Check DNS, Urls + Redirects, Certificates and Content of your Website



X

DNS-problem - authoritative Nameserver refused, not defined or timeout

Checked:
17.10.2020 20:28:14


Older results

No older results found


1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
diyacoo.ir
A
91.92.129.226
Tehran/Ostan-e Tehran/Iran (IR) - TIC
No Hostname found
yes
1
0

AAAA

yes


www.diyacoo.ir
A
91.92.129.226
Tehran/Ostan-e Tehran/Iran (IR) - TIC
No Hostname found
yes
1
0

AAAA

yes


*.diyacoo.ir
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 26116, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.11.2020, 00:00:00 +, Signature-Inception: 11.10.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: ir
ir
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "ir" and the NextOwner "irish". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: NS, RRSIG, NSEC



0 DNSKEY RR found




Zone: diyacoo.ir
diyacoo.ir
0 DS RR in the parent zone found



0 DNSKEY RR found




Zone: www.diyacoo.ir
www.diyacoo.ir
0 DS RR in the parent zone found


3. Name Servers

DomainNameserverNS-IP
www.diyacoo.ir
  ns1.diyacoo.ir

diyacoo.ir
  ns1.diyacoo.ir
91.92.129.226
Tehran/Ostan-e Tehran/Iran (IR) - TIC


  ns2.diyacoo.ir
91.92.129.226
Tehran/Ostan-e Tehran/Iran (IR) - TIC

ir
  a.nic.ir


  b.nic.ir / localhost


  dns-ir.univie.ac.at / dns-ir.univie.ac.at


  ir.cctld.authdns.ripe.net / ns3.nl-ams.authdns.ripe.net


  ns1.nic.ir


  ns5.univie.ac.at


4. SOA-Entries


Domain:ir
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:ir
Zone-Name:ir
Primary:ns1.nic.ir
Mail:info.nic.ir
Serial:2020101718
Refresh:14400
Retry:1800
Expire:604800
TTL:1440
num Entries:5


Domain:diyacoo.ir
Zone-Name:diyacoo.ir
Primary:ns1.diyacoo.ir
Mail:hostmaster.diyacoo.ir
Serial:20
Refresh:14400
Retry:130
Expire:1209600
TTL:14400
num Entries:2


Domain:www.diyacoo.ir
Zone-Name:diyacoo.ir
Primary:ns1.diyacoo.ir
Mail:hostmaster.diyacoo.ir
Serial:20
Refresh:14400
Retry:130
Expire:1209600
TTL:14400
num Entries:1


5. Screenshots

Startaddress: https://diyacoo.ir/b, address used: https://diyacoo.ir/b, Screenshot created 2020-10-17 20:29:54 +00:0

Mobil (412px x 732px)

383 milliseconds

Screenshot mobile - https://diyacoo.ir/b
Mobil + Landscape (732px x 412px)

382 milliseconds

Screenshot mobile landscape - https://diyacoo.ir/b
Screen (1280px x 1680px)

732 milliseconds

Screenshot Desktop - https://diyacoo.ir/b

Mobile- and other Chrome-Checks

widthheight
visual Viewport412732
content Size412732

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

Chrome-Connection: secure. secure connection settings. The connection to this site is encrypted and authenticated using TLS 1.2, ECDHE_RSA with P-256, and AES_128_GCM.

Chrome-Resources : secure. all served securely. All resources on this page are served securely.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://diyacoo.ir/
91.92.129.226
301
https://diyacoo.ir/
Html is minified: 107.78 %
0.237
A
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:46 GMT
Content-Type: text/html
Content-Length: 194
Connection: close
Location: https://diyacoo.ir/

• http://www.diyacoo.ir/
91.92.129.226 GZip used - 384 / 612 - 37.25 %
200

Html is minified: 129.94 %
0.237
H
small visible content (num chars: 273)
Welcome to nginx! If you see this page, the nginx web server is successfully installed and working. Further configuration is required. For online documentation and support please refer to nginx.org . Commercial support is available at nginx.com . Thank you for using nginx.
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:46 GMT
Content-Type: text/html
Last-Modified: Sat, 17 Oct 2020 17:34:54 GMT
Transfer-Encoding: chunked
Connection: close
ETag: W/"5f8b2b3e-264"
Content-Encoding: gzip

• https://diyacoo.ir/
91.92.129.226
307
https://diyacoo.ir/b
Html is minified: 107.69 %
4.864
B
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:47 GMT
Content-Type: text/html
Content-Length: 196
Location: https://diyacoo.ir/b
Connection: close

• https://www.diyacoo.ir/
91.92.129.226
307
https://www.diyacoo.ir/b
Html is minified: 107.69 %
4.747
N
Certificate error: RemoteCertificateNameMismatch
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:52 GMT
Content-Type: text/html
Content-Length: 196
Location: https://www.diyacoo.ir/b
Connection: close

• https://diyacoo.ir/b
GZip used - 141 / 178 - 20.79 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 108.54 %
4.827
M
Not Found
small visible content (num chars: 35)
404 Not Found nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:29:03 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• https://www.diyacoo.ir/b
GZip used - 141 / 178 - 20.79 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 108.54 %
4.813
N
Not Found
Certificate error: RemoteCertificateNameMismatch
small visible content (num chars: 35)
404 Not Found nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:29:09 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• http://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
91.92.129.226
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 107.78 %
0.237
A
Visible Content: 301 Moved Permanently nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:57 GMT
Content-Type: text/html
Content-Length: 194
Connection: close
Location: https://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

• http://www.diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
91.92.129.226 GZip used - 141 / 178 - 20.79 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 108.54 %
0.234
A
Not Found
Visible Content: 404 Not Found nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:58 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• https://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
GZip used - 141 / 178 - 20.79 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 108.54 %
4.780
A
Not Found
Visible Content: 404 Not Found nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:29:14 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• https://91.92.129.226/
91.92.129.226
307
https://91.92.129.226/b
Html is minified: 107.69 %
4.560
N
Certificate error: RemoteCertificateNameMismatch
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:28:58 GMT
Content-Type: text/html
Content-Length: 196
Location: https://91.92.129.226/b
Connection: close

• https://91.92.129.226/b
GZip used - 141 / 178 - 20.79 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 108.54 %
4.623
N
Not Found
Certificate error: RemoteCertificateNameMismatch
small visible content (num chars: 35)
404 Not Found nginx/1.10.3 (Ubuntu)
Server: nginx/1.10.3 (Ubuntu)
Date: Sat, 17 Oct 2020 18:29:19 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

7. Comments


1. General Results, most used to calculate the result

Aname "diyacoo.ir" is domain, public suffix is ".ir", top-level-domain is ".ir", top-level-domain-type is "country-code", Country is Iran (Islamic Republic of), tld-manager is "Institute for Research in Fundamental Sciences", num .ir-domains preloaded: 145 (complete: 131120)
Agood: All ip addresses are public addresses
Warning: Only one ip address found: diyacoo.ir has only one ip address.
Warning: Only one ip address found: www.diyacoo.ir has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: diyacoo.ir has no ipv6 address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: www.diyacoo.ir has no ipv6 address.
Agood: No asked Authoritative Name Server had a timeout
Ahttps://diyacoo.ir/ 91.92.129.226
307
https://diyacoo.ir/b
correct redirect https to https
Ahttps://www.diyacoo.ir/ 91.92.129.226
307
https://www.diyacoo.ir/b
correct redirect https to https
Ahttps://91.92.129.226/ 91.92.129.226
307
https://91.92.129.226/b
correct redirect https to https
Agood - only one version with Http-Status 200
AGood: No cookie sent via http.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):0 complete Content-Type - header (6 urls)
http://www.diyacoo.ir/ 91.92.129.226


Url with incomplete Content-Type - header - missing charset
https://diyacoo.ir/b


Url with incomplete Content-Type - header - missing charset
https://www.diyacoo.ir/b


Url with incomplete Content-Type - header - missing charset
http://www.diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 91.92.129.226


Url with incomplete Content-Type - header - missing charset
https://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de


Url with incomplete Content-Type - header - missing charset
https://91.92.129.226/b


Url with incomplete Content-Type - header - missing charset
Ahttp://diyacoo.ir/ 91.92.129.226
301
https://diyacoo.ir/
correct redirect http - https with the same domain name
Bhttps://diyacoo.ir/ 91.92.129.226
307

Missing HSTS-Header
Bhttps://diyacoo.ir/b
404

Missing HSTS-Header
Bhttps://www.diyacoo.ir/ 91.92.129.226
307

Missing HSTS-Header
Bhttps://www.diyacoo.ir/b
404

Missing HSTS-Header
Bhttps://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Missing HSTS-Header
Hfatal error: No https - result with http-status 200, no encryption
HFatal error: http result with http-status 200, no encryption. Add a redirect http ⇒ https, so every connection is secure. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop.
Mhttps://diyacoo.ir/b
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://www.diyacoo.ir/b
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://91.92.129.226/b
404

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://www.diyacoo.ir/ 91.92.129.226
307
https://www.diyacoo.ir/b
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://www.diyacoo.ir/b
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://91.92.129.226/ 91.92.129.226
307
https://91.92.129.226/b
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://91.92.129.226/b
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain diyacoo.ir, 1 ip addresses, 1 different http results.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain www.diyacoo.ir, 1 ip addresses, 1 different http results.

2. DNS- and NameServer - Checks

AInfo:: 2 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 2 Name Servers.
AInfo:: 2 Queries complete, 2 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.ns1.diyacoo.ir (91.92.129.226), ns2.diyacoo.ir (91.92.129.226)
AGood (1 - 3.0):: An average of 1.0 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 2 different Name Servers found: ns1.diyacoo.ir, ns2.diyacoo.ir, 2 Name Servers included in Delegation: ns1.diyacoo.ir, ns2.diyacoo.ir, 1 Name Servers included in 1 Zone definitions: ns1.diyacoo.ir, 1 Name Servers listed in SOA.Primary: ns1.diyacoo.ir.
AGood: Only one SOA.Primary Name Server found.: ns1.diyacoo.ir.
AGood: SOA.Primary Name Server included in the delegation set.: ns1.diyacoo.ir.
XFatal: Inconsistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone.: ns1.diyacoo.ir (91.92.129.226): Delegation: ns1.diyacoo.ir, ns2.diyacoo.ir, Zone: ns1.diyacoo.ir. Name Servers defined in Delegation, missing in Zone: ns2.diyacoo.ir.
XFatal: Inconsistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone.: ns2.diyacoo.ir (91.92.129.226): Delegation: ns1.diyacoo.ir, ns2.diyacoo.ir, Zone: ns1.diyacoo.ir. Name Servers defined in Delegation, missing in Zone: ns2.diyacoo.ir.
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 2 different Name Servers found
Warning: No Name Server IPv6 address found. IPv6 is the future, so your name servers should be visible via IPv6.: 2 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 2 Name Servers, 1 Top Level Domain: ir
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: diyacoo.ir
Warning: All Name Servers from the same Country / IP location.: 2 Name Servers, 1 Countries: IR
AInfo: Ipv4-Subnet-list: 2 Name Servers, 1 different subnets (first Byte): 91., 1 different subnets (first two Bytes): 91.92., 1 different subnets (first three Bytes): 91.92.129.
XFatal: All Name Server IPv4 addresses from the same subnet. Check https://www.iana.org/help/nameserver-requirements to learn some basics about name server configurations. If you manage these name servers, fix it. If it's your provider, change your provider.:
XFatal: Only one Name Server IPv4 address found. Check https://www.iana.org/help/nameserver-requirements to learn some basics about name server configurations. If you manage these name servers, fix it. If it's your provider, change your provider.
AGood: Nameserver supports TCP connections: 2 good Nameserver
AGood: Nameserver supports Echo Capitalization: 2 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 2 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 2 good Nameserver
Nameserver doesn't pass all EDNS-Checks: ns1.nic.ir: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

3. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://diyacoo.ir/b
404
4.827 seconds
Warning: 404 needs more then one second
https://www.diyacoo.ir/b
404
4.813 seconds
Warning: 404 needs more then one second
https://diyacoo.ir/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
4.780 seconds
Warning: 404 needs more then one second
https://91.92.129.226/b
404
4.623 seconds
Warning: 404 needs more then one second
ADuration: 105840 milliseconds, 105.840 seconds


8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
diyacoo.ir
diyacoo.ir
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
diyacoo.ir
diyacoo.ir
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


diyacoo.ir
91.92.129.226
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

diyacoo.ir
91.92.129.226
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


www.diyacoo.ir
www.diyacoo.ir
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

www.diyacoo.ir
www.diyacoo.ir
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


www.diyacoo.ir
91.92.129.226
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

www.diyacoo.ir
91.92.129.226
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


91.92.129.226
91.92.129.226
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

91.92.129.226
91.92.129.226
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


91.92.129.226
91.92.129.226
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

91.92.129.226
91.92.129.226
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)
1CN=diyacoo.ir

2CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US


9. Certificates

1.
1.
CN=diyacoo.ir
17.10.2020
15.01.2021
expires in 78 days
diyacoo.ir - 1 entry
1.
1.
CN=diyacoo.ir
17.10.2020

15.01.2021
expires in 78 days
diyacoo.ir - 1 entry

KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:04F86A3ABCED9AE040EAC01D6198193FC9D0
Thumbprint:A6E0C253DB5AB5F5FC773415E793AF7580E0FF6C
SHA256 / Certificate:4mu+JKCc3IzJctwrsgMV58zUHw2seJs1FPAMp7brrFI=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):cfebd0c572f832627abf28f085a7452107395db30e8fea447b852f0ba15367f8
SHA256 hex / Subject Public Key Information (SPKI):98b70d9e1a953fbba2881099ea249944a793ddfbc953badea43d3f0874e06b83
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.int-x3.letsencrypt.org
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)


2.
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
17.03.2016
17.03.2021
expires in 139 days


2.
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
17.03.2016

17.03.2021
expires in 139 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0A0141420000015385736A0B85ECA708
Thumbprint:E6A3B45B062D509B3382282D196EFE97D5956CCB
SHA256 / Certificate:JYR9Zo608E/dQLErawdAxWfafQJDCOtsLJb+QdneIY0=
SHA256 hex / Cert (DANE * 0 1):25847d668eb4f04fdd40b12b6b0740c567da7d024308eb6c2c96fe41d9de218d
SHA256 hex / PublicKey (DANE * 1 1):60b87575447dcba2a36b7d11ac09fb24a9db406fee12d2cc90180517616e8a18
SHA256 hex / Subject Public Key Information (SPKI):cbb93d32de628874a3ecfb92affadc97f1b795f84cc6f24221a089dee1aa25ad
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://isrg.trustid.ocsp.identrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:


3.
CN=DST Root CA X3, O=Digital Signature Trust Co.
30.09.2000
30.09.2021
expires in 336 days


3.
CN=DST Root CA X3, O=Digital Signature Trust Co.
30.09.2000

30.09.2021
expires in 336 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:44AFB080D6A327BA893039862EF8406B
Thumbprint:DAC9024F54D8F6DF94935FB1732638CA6AD77C13
SHA256 / Certificate:BocmAzGnJAPZCfEF5pvPDTLhvSST/8bZIG0RvNZ3Bzk=
SHA256 hex / Cert (DANE * 0 1):0687260331a72403d909f105e69bcf0d32e1bd2493ffc6d9206d11bcd6770739
SHA256 hex / PublicKey (DANE * 1 1):563b3caf8cfef34c2335caf560a7a95906e8488462eb75ac59784830df9e5b2b
SHA256 hex / Subject Public Key Information (SPKI):29cc40db5e2de462a311cbbafaa1dc466960002335ecdf3317f2cd05c1d0bedf
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:



10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
0
2
2
CN=Certum Domain Validation CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL
0
1
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
2001146632
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-10-17 16:43:11
2021-01-15 16:43:11
diyacoo.ir - 1 entries


2000992145
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-10-17 14:58:08
2021-01-15 14:58:08
diyacoo.ir - 1 entries


1998810072
precert
CN=Certum Domain Validation CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL
2020-10-16 17:15:37
2021-10-15 17:15:37
diyacoo.ir, www.diyacoo.ir - 2 entries



2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > 2019 are listed

Issuerlast 7 daysactivenum Certs
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
0 /0 new
2
2
CN=Certum Domain Validation CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL
0
1
1

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
3521866154
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-10-17 14:43:11
2021-01-15 15:43:11
diyacoo.ir
1 entries


3521567237
leaf cert
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US
2020-10-17 12:58:08
2021-01-15 13:58:08
diyacoo.ir
1 entries


3517450570
precert
CN=Certum Domain Validation CA SHA2, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL
2020-10-16 15:15:37
2021-10-15 15:15:37
diyacoo.ir, www.diyacoo.ir
2 entries



11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404


12. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.diyacoo.ir, ns2.diyacoo.ir

QNr.DomainTypeNS used
1
ir
NS
e.root-servers.net (2001:500:a8::e)

Answer: a.nic.ir, b.nic.ir, ir.cctld.authdns.ripe.net, ns5.univie.ac.at
2
ns1.diyacoo.ir: 91.92.129.226
NS
ir.cctld.authdns.ripe.net (2001:67c:e0::85)

Answer: ns2.diyacoo.ir
91.92.129.226


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.diyacoo.ir
0

no CAA entry found
1
0
diyacoo.ir
0

no CAA entry found
1
0
ir
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
diyacoo.ir

ok
1
0
www.diyacoo.ir

ok
1
0
_acme-challenge.diyacoo.ir

Name Error - The domain name does not exist
1
0
_acme-challenge.www.diyacoo.ir

Name Error - The domain name does not exist
1
0
_acme-challenge.diyacoo.ir.diyacoo.ir

Name Error - The domain name does not exist
1
0
_acme-challenge.www.diyacoo.ir.diyacoo.ir

Name Error - The domain name does not exist
1
0
_acme-challenge.www.diyacoo.ir.www.diyacoo.ir

Name Error - The domain name does not exist
1
0


15. Portchecks

Domain or IPPortDescriptionResultAnswer
diyacoo.ir
21
FTP



diyacoo.ir
21
FTP



diyacoo.ir
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

diyacoo.ir
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

diyacoo.ir
25
SMTP



diyacoo.ir
25
SMTP



diyacoo.ir
53
DNS
open


diyacoo.ir
53
DNS
open


diyacoo.ir
110
POP3



diyacoo.ir
110
POP3



diyacoo.ir
143
IMAP



diyacoo.ir
143
IMAP



diyacoo.ir
465
SMTP (encrypted)



diyacoo.ir
465
SMTP (encrypted)



diyacoo.ir
587
SMTP (encrypted, submission)



diyacoo.ir
587
SMTP (encrypted, submission)



diyacoo.ir
993
IMAP (encrypted)



diyacoo.ir
993
IMAP (encrypted)



diyacoo.ir
995
POP3 (encrypted)



diyacoo.ir
995
POP3 (encrypted)



diyacoo.ir
1433
MS SQL



diyacoo.ir
1433
MS SQL



diyacoo.ir
2082
cPanel (http)



diyacoo.ir
2082
cPanel (http)



diyacoo.ir
2083
cPanel (https)



diyacoo.ir
2083
cPanel (https)



diyacoo.ir
2086
WHM (http)



diyacoo.ir
2086
WHM (http)



diyacoo.ir
2087
WHM (https)



diyacoo.ir
2087
WHM (https)



diyacoo.ir
2089
cPanel Licensing



diyacoo.ir
2089
cPanel Licensing



diyacoo.ir
2095
cPanel Webmail (http)



diyacoo.ir
2095
cPanel Webmail (http)



diyacoo.ir
2096
cPanel Webmail (https)



diyacoo.ir
2096
cPanel Webmail (https)



diyacoo.ir
2222
DirectAdmin (http)



diyacoo.ir
2222
DirectAdmin (http)



diyacoo.ir
2222
DirectAdmin (https)



diyacoo.ir
2222
DirectAdmin (https)



diyacoo.ir
3306
mySql



diyacoo.ir
3306
mySql



diyacoo.ir
5224
Plesk Licensing



diyacoo.ir
5224
Plesk Licensing



diyacoo.ir
5432
PostgreSQL



diyacoo.ir
5432
PostgreSQL



diyacoo.ir
8080
Ookla Speedtest (http)
open
http://diyacoo.ir:8080/
Http-Status: 200

diyacoo.ir
8080
Ookla Speedtest (http)
open
http://diyacoo.ir:8080/
Http-Status: 200

diyacoo.ir
8080
Ookla Speedtest (https)
open
https://diyacoo.ir:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

diyacoo.ir
8080
Ookla Speedtest (https)
open
https://diyacoo.ir:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

diyacoo.ir
8083
VestaCP http



diyacoo.ir
8083
VestaCP http



diyacoo.ir
8083
VestaCP https



diyacoo.ir
8083
VestaCP https



diyacoo.ir
8443
Plesk Administration (https)



diyacoo.ir
8443
Plesk Administration (https)



diyacoo.ir
8447
Plesk Installer + Updates



diyacoo.ir
8447
Plesk Installer + Updates



diyacoo.ir
8880
Plesk Administration (http)



diyacoo.ir
8880
Plesk Administration (http)



diyacoo.ir
10000
Webmin (http)



diyacoo.ir
10000
Webmin (http)



diyacoo.ir
10000
Webmin (https)



diyacoo.ir
10000
Webmin (https)



www.diyacoo.ir
21
FTP



www.diyacoo.ir
21
FTP



www.diyacoo.ir
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

www.diyacoo.ir
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

www.diyacoo.ir
25
SMTP



www.diyacoo.ir
25
SMTP



www.diyacoo.ir
53
DNS
open


www.diyacoo.ir
53
DNS
open


www.diyacoo.ir
110
POP3



www.diyacoo.ir
110
POP3



www.diyacoo.ir
143
IMAP



www.diyacoo.ir
143
IMAP



www.diyacoo.ir
465
SMTP (encrypted)



www.diyacoo.ir
465
SMTP (encrypted)



www.diyacoo.ir
587
SMTP (encrypted, submission)



www.diyacoo.ir
587
SMTP (encrypted, submission)



www.diyacoo.ir
993
IMAP (encrypted)



www.diyacoo.ir
993
IMAP (encrypted)



www.diyacoo.ir
995
POP3 (encrypted)



www.diyacoo.ir
995
POP3 (encrypted)



www.diyacoo.ir
1433
MS SQL



www.diyacoo.ir
1433
MS SQL



www.diyacoo.ir
2082
cPanel (http)



www.diyacoo.ir
2082
cPanel (http)



www.diyacoo.ir
2083
cPanel (https)



www.diyacoo.ir
2083
cPanel (https)



www.diyacoo.ir
2086
WHM (http)



www.diyacoo.ir
2086
WHM (http)



www.diyacoo.ir
2087
WHM (https)



www.diyacoo.ir
2087
WHM (https)



www.diyacoo.ir
2089
cPanel Licensing



www.diyacoo.ir
2089
cPanel Licensing



www.diyacoo.ir
2095
cPanel Webmail (http)



www.diyacoo.ir
2095
cPanel Webmail (http)



www.diyacoo.ir
2096
cPanel Webmail (https)



www.diyacoo.ir
2096
cPanel Webmail (https)



www.diyacoo.ir
2222
DirectAdmin (http)



www.diyacoo.ir
2222
DirectAdmin (http)



www.diyacoo.ir
2222
DirectAdmin (https)



www.diyacoo.ir
2222
DirectAdmin (https)



www.diyacoo.ir
3306
mySql



www.diyacoo.ir
3306
mySql



www.diyacoo.ir
5224
Plesk Licensing



www.diyacoo.ir
5224
Plesk Licensing



www.diyacoo.ir
5432
PostgreSQL



www.diyacoo.ir
5432
PostgreSQL



www.diyacoo.ir
8080
Ookla Speedtest (http)
open
http://www.diyacoo.ir:8080/
Http-Status: 200

www.diyacoo.ir
8080
Ookla Speedtest (http)
open
http://www.diyacoo.ir:8080/
Http-Status: 200

www.diyacoo.ir
8080
Ookla Speedtest (https)
open
https://www.diyacoo.ir:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

www.diyacoo.ir
8080
Ookla Speedtest (https)
open
https://www.diyacoo.ir:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

www.diyacoo.ir
8083
VestaCP http



www.diyacoo.ir
8083
VestaCP http



www.diyacoo.ir
8083
VestaCP https



www.diyacoo.ir
8083
VestaCP https



www.diyacoo.ir
8443
Plesk Administration (https)



www.diyacoo.ir
8443
Plesk Administration (https)



www.diyacoo.ir
8447
Plesk Installer + Updates



www.diyacoo.ir
8447
Plesk Installer + Updates



www.diyacoo.ir
8880
Plesk Administration (http)



www.diyacoo.ir
8880
Plesk Administration (http)



www.diyacoo.ir
10000
Webmin (http)



www.diyacoo.ir
10000
Webmin (http)



www.diyacoo.ir
10000
Webmin (https)



www.diyacoo.ir
10000
Webmin (https)



91.92.129.226
21
FTP



91.92.129.226
21
FTP



91.92.129.226
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

91.92.129.226
22
SSH
open
SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

91.92.129.226
25
SMTP



91.92.129.226
25
SMTP



91.92.129.226
53
DNS
open


91.92.129.226
53
DNS
open


91.92.129.226
110
POP3



91.92.129.226
110
POP3



91.92.129.226
143
IMAP



91.92.129.226
143
IMAP



91.92.129.226
465
SMTP (encrypted)



91.92.129.226
465
SMTP (encrypted)



91.92.129.226
587
SMTP (encrypted, submission)



91.92.129.226
587
SMTP (encrypted, submission)



91.92.129.226
993
IMAP (encrypted)



91.92.129.226
993
IMAP (encrypted)



91.92.129.226
995
POP3 (encrypted)



91.92.129.226
995
POP3 (encrypted)



91.92.129.226
1433
MS SQL



91.92.129.226
1433
MS SQL



91.92.129.226
2082
cPanel (http)



91.92.129.226
2082
cPanel (http)



91.92.129.226
2083
cPanel (https)



91.92.129.226
2083
cPanel (https)



91.92.129.226
2086
WHM (http)



91.92.129.226
2086
WHM (http)



91.92.129.226
2087
WHM (https)



91.92.129.226
2087
WHM (https)



91.92.129.226
2089
cPanel Licensing



91.92.129.226
2089
cPanel Licensing



91.92.129.226
2095
cPanel Webmail (http)



91.92.129.226
2095
cPanel Webmail (http)



91.92.129.226
2096
cPanel Webmail (https)



91.92.129.226
2096
cPanel Webmail (https)



91.92.129.226
2222
DirectAdmin (http)



91.92.129.226
2222
DirectAdmin (http)



91.92.129.226
2222
DirectAdmin (https)



91.92.129.226
2222
DirectAdmin (https)



91.92.129.226
3306
mySql



91.92.129.226
3306
mySql



91.92.129.226
5224
Plesk Licensing



91.92.129.226
5224
Plesk Licensing



91.92.129.226
5432
PostgreSQL



91.92.129.226
5432
PostgreSQL



91.92.129.226
8080
Ookla Speedtest (http)
open
http://91.92.129.226:8080/
Http-Status: 200

91.92.129.226
8080
Ookla Speedtest (http)
open
http://91.92.129.226:8080/
Http-Status: 200

91.92.129.226
8080
Ookla Speedtest (https)
open
https://91.92.129.226:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

91.92.129.226
8080
Ookla Speedtest (https)
open
https://91.92.129.226:8080/
Http-Status: -4
SendFailure - The underlying connection was closed: An unexpected error occurred on a send.

91.92.129.226
8083
VestaCP http



91.92.129.226
8083
VestaCP http



91.92.129.226
8083
VestaCP https



91.92.129.226
8083
VestaCP https



91.92.129.226
8443
Plesk Administration (https)



91.92.129.226
8443
Plesk Administration (https)



91.92.129.226
8447
Plesk Installer + Updates



91.92.129.226
8447
Plesk Installer + Updates



91.92.129.226
8880
Plesk Administration (http)



91.92.129.226
8880
Plesk Administration (http)



91.92.129.226
10000
Webmin (http)



91.92.129.226
10000
Webmin (http)



91.92.129.226
10000
Webmin (https)



91.92.129.226
10000
Webmin (https)





Permalink: https://check-your-website.server-daten.de/?i=81e2070f-a459-4bfe-91ad-400075f7ebfa


Last Result: https://check-your-website.server-daten.de/?q=diyacoo.ir - 2020-10-17 20:28:14


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=diyacoo.ir" target="_blank">Check this Site: diyacoo.ir</a>