Check DNS, Urls + Redirects, Certificates and Content of your Website




O

old / weak connection

Checked:
02.06.2020 01:15:47


Older results

No older results found


1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
dipgg.desktopimaging.co.nz
A
203.97.68.250
Auckland/New Zealand (NZ) - VODAFONE
No Hostname found
yes
1
0

AAAA

yes


www.dipgg.desktopimaging.co.nz

Name Error
yes
1
0
*.desktopimaging.co.nz
A
203.167.239.22
yes



AAAA

yes



CNAME

yes


*.dipgg.desktopimaging.co.nz
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 48903, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 21.06.2020, 00:00:00 +, Signature-Inception: 31.05.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: nz
nz
8 DS RR in the parent zone found



1 RRSIG RR to validate DS RR found



RRSIG-Owner nz., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 14.06.2020, 17:00:00 +, Signature-Inception: 01.06.2020, 16:00:00 +, KeyTag 48903, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 48903 used to validate the DS RRSet in the parent zone



5 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 1324, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 12981, Flags 256



Public Key with Algorithm 8, KeyTag 25234, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 49425, Flags 256



Public Key with Algorithm 8, KeyTag 51655, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner nz., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 08.06.2020, 14:34:13 +, Signature-Inception: 27.05.2020, 11:41:28 +, KeyTag 25234, Signer-Name: nz



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 25234 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 25234, DigestType 1 and Digest "zVbwosNyTiG960xn7Eog9vjpRVk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 25234, DigestType 2 and Digest "dNAyFKQ4FCikIb/aGkXxqRuTJdmTgWSFSlXnmmZfyDM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: co.nz
co.nz
4 DS RR in the parent zone found



1 RRSIG RR to validate DS RR found



RRSIG-Owner co.nz., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 10.06.2020, 19:53:06 +, Signature-Inception: 27.05.2020, 02:26:28 +, KeyTag 12981, Signer-Name: nz



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 12981 used to validate the DS RRSet in the parent zone



5 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 14701, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 17230, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 21366, Flags 256



Public Key with Algorithm 8, KeyTag 36070, Flags 256



Public Key with Algorithm 8, KeyTag 51069, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner co.nz., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 11.06.2020, 04:12:43 +, Signature-Inception: 27.05.2020, 11:41:32 +, KeyTag 14701, Signer-Name: co.nz



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14701 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 14701, DigestType 1 and Digest "pq8gOO8ZVySZp0oRB+boWTMFEzo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 14701, DigestType 2 and Digest "NuZl3K163QfyN0xcq3kj4Rs7zjPvNnCPeCjm7eP2geA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: desktopimaging.co.nz
desktopimaging.co.nz
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "ta2a0jfrlmp7ufdi2led3qdfn05hh0vn" between the hashed NSEC3-owner "ta01o854pvpfcn767cqbqh1nv31u3ggu" and the hashed NextOwner "ta3dfp00m4d8futm28dg1biooj86v939". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner ta01o854pvpfcn767cqbqh1nv31u3ggu.co.nz., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 07.06.2020, 08:52:06 +, Signature-Inception: 29.05.2020, 11:56:30 +, KeyTag 21366, Signer-Name: co.nz



0 DNSKEY RR found




Zone: dipgg.desktopimaging.co.nz
dipgg.desktopimaging.co.nz
0 DS RR in the parent zone found



0 DNSKEY RR found




Zone: www.dipgg.desktopimaging.co.nz
www.dipgg.desktopimaging.co.nz
0 DS RR in the parent zone found


3. Name Servers

DomainNameserverNS-IP
www.dipgg.desktopimaging.co.nz
  ns1.openhost.co.nz

dipgg.desktopimaging.co.nz
  ns1.openhost.co.nz
112.109.83.11
Auckland/New Zealand (NZ) - Umbrellar Limited

desktopimaging.co.nz
  ns1.openhost.co.nz
112.109.83.11
Auckland/New Zealand (NZ) - Umbrellar Limited


  ns2.openhost.co.nz
52.187.240.75
Sydney/New South Wales/Australia (AU) - Microsoft Corporation


  ns3.openhost.co.nz
103.253.194.23
Auckland/New Zealand (NZ) - Umbrellar Limited

co.nz
  loopback.dns.net.nz


  ns1.dns.net.nz / ns1
202.46.190.130
Auckland/New Zealand (NZ) - InternetNZ


 
2001:dce:2000:2::130
Wellington/New Zealand (NZ) - InternetNZ


  ns2.dns.net.nz / ns2a
202.46.187.130
Wellington/New Zealand (NZ) - InternetNZ


 
2001:dce:7000:2::130
Wellington/New Zealand (NZ) - InternetNZ


  ns3.dns.net.nz / ns3a
202.46.188.130
Wellington/New Zealand (NZ) - InternetNZ


 
2001:dce:d453::53
Wellington/New Zealand (NZ) - InternetNZ


  ns4.dns.net.nz / ns4b
202.46.189.130
Wellington/New Zealand (NZ) - InternetNZ


 
2001:dce:d454::53
Wellington/New Zealand (NZ) - InternetNZ


  ns5.dns.net.nz / LHR2
185.159.197.130
Stockholm/Stockholm County/Sweden (SE) - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enreg


 
2620:10a:80aa::130
Montreal/Quebec/Canada (CA) - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enreg


  ns6.dns.net.nz / STO2
185.159.198.130
Chicago/Illinois/United States (US) - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enreg


 
2620:10a:80ab::130
Ottawa/Ontario/Canada (CA) - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enreg


  ns7.dns.net.nz / s2.amx
194.146.106.54
Norrtaelje/Stockholm County/Sweden (SE) - NETNOD Internet Exchange i Sverige AB


 
2001:67c:1010:13::53
Zurich/Switzerland (CH) - NETNOD Internet Exchange i Sverige AB

nz
  loopback.dns.net.nz


  ns1.dns.net.nz / ns1


  ns2.dns.net.nz / ns2a


  ns3.dns.net.nz / ns3a


  ns4.dns.net.nz / ns4b


  ns5.dns.net.nz / LHR2


  ns6.dns.net.nz / STO2


  ns7.dns.net.nz / s2.amx


4. SOA-Entries


Domain:nz
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:nz
Zone-Name:nz
Primary:loopback.dns.net.nz
Mail:soa.nzrs.net.nz
Serial:2020060244
Refresh:900
Retry:300
Expire:604800
TTL:3600
num Entries:7


Domain:co.nz
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:co.nz
Zone-Name:co.nz
Primary:loopback.dns.net.nz
Mail:soa.nzrs.net.nz
Serial:2020060244
Refresh:900
Retry:300
Expire:604800
TTL:3600
num Entries:11


Domain:co.nz
Zone-Name:co.nz
Primary:loopback.dns.net.nz
Mail:soa.nzrs.net.nz
Serial:2020060245
Refresh:900
Retry:300
Expire:604800
TTL:3600
num Entries:3


Domain:desktopimaging.co.nz
Zone-Name:desktopimaging.co.nz
Primary:ns1.openhost.co.nz
Mail:soa.nameserver.net.nz
Serial:766621
Refresh:7200
Retry:3600
Expire:604800
TTL:300
num Entries:3


Domain:dipgg.desktopimaging.co.nz
Zone-Name:desktopimaging.co.nz
Primary:ns1.openhost.co.nz
Mail:soa.nameserver.net.nz
Serial:766621
Refresh:7200
Retry:3600
Expire:604800
TTL:300
num Entries:1


Domain:www.dipgg.desktopimaging.co.nz
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


5. Screenshots

Startaddress: https://dipgg.desktopimaging.co.nz, address used: https://dipgg.desktopimaging.co.nz/, Screenshot created 2020-06-02 01:19:49 +00:0

Mobil (412px x 732px)

599 milliseconds

Screenshot mobile - https://dipgg.desktopimaging.co.nz/
Mobil + Landscape (732px x 412px)

1221 milliseconds

Screenshot mobile landscape - https://dipgg.desktopimaging.co.nz/
Screen (1280px x 1680px)

1725 milliseconds

Screenshot Desktop - https://dipgg.desktopimaging.co.nz/

Mobile- and other Chrome-Checks

widthheight
visual Viewport412716
content Size418716

Fatal: Horizontal scrollbar detected. Content-size width is greater then visual Viewport width.

Chrome-Connection: info. obsolete connection settings. The connection to this site is encrypted and authenticated using TLS 1.0, RSA, and 3DES_EDE_CBC with HMAC-SHA1.

Chrome-Resources : secure. all served securely. All resources on this page are served securely.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://dipgg.desktopimaging.co.nz/
203.97.68.250
403

Html is minified: 119.48 %
0.656
M
Forbidden ( The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. )
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 2024

• https://dipgg.desktopimaging.co.nz/
203.97.68.250
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/111
403

Html is minified: 119.48 %
6.613
I
Forbidden ( The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. )
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 2024

• http://dipgg.desktopimaging.co.nz/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
203.97.68.250
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/111
403

Html is minified: 119.48 %
0.666
M
Forbidden ( The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. )
Visible Content: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> The page cannot be displayed The page cannot be displayed Explanation: There is a problem with the page you are trying to reach and it cannot be displayed. Try the following: Refresh page: Search for the page again by clicking the Refresh button. The timeout may have occurred due to Internet congestion. Check spelling: Check that you typed the Web page address correctly. The address may have been mistyped. Access from a link: If there is a link to the page you are looking for, try accessing the page from that link. Technical Information (for support personnel) Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202)
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 2024

• https://203.97.68.250/
203.97.68.250
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/111
403

Html is minified: 119.48 %
6.590
N
Forbidden ( The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. )
Certificate error: RemoteCertificateNameMismatch
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 2024

7. Comments


1. General Results, most used to calculate the result

Aname "dipgg.desktopimaging.co.nz" is subdomain, public suffix is "co.nz", top-level-domain-type is "country-code", Country is New Zealand, tld-manager is "InternetNZ"
Agood: All ip addresses are public addresses
Warning: Only one ip address found: dipgg.desktopimaging.co.nz has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: dipgg.desktopimaging.co.nz has no ipv6 address.
Agood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):0 complete Content-Type - header (4 urls)
http://dipgg.desktopimaging.co.nz/ 203.97.68.250


Url with incomplete Content-Type - header - missing charset
https://dipgg.desktopimaging.co.nz/ 203.97.68.250


Url with incomplete Content-Type - header - missing charset
http://dipgg.desktopimaging.co.nz/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 203.97.68.250


Url with incomplete Content-Type - header - missing charset
https://203.97.68.250/ 203.97.68.250


Url with incomplete Content-Type - header - missing charset
CError - no version with Http-Status 200
Hfatal error: No https - result with http-status 200, no encryption
Mhttp://dipgg.desktopimaging.co.nz/ 203.97.68.250
403

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://dipgg.desktopimaging.co.nz/ 203.97.68.250
403

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://203.97.68.250/ 203.97.68.250
403

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://203.97.68.250/ 203.97.68.250
403

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
OOld connection: Tls.1.0 is deprecated, Tls.1.2 should be supported
OOld connection: RSA Key Exchange is unsecure. Use Diffie-Hellman or Elliptic Curve Diffi-Hellmann Key Exchange to support Forward Secrecy
OOld connection: Non-Aes Cipher Suites are deprecated. Switch to AES Cipher-Suites
OOld connection: SHA1 as Hash Algorithm is deprecated. Switch to SHA256 or SHA384. If your certificate has SHA256, first check your domain via ssllabs.com and update weak Cipher Suites. Forward Secrecy support is required. The part "Cipher Suites" should have a preference. First Cipher Suite with SHA instead of SHA256 or higher - that's the problem, change that. If that doesn't help, check if there is an old Firewall / router or something else, that supports only SHA1. Update that component.
OOld connection: CBC Cipher suites are deprecated. A GCM Cipher suite is required. See the Chrome-Check-Result:: obsolete connection settings. The connection to this site is encrypted and authenticated using TLS 1.0, RSA, and 3DES_EDE_CBC with HMAC-SHA1.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain dipgg.desktopimaging.co.nz, 1 ip addresses, 1 different http results.

2. DNS- and NameServer - Checks

AInfo:: 11 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 3 Name Servers.
AInfo:: 11 Queries complete, 5 with IPv6, 6 with IPv4.
Warning: Only some DNS Queries done via ipv6. IPv6 is the future, so the name servers of your name servers should have ipv6 addresses.
Ok (4 - 8):: An average of 3.7 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 3 different Name Servers found: ns1.openhost.co.nz, ns2.openhost.co.nz, ns3.openhost.co.nz, 3 Name Servers included in Delegation: ns1.openhost.co.nz, ns2.openhost.co.nz, ns3.openhost.co.nz, 3 Name Servers included in 1 Zone definitions: ns1.openhost.co.nz, ns2.openhost.co.nz, ns3.openhost.co.nz, 1 Name Servers listed in SOA.Primary: ns1.openhost.co.nz.
AGood: Only one SOA.Primary Name Server found.: ns1.openhost.co.nz.
AGood: SOA.Primary Name Server included in the delegation set.: ns1.openhost.co.nz.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns1.openhost.co.nz, ns2.openhost.co.nz, ns3.openhost.co.nz
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 3 different Name Servers found
Warning: No Name Server IPv6 address found. IPv6 is the future, so your name servers should be visible via IPv6.: 3 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 3 Name Servers, 1 Top Level Domain: co.nz
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: openhost.co.nz
AGood: Name servers with different Country locations found: 3 Name Servers, 2 Countries: AU, NZ
AInfo: Ipv4-Subnet-list: 3 Name Servers, 3 different subnets (first Byte): 103., 112., 52., 3 different subnets (first two Bytes): 103.253., 112.109., 52.187., 3 different subnets (first three Bytes): 103.253.194., 112.109.83., 52.187.240.
AExcellent: Every Name Server IPv4-address starts with an unique Byte.
AGood: Nameserver supports TCP connections: 1 good Nameserver
AGood: Nameserver supports Echo Capitalization: 1 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 1 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 1 good Nameserver
Nameserver doesn't pass all EDNS-Checks: loopback.dns.net.nz: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: loopback.dns.net.nz: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: ns1.openhost.co.nz: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: ns7.dns.net.nz: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: ok (s2.amx). COOKIE: ok. CLIENTSUBNET: ok.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

3. Content- and Performance-critical Checks

http://dipgg.desktopimaging.co.nz/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 203.97.68.250
403

Fatal: Check of /.well-known/acme-challenge/random-filename has a http status 401 / 403 Not Allowed / Forbidden. A http status 404 - Not Found - is expected. Creating a Letsencrypt certificate via http-01 challenge may not work. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
IWrong: Attribute values found, not enclosed in quotation marks (" or ').: 9 Html-Elements with attributes and missing enclosed quotation marks found. 12 wrong attributes.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 243747 milliseconds, 243.747 seconds


8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
dipgg.desktopimaging.co.nz
203.97.68.250
443
ok
Tls
RsaKeyX
2048
TripleDes
168
Sha1
error checking OCSP stapling
weak
dipgg.desktopimaging.co.nz
203.97.68.250
443
ok
Tls

RsaKeyX
2048
TripleDes
168
Sha1
error checking OCSP stapling
weak
no http/2 via ALPN 
No SNI required - domain included in main certificate
no Tls.1.2
no Tls.1.1
Tls.1.0
no http/2 via ALPN
No SNI required - domain included in main certificate
no Tls.1.2
no Tls.1.1
Tls.1.0


203.97.68.250
203.97.68.250
443
name does not match
Tls
RsaKeyX
2048
TripleDes
168
Sha1
error checking OCSP stapling
weak

203.97.68.250
203.97.68.250
443
name does not match
Tls

RsaKeyX
2048
TripleDes
168
Sha1
error checking OCSP stapling
weak
no http/2 via ALPN 
Cert sent without SNI
no Tls.1.2
no Tls.1.1
Tls.1.0
no http/2 via ALPN
Cert sent without SNI
no Tls.1.2
no Tls.1.1
Tls.1.0


9. Certificates

1.
1.
CN=*.desktopimaging.co.nz, OU=PositiveSSL Wildcard, OU=Domain Control Validated
31.05.2018
02.09.2020
expires in 54 days
*.desktopimaging.co.nz, desktopimaging.co.nz - 2 entries
1.
1.
CN=*.desktopimaging.co.nz, OU=PositiveSSL Wildcard, OU=Domain Control Validated
31.05.2018

02.09.2020
expires in 54 days
*.desktopimaging.co.nz, desktopimaging.co.nz - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:72A3529B8494BD5A5E1542D94E0014A2
Thumbprint:F19865F57BFA945090E78EBBA5DFC3983F1C37A8
SHA256 / Certificate:tZHkr7BM/fwAKKBwm14bGStCO5euDRo9rRAF72m2tH0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):897caf765df94f792a34f0a41299b2826580e282b627a802411bb2747192b227
SHA256 hex / Subject Public Key Information (SPKI):4923450fdf902e1fa5a997df8da15cb583089c5cac4549ee1db1a37cf378da9c
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.comodoca.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)


2.
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
12.02.2014
12.02.2029
expires in 3139 days


2.
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
12.02.2014

12.02.2029
expires in 3139 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:2B2E6EEAD975366C148A6EDBA37C8C07
Thumbprint:339CDD57CFD5B141169B615FF31428782D1DA639
SHA256 / Certificate:AqtX5OZ6DLSN0v80gw6KxA9EdvsIymvj9c2Eb2RoQPA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):9253b6de74f67a11435c27f1dde1d30d1112333ddab23d66b8efb86887638ae6
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.comodoca.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)


3.
CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
19.01.2010
19.01.2038
expires in 6402 days


3.
CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
19.01.2010

19.01.2038
expires in 6402 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:4CAAF9CADB636FE01FF74ED85B03869D
Thumbprint:AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4
SHA256 / Certificate:UvDhxOWOxikpG2AxfwdGcbhdfqgNWwcnNGNTSzK0AjQ=
SHA256 hex / Cert (DANE * 0 1):52f0e1c4e58ec629291b60317f074671b85d7ea80d5b07273463534b32b40234
SHA256 hex / PublicKey (DANE * 1 1):82b5f84daf47a59c7ab521e4982aefa40a53406a3aec26039efa6b2e0e7244c1
SHA256 hex / Subject Public Key Information (SPKI):f6761914d3b7f6abaa7dc85adc13aa19dd5f6a6707ebb7120029fe01e967b668
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:



10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

No CertSpotter - CT-Log entries found


2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > 2019 are listed

Issuerlast 7 daysactivenum Certs
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, C=GB, ST=Greater Manchester
0
2
2

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
496790867
leaf cert
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, C=GB, ST=Greater Manchester
2018-05-30 22:00:00
2020-09-01 21:59:59
*.desktopimaging.co.nz, desktopimaging.co.nz
2 entries


492428486
leaf cert
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, C=GB, ST=Greater Manchester
2018-05-28 22:00:00
2020-08-30 21:59:59
*.desktopimaging.co.nz, desktopimaging.co.nz
2 entries



11. Html-Content - Entries

Summary

Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://dipgg.desktopimaging.co.nz/
203.97.68.250
meta (4)
other
3

0


0
0
0

http://dipgg.desktopimaging.co.nz/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
203.97.68.250
meta (4)
other
3

0


0
0
0

https://203.97.68.250/
203.97.68.250
meta (4)
other
3

0


0
0
0

Details

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://dipgg.desktopimaging.co.nz/
203.97.68.250
meta (1)
Content-Type
text-html; charset=UTF-8


1
ok








meta (1)
GENERATOR
MSHTML 5.50.4522.1800


1
ok








meta (2)
ROBOTS
NOINDEX


1
ok







http://dipgg.desktopimaging.co.nz/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
203.97.68.250
meta (1)
Content-Type
text-html; charset=UTF-8


1
ok








meta (1)
GENERATOR
MSHTML 5.50.4522.1800


1
ok








meta (2)
ROBOTS
NOINDEX


1
ok







https://203.97.68.250/
203.97.68.250
meta (1)
Content-Type
text-html; charset=UTF-8


1
ok








meta (1)
GENERATOR
MSHTML 5.50.4522.1800


1
ok








meta (2)
ROBOTS
NOINDEX


1
ok








12. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.openhost.co.nz, ns2.openhost.co.nz, ns3.openhost.co.nz

QNr.DomainTypeNS used
1
nz
NS
k.root-servers.net (2001:7fd::1)

Answer: ns1.dns.net.nz, ns2.dns.net.nz, ns3.dns.net.nz, ns4.dns.net.nz, ns5.dns.net.nz, ns6.dns.net.nz, ns7.dns.net.nz
2
ns1.openhost.co.nz
NS
ns1.dns.net.nz (2001:dce:2000:2::130)

Answer: ns1.platform.net.nz, ns2.platform.net.nz, ns3.platform.net.nz
3
ns2.openhost.co.nz
NS
ns1.dns.net.nz (2001:dce:2000:2::130)

Answer: ns1.platform.net.nz, ns2.platform.net.nz, ns3.platform.net.nz
4
ns3.openhost.co.nz
NS
ns1.dns.net.nz (2001:dce:2000:2::130)

Answer: ns1.platform.net.nz, ns2.platform.net.nz, ns3.platform.net.nz
5
ns1.platform.net.nz: 112.109.83.11
NS
ns1.dns.net.nz (2001:dce:2000:2::130)

Answer: ns2.platform.net.nz
52.187.240.75

Answer: ns3.platform.net.nz
103.253.194.23
6
ns1.openhost.co.nz: 112.109.83.11
A
ns1.platform.net.nz (112.109.83.11)
7
ns1.openhost.co.nz: No AAAA record found
AAAA
ns1.platform.net.nz (112.109.83.11)
8
ns2.openhost.co.nz: 52.187.240.75
A
ns1.platform.net.nz (112.109.83.11)
9
ns2.openhost.co.nz: No AAAA record found
AAAA
ns1.platform.net.nz (112.109.83.11)
10
ns3.openhost.co.nz: 103.253.194.23
A
ns1.platform.net.nz (112.109.83.11)
11
ns3.openhost.co.nz: No AAAA record found
AAAA
ns1.platform.net.nz (112.109.83.11)


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
dipgg.desktopimaging.co.nz
0

no CAA entry found
1
0
desktopimaging.co.nz
0

no CAA entry found
1
0
co.nz
0

no CAA entry found
1
0
nz
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
desktopimaging.co.nz
v=spf1 include:spf.protection.outlook.com include:spf.exclaimer.net include:spf.messagelabs.com ip4:203.167.239.22 ip4:203.84.134.33 ip4:122.56.8.51 -all
ok
1
0
dipgg.desktopimaging.co.nz

ok
1
0
_acme-challenge.dipgg.desktopimaging.co.nz

Name Error - The domain name does not exist
1
0
_acme-challenge.dipgg.desktopimaging.co.nz.desktopimaging.co.nz

perhaps wrong
1
0
_acme-challenge.dipgg.desktopimaging.co.nz.dipgg.desktopimaging.co.nz

Name Error - The domain name does not exist
1
0


15. Portchecks

Domain or IPPortDescriptionResultAnswer
dipgg.desktopimaging.co.nz
21
FTP



dipgg.desktopimaging.co.nz
21
FTP



dipgg.desktopimaging.co.nz
22
SSH



dipgg.desktopimaging.co.nz
22
SSH



dipgg.desktopimaging.co.nz
25
SMTP



dipgg.desktopimaging.co.nz
25
SMTP



dipgg.desktopimaging.co.nz
53
DNS



dipgg.desktopimaging.co.nz
53
DNS



dipgg.desktopimaging.co.nz
110
POP3



dipgg.desktopimaging.co.nz
110
POP3



dipgg.desktopimaging.co.nz
143
IMAP



dipgg.desktopimaging.co.nz
143
IMAP



dipgg.desktopimaging.co.nz
465
SMTP (encrypted)



dipgg.desktopimaging.co.nz
465
SMTP (encrypted)



dipgg.desktopimaging.co.nz
587
SMTP (encrypted, submission)



dipgg.desktopimaging.co.nz
587
SMTP (encrypted, submission)



dipgg.desktopimaging.co.nz
993
IMAP (encrypted)



dipgg.desktopimaging.co.nz
993
IMAP (encrypted)



dipgg.desktopimaging.co.nz
995
POP3 (encrypted)



dipgg.desktopimaging.co.nz
995
POP3 (encrypted)



dipgg.desktopimaging.co.nz
1433
MS SQL



dipgg.desktopimaging.co.nz
1433
MS SQL



dipgg.desktopimaging.co.nz
2082
cPanel (http)



dipgg.desktopimaging.co.nz
2082
cPanel (http)



dipgg.desktopimaging.co.nz
2083
cPanel (https)



dipgg.desktopimaging.co.nz
2083
cPanel (https)



dipgg.desktopimaging.co.nz
2086
WHM (http)



dipgg.desktopimaging.co.nz
2086
WHM (http)



dipgg.desktopimaging.co.nz
2087
WHM (https)



dipgg.desktopimaging.co.nz
2087
WHM (https)



dipgg.desktopimaging.co.nz
2089
cPanel Licensing



dipgg.desktopimaging.co.nz
2089
cPanel Licensing



dipgg.desktopimaging.co.nz
2095
cPanel Webmail (http)



dipgg.desktopimaging.co.nz
2095
cPanel Webmail (http)



dipgg.desktopimaging.co.nz
2096
cPanel Webmail (https)



dipgg.desktopimaging.co.nz
2096
cPanel Webmail (https)



dipgg.desktopimaging.co.nz
2222
DirectAdmin (http)



dipgg.desktopimaging.co.nz
2222
DirectAdmin (http)



dipgg.desktopimaging.co.nz
2222
DirectAdmin (https)



dipgg.desktopimaging.co.nz
2222
DirectAdmin (https)



dipgg.desktopimaging.co.nz
3306
mySql



dipgg.desktopimaging.co.nz
3306
mySql



dipgg.desktopimaging.co.nz
5224
Plesk Licensing



dipgg.desktopimaging.co.nz
5224
Plesk Licensing



dipgg.desktopimaging.co.nz
5432
PostgreSQL



dipgg.desktopimaging.co.nz
5432
PostgreSQL



dipgg.desktopimaging.co.nz
8080
Ookla Speedtest (http)



dipgg.desktopimaging.co.nz
8080
Ookla Speedtest (http)



dipgg.desktopimaging.co.nz
8080
Ookla Speedtest (https)



dipgg.desktopimaging.co.nz
8080
Ookla Speedtest (https)



dipgg.desktopimaging.co.nz
8083
VestaCP http



dipgg.desktopimaging.co.nz
8083
VestaCP http



dipgg.desktopimaging.co.nz
8083
VestaCP https



dipgg.desktopimaging.co.nz
8083
VestaCP https



dipgg.desktopimaging.co.nz
8443
Plesk Administration (https)



dipgg.desktopimaging.co.nz
8443
Plesk Administration (https)



dipgg.desktopimaging.co.nz
8447
Plesk Installer + Updates



dipgg.desktopimaging.co.nz
8447
Plesk Installer + Updates



dipgg.desktopimaging.co.nz
8880
Plesk Administration (http)



dipgg.desktopimaging.co.nz
8880
Plesk Administration (http)



dipgg.desktopimaging.co.nz
10000
Webmin (http)



dipgg.desktopimaging.co.nz
10000
Webmin (http)



dipgg.desktopimaging.co.nz
10000
Webmin (https)



dipgg.desktopimaging.co.nz
10000
Webmin (https)



203.97.68.250
21
FTP



203.97.68.250
21
FTP



203.97.68.250
22
SSH



203.97.68.250
22
SSH



203.97.68.250
25
SMTP



203.97.68.250
25
SMTP



203.97.68.250
53
DNS



203.97.68.250
53
DNS



203.97.68.250
110
POP3



203.97.68.250
110
POP3



203.97.68.250
143
IMAP



203.97.68.250
143
IMAP



203.97.68.250
465
SMTP (encrypted)



203.97.68.250
465
SMTP (encrypted)



203.97.68.250
587
SMTP (encrypted, submission)



203.97.68.250
587
SMTP (encrypted, submission)



203.97.68.250
993
IMAP (encrypted)



203.97.68.250
993
IMAP (encrypted)



203.97.68.250
995
POP3 (encrypted)



203.97.68.250
995
POP3 (encrypted)



203.97.68.250
1433
MS SQL



203.97.68.250
1433
MS SQL



203.97.68.250
2082
cPanel (http)



203.97.68.250
2082
cPanel (http)



203.97.68.250
2083
cPanel (https)



203.97.68.250
2083
cPanel (https)



203.97.68.250
2086
WHM (http)



203.97.68.250
2086
WHM (http)



203.97.68.250
2087
WHM (https)



203.97.68.250
2087
WHM (https)



203.97.68.250
2089
cPanel Licensing



203.97.68.250
2089
cPanel Licensing



203.97.68.250
2095
cPanel Webmail (http)



203.97.68.250
2095
cPanel Webmail (http)



203.97.68.250
2096
cPanel Webmail (https)



203.97.68.250
2096
cPanel Webmail (https)



203.97.68.250
2222
DirectAdmin (http)



203.97.68.250
2222
DirectAdmin (http)



203.97.68.250
2222
DirectAdmin (https)



203.97.68.250
2222
DirectAdmin (https)



203.97.68.250
3306
mySql



203.97.68.250
3306
mySql



203.97.68.250
5224
Plesk Licensing



203.97.68.250
5224
Plesk Licensing



203.97.68.250
5432
PostgreSQL



203.97.68.250
5432
PostgreSQL



203.97.68.250
8080
Ookla Speedtest (http)



203.97.68.250
8080
Ookla Speedtest (http)



203.97.68.250
8080
Ookla Speedtest (https)



203.97.68.250
8080
Ookla Speedtest (https)



203.97.68.250
8083
VestaCP http



203.97.68.250
8083
VestaCP http



203.97.68.250
8083
VestaCP https



203.97.68.250
8083
VestaCP https



203.97.68.250
8443
Plesk Administration (https)



203.97.68.250
8443
Plesk Administration (https)



203.97.68.250
8447
Plesk Installer + Updates



203.97.68.250
8447
Plesk Installer + Updates



203.97.68.250
8880
Plesk Administration (http)



203.97.68.250
8880
Plesk Administration (http)



203.97.68.250
10000
Webmin (http)



203.97.68.250
10000
Webmin (http)



203.97.68.250
10000
Webmin (https)



203.97.68.250
10000
Webmin (https)





Permalink: https://check-your-website.server-daten.de/?i=76f26501-d02f-4b61-aa30-637da47a1f83


Last Result: https://check-your-website.server-daten.de/?q=dipgg.desktopimaging.co.nz - 2020-06-02 01:15:47


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=dipgg.desktopimaging.co.nz" target="_blank">Check this Site: dipgg.desktopimaging.co.nz</a>