Algorithm: 8, 2 Labels, original TTL: 172800 sec, Signature-expiration: 13.06.2021, 18:19:40 +, Signature-Inception: 09.06.2021, 17:21:14 +, KeyTag 36184, Signer-Name: uva.nl



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 13170 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 36184 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 36184, DigestType 2 and Digest "jLHVbTryZtMFmmZHl2F8+1SMM2gjyHeDmTtgMTze/Ps=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: science.uva.nl
science.uva.nl
2 DS RR in the parent zone found



DS with Algorithm 8, KeyTag 60376, DigestType 1 and Digest AxyANyZawsFWeoq2W+qoMHA73Kw=



DS with Algorithm 8, KeyTag 60376, DigestType 2 and Digest MnC7r0m2g+X/DUwAeriaisnQISUt9cpLK2zSHBvZgkM=



1 RRSIG RR to validate DS RR found



RRSIG-Owner science.uva.nl., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 14.06.2021, 10:57:59 +, Signature-Inception: 10.06.2021, 10:09:38 +, KeyTag 13170, Signer-Name: uva.nl



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 13170 used to validate the DS RRSet in the parent zone



3 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 33921, Flags 256



Public Key with Algorithm 8, KeyTag 38223, Flags 256



Public Key with Algorithm 8, KeyTag 60376, Flags 257 (SEP = Secure Entry Point)



2 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner science.uva.nl., Algorithm: 8, 3 Labels, original TTL: 172800 sec, Signature-expiration: 14.06.2021, 01:02:02 +, Signature-Inception: 10.06.2021, 00:20:37 +, KeyTag 38223, Signer-Name: science.uva.nl



RRSIG-Owner science.uva.nl., Algorithm: 8, 3 Labels, original TTL: 172800 sec, Signature-expiration: 14.06.2021, 01:02:02 +, Signature-Inception: 10.06.2021, 00:20:37 +, KeyTag 60376, Signer-Name: science.uva.nl



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 38223 used to validate the DNSKEY RRSet



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 60376 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 60376, DigestType 1 and Digest "AxyANyZawsFWeoq2W+qoMHA73Kw=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 60376, DigestType 2 and Digest "MnC7r0m2g+X/DUwAeriaisnQISUt9cpLK2zSHBvZgkM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: chimay.science.uva.nl
chimay.science.uva.nl
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "3k2rtjkohpp45mtcb87p4449t1ar60ja" between the hashed NSEC3-owner "3k2rtjkohpp45mtcb87p4449t1ar60ja" and the hashed NextOwner "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



0 DNSKEY RR found






RRSIG Type 1 validates the A - Result: 146.50.56.13
Validated: RRSIG-Owner chimay.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 13.06.2021, 18:40:35 +, Signature-Inception: 09.06.2021, 18:18:44 +, KeyTag 38223, Signer-Name: science.uva.nl



CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "3k2rtjkohpp45mtcb87p4449t1ar60ja" equal the hashed NSEC3-owner "3k2rtjkohpp45mtcb87p4449t1ar60ja" and the hashed NextOwner "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NoData-Proof required and found.



TXT-Query sends a valid NSEC3 RR as result with the hashed query name "3k2rtjkohpp45mtcb87p4449t1ar60ja" equal the hashed NSEC3-owner "3k2rtjkohpp45mtcb87p4449t1ar60ja" and the hashed NextOwner "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NoData-Proof required and found.



AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "3k2rtjkohpp45mtcb87p4449t1ar60ja" equal the hashed NSEC3-owner "3k2rtjkohpp45mtcb87p4449t1ar60ja" and the hashed NextOwner "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NoData-Proof required and found.



TLSA-Query (_443._tcp.chimay.science.uva.nl) sends a valid NSEC3 RR as result with the hashed owner name "3k2rtjkohpp45mtcb87p4449t1ar60ja" (unhashed: chimay.science.uva.nl). So that's the Closest Encloser of the query name.
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NXDomain-Proof required and found.



TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "tl6e6e7jp5d5ni8t4pqhq89d7u5ribe5" (unhashed: _tcp.chimay.science.uva.nl) with the owner "tka5qfugohr6rkvpkp2vut7qvkrmm96h" and the NextOwner "tlfshh2uhtnvhon2djora1khhbg1qh91". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: A, RRSIG Validated: RRSIG-Owner tka5qfugohr6rkvpkp2vut7qvkrmm96h.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 17:58:15 +, Signature-Inception: 09.06.2021, 17:34:30 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NXDomain-Proof required and found.



TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "gt4bj4pe82pfpppg3v8a6cmt57e4dq9m" (unhashed: *.chimay.science.uva.nl) with the owner "gs6e4f1uvaevfj1ehak92e6n79g9ep3h" and the NextOwner "gugf4vgmkpkjhb4i3cl1t24rge8mpjcp". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: A, RRSIG Validated: RRSIG-Owner gs6e4f1uvaevfj1ehak92e6n79g9ep3h.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 14:54:01 +, Signature-Inception: 09.06.2021, 14:52:11 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NXDomain-Proof required and found.



CAA-Query sends a valid NSEC3 RR as result with the hashed query name "3k2rtjkohpp45mtcb87p4449t1ar60ja" equal the hashed NSEC3-owner "3k2rtjkohpp45mtcb87p4449t1ar60ja" and the hashed NextOwner "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



Status: Good. NoData-Proof required and found.

Zone: www.chimay.science.uva.nl
www.chimay.science.uva.nl
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "r18mg5qe6earmi5ibthv99cckoci7jqu" between the hashed NSEC3-owner "r12nsak731udtnd41bij9m86tne0of1q" and the hashed NextOwner "r285fkj8tqc80pmjvas99vmro5r3pvj0". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner r12nsak731udtnd41bij9m86tne0of1q.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:35:50 +, Signature-Inception: 09.06.2021, 15:23:02 +, KeyTag 38223, Signer-Name: science.uva.nl



DS-Query in the parent zone sends valid NSEC3 RR with the Hash "3k2rtjkohpp45mtcb87p4449t1ar60ja" as Owner. That's the Hash of "chimay.science.uva.nl" with the NextHashedOwnerName "3k6kp8qdoi0o293gu1to0ilp1avflcgk". So that domain name is the Closest Encloser of "www.chimay.science.uva.nl". Opt-Out: False.
Bitmap: A, RRSIG Validated: RRSIG-Owner 3k2rtjkohpp45mtcb87p4449t1ar60ja.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 15:32:49 +, Signature-Inception: 09.06.2021, 15:24:32 +, KeyTag 38223, Signer-Name: science.uva.nl



The ClosestEncloser says, that "*.chimay.science.uva.nl" with the Hash "gt4bj4pe82pfpppg3v8a6cmt57e4dq9m" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "gs6e4f1uvaevfj1ehak92e6n79g9ep3h" and the Next Owner "gugf4vgmkpkjhb4i3cl1t24rge8mpjcp", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: A, RRSIG Validated: RRSIG-Owner gs6e4f1uvaevfj1ehak92e6n79g9ep3h.science.uva.nl., Algorithm: 8, 4 Labels, original TTL: 900 sec, Signature-expiration: 13.06.2021, 14:54:01 +, Signature-Inception: 09.06.2021, 14:52:11 +, KeyTag 38223, Signer-Name: science.uva.nl


3. Name Servers

DomainNameserverNS-IP
www.chimay.science.uva.nl
  gm.net.uha.nl

chimay.science.uva.nl
T  gm.net.uha.nl
145.18.116.20
Amsterdam/North Holland/Netherlands (NL) - Universiteit van Amsterdam


T 
2001:610:159:3010::20
Amsterdam/North Holland/Netherlands (NL) - SURFnet

science.uva.nl
  gm.net.uha.nl


  ns1.uha.nl / ns1.uha.nl
145.18.128.7
Amsterdam/North Holland/Netherlands (NL) - Universiteit van Amsterdam


 
2001:610:159:3128::7
Amsterdam/North Holland/Netherlands (NL) - SURFnet


  ns2.uha.nl / ns2.uha.nl
145.18.128.8
Amsterdam/North Holland/Netherlands (NL) - Universiteit van Amsterdam


 
2001:610:159:3128::8
Amsterdam/North Holland/Netherlands (NL) - SURFnet

uva.nl
  gm.net.uha.nl


  ns1.uha.nl / ns1.uha.nl
145.18.128.7
Amsterdam/North Holland/Netherlands (NL) - Universiteit van Amsterdam


 
2001:610:159:3128::7
Amsterdam/North Holland/Netherlands (NL) - SURFnet


  ns1.zurich.surf.net
195.176.255.9
Geneva/Switzerland (CH) - SWITCH.102


 
2001:620:0:9::1103
Allenwinden (Baar)/Zug/Switzerland (CH) - SWITCH


  ns2.uha.nl / ns2.uha.nl
145.18.128.8
Amsterdam/North Holland/Netherlands (NL) - Universiteit van Amsterdam


 
2001:610:159:3128::8
Amsterdam/North Holland/Netherlands (NL) - SURFnet


  ns3.surfnet.nl
195.169.124.71
Dalfsen/Overijssel/Netherlands (NL) - SURFnet VI


 
2001:610:0:800c:195:169:124:71
Utrecht/Netherlands (NL) - SURFnet

nl
  ns1.dns.nl / LHR1


  ns2.dns.nl / s2.amx


  ns3.dns.nl / tld-all-ber1


4. SOA-Entries


Domain:nl
Zone-Name:nl
Primary:ns1.dns.nl
Mail:hostmaster.domain-registry.nl
Serial:2021061022
Refresh:3600
Retry:600
Expire:2419200
TTL:600
num Entries:3


Domain:uva.nl
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:uva.nl
Zone-Name:uva.nl
Primary:gm.net.uha.nl
Mail:hostmaster.uva.nl
Serial:2020090704
Refresh:3600
Retry:360
Expire:604800
TTL:900
num Entries:8


Domain:science.uva.nl
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:science.uva.nl
Zone-Name:science.uva.nl
Primary:gm.net.uha.nl
Mail:hostmaster.uva.nl
Serial:2020100652
Refresh:3600
Retry:360
Expire:604800
TTL:900
num Entries:4


Domain:chimay.science.uva.nl
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:2


Domain:www.chimay.science.uva.nl
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


5. Screenshots

No Screenshot listed, because no url-check with https + http status 200-299, 400-599 + not-ACME-check found.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://chimay.science.uva.nl/
146.50.56.13 GZip used - 110 / 130 - 15.38 %
200

Html is minified: 120.37 %
0.033
H
small visible content (num chars: 13)
Hallo wereld!
Date: Thu, 10 Jun 2021 11:33:28 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Thu, 10 Jun 2021 10:31:59 GMT
ETag: "82-5c466e6af8f38-gzip"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 110
Connection: close
Content-Type: text/html

• https://chimay.science.uva.nl/
146.50.56.13
-2

1.043
V
ConnectFailure - Unable to connect to the remote server

• http://chimay.science.uva.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
146.50.56.13
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 100.00 %
0.033
A
Not Found
Visible Content: Not Found The requested URL was not found on this server. Apache/2.4.41 (Ubuntu) Server at chimay.science.uva.nl Port 80
Date: Thu, 10 Jun 2021 11:33:29 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 283
Connection: close
Content-Type: text/html; charset=iso-8859-1

• https://146.50.56.13/
146.50.56.13
-2

1.044
V
ConnectFailure - Unable to connect to the remote server

7. Comments


1. General Results, most used to calculate the result

Aname "chimay.science.uva.nl" is subdomain, public suffix is ".nl", top-level-domain is ".nl", top-level-domain-type is "country-code", Country is Netherlands (the), tld-manager is "SIDN (Stichting Internet Domeinregistratie Nederland)", num .nl-domains preloaded: 3527 (complete: 151507)
Agood: All ip addresses are public addresses
Warning: Only one ip address found: chimay.science.uva.nl has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: chimay.science.uva.nl has no ipv6 address.
Agood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
Agood - only one version with Http-Status 200
AGood: No cookie sent via http.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):1 complete Content-Type - header (2 urls)
http://chimay.science.uva.nl/ 146.50.56.13


Url with incomplete Content-Type - header - missing charset
Hfatal error: No https - result with http-status 200, no encryption
HFatal error: http result with http-status 200, no encryption. Add a redirect http ⇒ https, so every connection is secure. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop.
Vhttps://chimay.science.uva.nl/ 146.50.56.13
-2

connect failure - perhaps firewall
Vhttps://146.50.56.13/ 146.50.56.13
-2

connect failure - perhaps firewall
XFatal error: Nameserver doesn't support TCP connection: gm.net.uha.nl / 145.18.116.20: Timeout
XFatal error: Nameserver doesn't support TCP connection: gm.net.uha.nl / 2001:610:159:3010::20: Timeout
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain chimay.science.uva.nl, 1 ip addresses.

2. DNS- and NameServer - Checks

AInfo:: 2 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 2 Name Servers.
AInfo:: 2 Queries complete, 2 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.ns1.uha.nl (145.18.128.7, 2001:610:159:3128::7), ns2.uha.nl (145.18.128.8, 2001:610:159:3128::8)
AGood (1 - 3.0):: An average of 1.0 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 3 different Name Servers found: gm.net.uha.nl, ns1.uha.nl, ns2.uha.nl, 2 Name Servers included in Delegation: ns1.uha.nl, ns2.uha.nl, 2 Name Servers included in 2 Zone definitions: ns1.uha.nl, ns2.uha.nl, 1 Name Servers listed in SOA.Primary: gm.net.uha.nl.
AGood: Only one SOA.Primary Name Server found.: gm.net.uha.nl.
Error: SOA.Primary Name Server not included in the delegation set.: gm.net.uha.nl.
AGood: All Name Server Domain Names have a Public Suffix.
Error: Name Server Domain Names with Public Suffix and without ip address found.: 1 Name Servers without ipv4 and ipv6: 1

AInfo: Ipv4-Subnet-list: 2 Name Servers, 1 different subnets (first Byte): 145., 1 different subnets (first two Bytes): 145.18., 1 different subnets (first three Bytes): 145.18.128.
XFatal: All Name Server IPv4 addresses from the same subnet. Check https://www.iana.org/help/nameserver-requirements to learn some basics about name server configurations. If you manage these name servers, fix it. If it's your provider, change your provider.:
AInfo: IPv6-Subnet-list: 2 Name Servers with IPv6, 1 different subnets (first block): 2001:, 1 different subnets (first two blocks): 2001:0610:, 1 different subnets (first three blocks): 2001:0610:0159:, 1 different subnets (first four blocks): 2001:0610:0159:3128:
Fatal: All Name Server IPv6 addresses from the same subnet.
XNameserver Timeout checking Echo Capitalization: gm.net.uha.nl / 145.18.116.20
XNameserver Timeout checking Echo Capitalization: gm.net.uha.nl / 2001:610:159:3010::20
XNameserver Timeout checking EDNS512: gm.net.uha.nl / 145.18.116.20
XNameserver Timeout checking EDNS512: gm.net.uha.nl / 2001:610:159:3010::20
Nameserver doesn't pass all EDNS-Checks: gm.net.uha.nl: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: gm.net.uha.nl: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: gm.net.uha.nl: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: gm.net.uha.nl / 145.18.116.20: OP100: fatal timeout. FLAGS: fatal timeout. V1: fatal timeout. V1OP100: fatal timeout. V1FLAGS: fatal timeout. DNSSEC: fatal timeout. V1DNSSEC: fatal timeout. NSID: fatal timeout. COOKIE: fatal timeout. CLIENTSUBNET: fatal timeout.
Nameserver doesn't pass all EDNS-Checks: gm.net.uha.nl / 2001:610:159:3010::20: OP100: fatal timeout. FLAGS: fatal timeout. V1: fatal timeout. V1OP100: fatal timeout. V1FLAGS: fatal timeout. DNSSEC: fatal timeout. V1DNSSEC: fatal timeout. NSID: fatal timeout. COOKIE: fatal timeout. CLIENTSUBNET: fatal timeout.
AGood: All SOA have the same Serial Number
Agood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create certificates
Agood: CAA entries found, creating certificate is limited: ssl.com is allowed to create certificates
Agood: CAA entries found, creating certificate is limited: www.pkioverheid.nl is allowed to create certificates
Agood: CAA entries found, creating certificate is limited: no CAA is allowed to create wildcard certificates
Warning: Unknown CAA found: www.pkioverheid.nl isn't defined. Value is wrong, but "www.digicert.com" is valid. Wrong Top level domain?

3. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 155730 milliseconds, 155.730 seconds


8. Connections

No connection informations found. Perhaps only http - connections.


9. Certificates

No certificate informations found. Perhaps only http - connections.


10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

No CertSpotter - CT-Log entries found


2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > 2019 are listed

No CRT - CT-Log entries found


11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404


12. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.uha.nl, ns2.uha.nl

QNr.DomainTypeNS used
1
nl
NS
f.root-servers.net (2001:500:2f::f)

Answer: ns1.dns.nl, ns2.dns.nl, ns3.dns.nl
2
ns1.uha.nl: 145.18.128.7, 2001:610:159:3128::7
NS
ns1.dns.nl (2001:678:2c:0:194:0:28:53)

Answer: ns2.uha.nl
145.18.128.8, 2001:610:159:3128::8


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
chimay.science.uva.nl
0

no CAA entry found
1
0
science.uva.nl
0

no CAA entry found
1
0
uva.nl
9
issuewild
;
1
0

5
iodef
mailto:scs-ra@uva.nl
1
0

5
issue
sectigo.com
1
0

5
issue
ssl.com
1
0

5
issue
www.pkioverheid.nl
1
0
nl
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
science.uva.nl
GzJWRq95dBM8gmzYVs7KfAY6B/JEUm0rW/8FrAqdbI03u4cBuVHcI1Ms3Smy1+sf3OAAQ3DE82tHc2FcTXZ3mg==
ok
1
0
science.uva.nl
have-i-been-pwned-verification=de81beb8a30653dba5a69f69dadc4fb1
ok
1
0
science.uva.nl
MS=174A3DC6053DDF5B74D91B76C09C395CDAB1EEDD
ok
1
0
science.uva.nl
MS=70AE1029C67F7FF07907B6359B40AE613103AE4D
ok
1
0
science.uva.nl
v=spf1 ip4:146.50.108.128/27 ip4:145.18.227.128/27 ip4:145.18.227.160/28 include:_spf.surfmailfilter.nl include:spf.protection.outlook.com -all
ok
1
0
chimay.science.uva.nl

ok
1
0
_acme-challenge.chimay.science.uva.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.chimay.science.uva.nl.science.uva.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.chimay.science.uva.nl.chimay.science.uva.nl

Name Error - The domain name does not exist
1
0


15. Portchecks

Domain or IPPortDescriptionResultAnswer
chimay.science.uva.nl
21
FTP



chimay.science.uva.nl
21
FTP



chimay.science.uva.nl
22
SSH



chimay.science.uva.nl
22
SSH



chimay.science.uva.nl
25
SMTP



chimay.science.uva.nl
25
SMTP



chimay.science.uva.nl
53
DNS



chimay.science.uva.nl
53
DNS



chimay.science.uva.nl
110
POP3



chimay.science.uva.nl
110
POP3



chimay.science.uva.nl
143
IMAP



chimay.science.uva.nl
143
IMAP



chimay.science.uva.nl
465
SMTP (encrypted)



chimay.science.uva.nl
465
SMTP (encrypted)



chimay.science.uva.nl
587
SMTP (encrypted, submission)



chimay.science.uva.nl
587
SMTP (encrypted, submission)



chimay.science.uva.nl
993
IMAP (encrypted)



chimay.science.uva.nl
993
IMAP (encrypted)



chimay.science.uva.nl
995
POP3 (encrypted)



chimay.science.uva.nl
995
POP3 (encrypted)



chimay.science.uva.nl
1433
MS SQL



chimay.science.uva.nl
1433
MS SQL



chimay.science.uva.nl
2082
cPanel (http)



chimay.science.uva.nl
2082
cPanel (http)



chimay.science.uva.nl
2083
cPanel (https)



chimay.science.uva.nl
2083
cPanel (https)



chimay.science.uva.nl
2086
WHM (http)



chimay.science.uva.nl
2086
WHM (http)



chimay.science.uva.nl
2087
WHM (https)



chimay.science.uva.nl
2087
WHM (https)



chimay.science.uva.nl
2089
cPanel Licensing



chimay.science.uva.nl
2089
cPanel Licensing



chimay.science.uva.nl
2095
cPanel Webmail (http)



chimay.science.uva.nl
2095
cPanel Webmail (http)



chimay.science.uva.nl
2096
cPanel Webmail (https)



chimay.science.uva.nl
2096
cPanel Webmail (https)



chimay.science.uva.nl
2222
DirectAdmin (http)



chimay.science.uva.nl
2222
DirectAdmin (http)



chimay.science.uva.nl
2222
DirectAdmin (https)



chimay.science.uva.nl
2222
DirectAdmin (https)



chimay.science.uva.nl
3306
mySql



chimay.science.uva.nl
3306
mySql



chimay.science.uva.nl
5224
Plesk Licensing



chimay.science.uva.nl
5224
Plesk Licensing



chimay.science.uva.nl
5432
PostgreSQL



chimay.science.uva.nl
5432
PostgreSQL



chimay.science.uva.nl
8080
Ookla Speedtest (http)
open
http://chimay.science.uva.nl:8080/
Http-Status: 200

chimay.science.uva.nl
8080
Ookla Speedtest (http)
open
http://chimay.science.uva.nl:8080/
Http-Status: 200

chimay.science.uva.nl
8080
Ookla Speedtest (https)
open
https://chimay.science.uva.nl:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

chimay.science.uva.nl
8080
Ookla Speedtest (https)
open
https://chimay.science.uva.nl:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

chimay.science.uva.nl
8083
VestaCP http



chimay.science.uva.nl
8083
VestaCP http



chimay.science.uva.nl
8083
VestaCP https



chimay.science.uva.nl
8083
VestaCP https



chimay.science.uva.nl
8443
Plesk Administration (https)



chimay.science.uva.nl
8443
Plesk Administration (https)



chimay.science.uva.nl
8447
Plesk Installer + Updates



chimay.science.uva.nl
8447
Plesk Installer + Updates



chimay.science.uva.nl
8880
Plesk Administration (http)



chimay.science.uva.nl
8880
Plesk Administration (http)



chimay.science.uva.nl
10000
Webmin (http)



chimay.science.uva.nl
10000
Webmin (http)



chimay.science.uva.nl
10000
Webmin (https)



chimay.science.uva.nl
10000
Webmin (https)



146.50.56.13
21
FTP



146.50.56.13
21
FTP



146.50.56.13
22
SSH



146.50.56.13
22
SSH



146.50.56.13
25
SMTP



146.50.56.13
25
SMTP



146.50.56.13
53
DNS



146.50.56.13
53
DNS



146.50.56.13
110
POP3



146.50.56.13
110
POP3



146.50.56.13
143
IMAP



146.50.56.13
143
IMAP



146.50.56.13
465
SMTP (encrypted)



146.50.56.13
465
SMTP (encrypted)



146.50.56.13
587
SMTP (encrypted, submission)



146.50.56.13
587
SMTP (encrypted, submission)



146.50.56.13
993
IMAP (encrypted)



146.50.56.13
993
IMAP (encrypted)



146.50.56.13
995
POP3 (encrypted)



146.50.56.13
995
POP3 (encrypted)



146.50.56.13
1433
MS SQL



146.50.56.13
1433
MS SQL



146.50.56.13
2082
cPanel (http)



146.50.56.13
2082
cPanel (http)



146.50.56.13
2083
cPanel (https)



146.50.56.13
2083
cPanel (https)



146.50.56.13
2086
WHM (http)



146.50.56.13
2086
WHM (http)



146.50.56.13
2087
WHM (https)



146.50.56.13
2087
WHM (https)



146.50.56.13
2089
cPanel Licensing



146.50.56.13
2089
cPanel Licensing



146.50.56.13
2095
cPanel Webmail (http)



146.50.56.13
2095
cPanel Webmail (http)



146.50.56.13
2096
cPanel Webmail (https)



146.50.56.13
2096
cPanel Webmail (https)



146.50.56.13
2222
DirectAdmin (http)



146.50.56.13
2222
DirectAdmin (http)



146.50.56.13
2222
DirectAdmin (https)



146.50.56.13
2222
DirectAdmin (https)



146.50.56.13
3306
mySql



146.50.56.13
3306
mySql



146.50.56.13
5224
Plesk Licensing



146.50.56.13
5224
Plesk Licensing



146.50.56.13
5432
PostgreSQL



146.50.56.13
5432
PostgreSQL



146.50.56.13
8080
Ookla Speedtest (http)
open
http://146.50.56.13:8080/
Http-Status: 200

146.50.56.13
8080
Ookla Speedtest (http)
open
http://146.50.56.13:8080/
Http-Status: 200

146.50.56.13
8080
Ookla Speedtest (https)
open
https://146.50.56.13:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

146.50.56.13
8080
Ookla Speedtest (https)
open
https://146.50.56.13:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

146.50.56.13
8083
VestaCP http



146.50.56.13
8083
VestaCP http



146.50.56.13
8083
VestaCP https



146.50.56.13
8083
VestaCP https



146.50.56.13
8443
Plesk Administration (https)



146.50.56.13
8443
Plesk Administration (https)



146.50.56.13
8447
Plesk Installer + Updates



146.50.56.13
8447
Plesk Installer + Updates



146.50.56.13
8880
Plesk Administration (http)



146.50.56.13
8880
Plesk Administration (http)



146.50.56.13
10000
Webmin (http)



146.50.56.13
10000
Webmin (http)



146.50.56.13
10000
Webmin (https)



146.50.56.13
10000
Webmin (https)





Permalink: https://check-your-website.server-daten.de/?i=5ccfacaf-6e19-4cc3-9439-21caa92e60c9


Last Result: https://check-your-website.server-daten.de/?q=chimay.science.uva.nl - 2021-06-10 13:31:13


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=chimay.science.uva.nl" target="_blank">Check this Site: chimay.science.uva.nl</a>