Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

O

 

old / weak connection

 

Checked:
09.05.2025 20:55:48

 

Older results

No older results found

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
dns.constellix.com
A
208.80.120.50
Ashburn/Virginia/United States (US) - Tiggee LLC
Hostname: systems.tiggee.net
yes
1
0

AAAA

yes


www.dns.constellix.com

Name Error
yes
1
0
*.constellix.com
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


*.dns.constellix.com
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 53148, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: com

com
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=






1 RRSIG RR to validate DS RR found






RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.05.2025, 17:00:00 +, Signature-Inception: 09.05.2025, 16:00:00 +, KeyTag 53148, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 53148 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 19718, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 40097, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner com., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 17.05.2025, 14:02:35 +, Signature-Inception: 02.05.2025, 13:57:35 +, KeyTag 19718, Signer-Name: com






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 19718 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest "isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: constellix.com

constellix.com
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "uv3f9trspr0t621gphols4lkp5s9djtv" between the hashed NSEC3-owner "uv3f83kc5jolgc86i73h188ei4gjjo1f" and the hashed NextOwner "uv3ffk3n8g34l45pg8ujj4cspspa59lp". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner uv3f83kc5jolgc86i73h188ei4gjjo1f.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 13.05.2025, 00:19:27 +, Signature-Inception: 05.05.2025, 23:09:27 +, KeyTag 40097, Signer-Name: com






DS-Query in the parent zone sends valid NSEC3 RR with the Hash "ck0pojmg874ljref7efn8430qvit8bsm" as Owner. That's the Hash of "com" with the NextHashedOwnerName "ck0q3udg8cekkae7rukpgct1dvssh8ll". So that domain name is the Closest Encloser of "constellix.com". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner ck0pojmg874ljref7efn8430qvit8bsm.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 15.05.2025, 00:25:55 +, Signature-Inception: 07.05.2025, 23:15:55 +, KeyTag 40097, Signer-Name: com






0 DNSKEY RR found









Zone: dns.constellix.com

dns.constellix.com
0 DS RR in the parent zone found






0 DNSKEY RR found









Zone: www.dns.constellix.com

www.dns.constellix.com
0 DS RR in the parent zone found

 

3. Name Servers

DomainNameserverNS-IP
www.dns.constellix.com
  ns11.constellix.com

dns.constellix.com
  ns11.constellix.com
96.45.80.1
New York/United States (US) - Tiggee LLC


 
2600:180a:1001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns21.constellix.com
46.31.236.1
Reston/Virginia/United States (US) - TIGGEE


 
2600:180b:2001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns31.constellix.com
43.247.170.1
Chiyoda/Tokyo/Japan (JP) - Tiggee LLC


 
2600:180c:3001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns41.constellix.net
96.45.81.1
New York/United States (US) - Tiggee LLC


 
2600:180a:4001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns51.constellix.net
46.31.237.1
Reston/Virginia/United States (US) - TIGGEE


 
2600:180b:5001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns61.constellix.net
43.247.171.1
Chiyoda/Tokyo/Japan (JP) - Tiggee LLC


 
2600:180c:6001::1
Herndon/Virginia/United States (US) - Tiggee LLC

constellix.com
  ns11.constellix.com
96.45.80.1
New York/United States (US) - Tiggee LLC


 
2600:180a:1001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns21.constellix.com
46.31.236.1
Reston/Virginia/United States (US) - TIGGEE


 
2600:180b:2001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns31.constellix.com
43.247.170.1
Chiyoda/Tokyo/Japan (JP) - Tiggee LLC


 
2600:180c:3001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns41.constellix.net
96.45.81.1
New York/United States (US) - Tiggee LLC


 
2600:180a:4001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns51.constellix.net
46.31.237.1
Reston/Virginia/United States (US) - TIGGEE


 
2600:180b:5001::1
Herndon/Virginia/United States (US) - Tiggee LLC


  ns61.constellix.net
43.247.171.1
Chiyoda/Tokyo/Japan (JP) - Tiggee LLC


 
2600:180c:6001::1
Herndon/Virginia/United States (US) - Tiggee LLC

com
  a.gtld-servers.net / nnn1-par6


  b.gtld-servers.net / nnn1-eltxl1


  c.gtld-servers.net / nnn1-par6


  d.gtld-servers.net / nnn1-par6


  e.gtld-servers.net / nnn1-par6


  f.gtld-servers.net / nnn1-defra-4


  g.gtld-servers.net / nnn1-defra-4


  h.gtld-servers.net / nnn1-defra-4


  i.gtld-servers.net / nnn1-defra-4


  j.gtld-servers.net / nnn1-frmrs-2


  k.gtld-servers.net / nnn1-frmrs-2


  l.gtld-servers.net / nnn1-frmrs-2


  m.gtld-servers.net / nnn1-frmrs-2

 

4. SOA-Entries


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1746816930
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:9


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1746816945
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:4


Domain:constellix.com
Zone-Name:constellix.com
Primary:ns11.constellix.com
Mail:dns.constellix.com
Serial:2015010687
Refresh:43200
Retry:3600
Expire:1209600
TTL:180
num Entries:12


Domain:dns.constellix.com
Zone-Name:dns.constellix.com
Primary:ns11.constellix.com
Mail:dns.constellix.com
Serial:2015010394
Refresh:43200
Retry:3600
Expire:1209600
TTL:180
num Entries:12


Domain:www.dns.constellix.com
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


5. Screenshots

Startaddress: https://auth.constellix.com/login, address used: https://auth.constellix.com/login, Screenshot created 2025-05-09 21:01:03 +00:0

 

Mobil (412px x 732px)

 

1289 milliseconds

 

Screenshot mobile - https://auth.constellix.com/login
Mobil + Landscape (732px x 412px)

 

1275 milliseconds

 

Screenshot mobile landscape - https://auth.constellix.com/login
Screen (1280px x 1680px)

 

1415 milliseconds

 

Screenshot Desktop - https://auth.constellix.com/login

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport396732
content Size396764

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://dns.constellix.com/
208.80.120.50
301
https://dns.constellix.com/
Html is minified: 109.03 %
0.236
A
Server: nginx/1.22.0
Date: Fri, 09 May 2025 18:57:40 GMT
Connection: keep-alive
Location: https://dns.constellix.com/
Content-Type: text/html
Content-Length: 169

• http://dns.constellix.com/login

301
https://dns.constellix.com/login
Html is minified: 109.03 %
0.250
A
Server: nginx/1.22.0
Date: Fri, 09 May 2025 18:57:53 GMT
Connection: keep-alive
Location: https://dns.constellix.com/login
Content-Type: text/html
Content-Length: 169

• https://dns.constellix.com/
208.80.120.50
302
http://dns.constellix.com/login

5.073
F
Date: Fri, 09 May 2025 18:57:40 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=A40AEDADAF40932C50A1F5EA453F1E9D; Path=/; HttpOnly
Location: http://dns.constellix.com/login
Content-Length: 0

• https://dns.constellix.com/login

302
https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns.constellix.com/login&response_type=code&scope=user_info&state=lTLIsz

3.980
B
Date: Fri, 09 May 2025 18:58:01 GMT
Connection: keep-alive
X-Application-Context: application:production
Location: https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns.constellix.com/login&response_type=code&scope=user_info&state=lTLIsz
Content-Length: 0

• https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns.constellix.com/login&response_type=code&scope=user_info&state=lTLIsz

302
https://auth.constellix.com/login

4.836
A
Date: Fri, 09 May 2025 18:58:05 GMT
Connection: keep-alive
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-store, must-revalidate, no-cache, max-age=0
Pragma: no-cache
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
X-Frame-Options: DENY,DENY
Set-Cookie: SESSION=ZWUzODMyMDctMTUxYi00OTZhLThlNTQtNTljNjM4NGMxYzdk; Path=/; Secure; HttpOnly; SameSite=Lax
Location: https://auth.constellix.com/login
Content-Length: 0
Expires: 0

• https://auth.constellix.com/login
gzip used - 3741 / 16221 - 76.94 %
Inline-JavaScript (∑/total): 5/4965 Inline-CSS (∑/total): 0/0
200

Html is minified: 207.35 %
Other inline scripts (∑/total): 0/0
3.997
I
Date: Fri, 09 May 2025 18:58:18 GMT
Transfer-Encoding: chunked
Connection: keep-alive
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-store, must-revalidate, no-cache, max-age=0
Pragma: no-cache
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
X-Frame-Options: DENY,DENY
Set-Cookie: SESSION=M2UxNTM4OWUtZWFlOC00NjVjLTk4MDYtZDVmMTBhZjdmMDQ4; Path=/; Secure; HttpOnly; SameSite=Lax
Content-Type: text/html; charset=UTF-8
Expires: 0
Content-Language: en-US
Content-Encoding: gzip
Content-Length: 3741

• http://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
208.80.120.50
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 109.03 %
Other inline scripts (∑/total): 0/0
0.240
A
Visible Content:
Server: nginx/1.22.0
Date: Fri, 09 May 2025 18:57:47 GMT
Connection: keep-alive
Location: https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Content-Type: text/html
Content-Length: 169

• https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
gzip used - 660 / 1212 - 45.54 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 1/79
404

Html is minified: 127.44 %
Other inline scripts (∑/total): 0/0
4.410
B
Visible Content:
Date: Fri, 09 May 2025 18:57:54 GMT
Transfer-Encoding: chunked
Connection: keep-alive
X-Application-Context: application:production
Set-Cookie: JSESSIONID=AEBDF6C03FB522419AAFDCECB8DFF081; Path=/; HttpOnly
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Encoding: gzip
Content-Length: 660

• http://208.80.120.50/login

301
http://dns-a.constellix.net/login
Html is minified: 109.03 %
0.234
D
Server: nginx/1.22.0
Date: Fri, 09 May 2025 18:58:00 GMT
Connection: keep-alive
Location: http://dns-a.constellix.net/login
Content-Type: text/html
Content-Length: 169

• http://dns-a.constellix.net/login

301
https://dns-a.constellix.net/login
Html is minified: 109.03 %
0.273
A
Server: nginx/1.22.0
Date: Fri, 09 May 2025 18:58:05 GMT
Connection: keep-alive
Location: https://dns-a.constellix.net/login
Content-Type: text/html
Content-Length: 169

• https://208.80.120.50/
208.80.120.50
302
http://208.80.120.50/login

4.847
N
Certificate error: RemoteCertificateNameMismatch
Date: Fri, 09 May 2025 18:57:47 GMT
Connection: keep-alive
Location: http://208.80.120.50/login
Content-Length: 0

• https://dns-a.constellix.net/login

302
https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns-a.constellix.net/login&response_type=code&scope=user_info&state=3JAgW9

4.870
B
Date: Fri, 09 May 2025 18:58:12 GMT
Connection: keep-alive
X-Application-Context: application:production
Set-Cookie: JSESSIONID=F2E1251FF6DD1F07BAB585A75830939E; Path=/; HttpOnly
Location: https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns-a.constellix.net/login&response_type=code&scope=user_info&state=3JAgW9
Content-Length: 0

 

7. Comments


1. General Results, most used to calculate the result

Aname "dns.constellix.com" is subdomain, public suffix is ".com", top-level-domain is ".com", top-level-domain-type is "generic", tld-manager is "VeriSign Global Registry Services", num .com-domains preloaded: 105479 (complete: 270180)
AGood: All ip addresses are public addresses
Warning: Only one ip address found: dns.constellix.com has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: dns.constellix.com has no ipv6 address.
AGood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
Ahttps://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns.constellix.com/login&response_type=code&scope=user_info&state=lTLIsz
302
https://auth.constellix.com/login
Correct redirect https to https
Ahttps://dns.constellix.com/login
302
https://auth.constellix.com/oauth/authorize?client_id=constellix_dns&redirect_uri=https://dns.constellix.com/login&response_type=code&scope=user_info&state=lTLIsz
Correct redirect https to https
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: non-www is preferred
AGood: No cookie sent via http.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: All urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset)
Ahttp://dns.constellix.com/ 208.80.120.50
301
https://dns.constellix.com/
Correct redirect http - https with the same domain name
Bhttps://dns.constellix.com/login
302

Missing HSTS-Header
Bhttps://dns.constellix.com/ 208.80.120.50
302

Missing HSTS-Header
Bhttps://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Missing HSTS-Header
Bhttps://dns.constellix.com/ 208.80.120.50
302
JSESSIONID=A40AEDADAF40932C50A1F5EA453F1E9D; Path=/; HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
JSESSIONID=AEBDF6C03FB522419AAFDCECB8DFF081; Path=/; HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://dns-a.constellix.net/login
302
JSESSIONID=F2E1251FF6DD1F07BAB585A75830939E; Path=/; HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://dns.constellix.com/ 208.80.120.50
302
JSESSIONID=A40AEDADAF40932C50A1F5EA453F1E9D; Path=/; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
JSESSIONID=AEBDF6C03FB522419AAFDCECB8DFF081; Path=/; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://dns-a.constellix.net/login
302
JSESSIONID=F2E1251FF6DD1F07BAB585A75830939E; Path=/; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Dhttp://208.80.120.50/login
301
http://dns-a.constellix.net/login
Wrong redirect one domain http to other domain http. First redirect to https without changing the domain, so no new dns query is required. So the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Fhttps://dns.constellix.com/ 208.80.120.50
302
http://dns.constellix.com/login
Wrong redirect https - http - never redirect https to http
Fhttps://208.80.120.50/ 208.80.120.50
302
http://208.80.120.50/login
Wrong redirect https - http - never redirect https to http
Ihttps://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Ihttps://auth.constellix.com/login
200

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Nhttps://208.80.120.50/ 208.80.120.50
302
http://208.80.120.50/login
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Odns.constellix.com / 208.80.120.50 / 443


Old connection: Cipher Suites without Forward Secrecy (FS) found. Remove all of these Cipher Suites, use only Cipher Suites with Forward Secrecy: Starting with ECDHE- or DHE - the last "E" says: "ephemeral". Or use Tls.1.3, then all Cipher Suites use FS. 16 Cipher Suites without Forward Secrecy found
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain dns.constellix.com, 1 ip addresses.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.dns.constellix.com

2. Header-Checks

Aauth.constellix.com
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
F
X-Frame-Options
Critical: Header with syntax errors found: DENY,DENY
B

Info: Header is deprecated. May not longer work in modern browsers. DENY,DENY. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
F

Critical: Duplicated values found. Looks like the page sends multiple headers with the same name. DENY,DENY
F

Critical: Unknown token found. Standard-token with additional characters are not defined. DENY,DENY
F

Critical: Unknown token found. Standard-token with additional characters are not defined. DENY,DENY
A
X-Xss-Protection
Ok: Header without syntax errors found: 1; mode=block
B

Info: Header is deprecated. May not longer work in modern browsers. 1; mode=block
Fauth.constellix.com
Content-Security-Policy
Critical: Missing Header:
Fauth.constellix.com
Referrer-Policy
Critical: Missing Header:
Fauth.constellix.com
Permissions-Policy
Critical: Missing Header:
Bauth.constellix.com
Cross-Origin-Embedder-Policy
Info: Missing Header
Bauth.constellix.com
Cross-Origin-Opener-Policy
Info: Missing Header
Bauth.constellix.com
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 4 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 6 Name Servers.
AInfo:: 4 Queries complete, 4 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.ns11.constellix.com (2600:180a:1001::1, 96.45.80.1), ns41.constellix.net (2600:180a:4001::1, 96.45.81.1), ns21.constellix.com (2600:180b:2001::1, 46.31.236.1), ns31.constellix.com (2600:180c:3001::1, 43.247.170.1), ns51.constellix.net (2600:180b:5001::1, 46.31.237.1), ns61.constellix.net (2600:180c:6001::1, 43.247.171.1)
AGood (1 - 3.0):: An average of 0.7 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 6 different Name Servers found: ns11.constellix.com, ns21.constellix.com, ns31.constellix.com, ns41.constellix.net, ns51.constellix.net, ns61.constellix.net, 6 Name Servers included in Delegation: ns11.constellix.com, ns21.constellix.com, ns31.constellix.com, ns41.constellix.net, ns51.constellix.net, ns61.constellix.net, 6 Name Servers included in 1 Zone definitions: ns11.constellix.com, ns21.constellix.com, ns31.constellix.com, ns41.constellix.net, ns51.constellix.net, ns61.constellix.net, 1 Name Servers listed in SOA.Primary: ns11.constellix.com.
AGood: Only one SOA.Primary Name Server found.: ns11.constellix.com.
AGood: SOA.Primary Name Server included in the delegation set.: ns11.constellix.com.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns11.constellix.com, ns21.constellix.com, ns31.constellix.com, ns41.constellix.net, ns51.constellix.net, ns61.constellix.net
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 6 different Name Servers found
AGood: All name servers have ipv4- and ipv6-addresses.: 6 different Name Servers found
AGood: Name servers with different Top Level Domains / Public Suffix List entries found: 6 Name Servers, 2 Top Level Domains: net, com
AGood: Name Servers with different domain names found.: 2 different Domains found
AGood: Name servers with different Country locations found: 6 Name Servers, 2 Countries: JP, US
AInfo: Ipv4-Subnet-list: 6 Name Servers, 3 different subnets (first Byte): 43., 46., 96., 3 different subnets (first two Bytes): 43.247., 46.31., 96.45., 6 different subnets (first three Bytes): 43.247.170., 43.247.171., 46.31.236., 46.31.237., 96.45.80., 96.45.81.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 6 Name Servers with IPv6, 1 different subnets (first block): 2600:, 3 different subnets (first two blocks): 2600:180a:, 2600:180b:, 2600:180c:, 6 different subnets (first three blocks): 2600:180a:1001:, 2600:180a:4001:, 2600:180b:2001:, 2600:180b:5001:, 2600:180c:3001:, 2600:180c:6001:, 6 different subnets (first four blocks): 2600:180a:1001:0000:, 2600:180a:4001:0000:, 2600:180b:2001:0000:, 2600:180b:5001:0000:, 2600:180c:3001:0000:, 2600:180c:6001:0000:
AGood: Name Server IPv6 addresses from different subnets found.
AGood: Nameserver supports TCP connections: 12 good Nameserver
AGood: Nameserver supports Echo Capitalization: 12 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 12 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 12 good Nameserver
Nameserver doesn't pass all EDNS-Checks: ns11.constellix.com: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://auth.constellix.com/login
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://auth.constellix.com/login
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://auth.constellix.com/login
200

Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
AGood: Some script Elements (type text/javascript) with a src-Attribute have a defer / async - Attribute. So loading and executing these JavaScripts doesn't block parsing and rendering the Html-Output.
https://auth.constellix.com/login
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 4 script elements without defer/async.
https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 1 script elements without defer/async.
Warning: CSS / JavaScript found without Compression. Compress these ressources, gzip, deflate, br are checked. 7 external CSS / JavaScript files without Compression found - 3 with Compression, 10 complete
AGood: All images with internal compression not compressed. Some Images (.png, .jpg, .jpeg, .webp, .gif) are already compressed, so an additional compression isn't helpful. 1 images (type image/png, image/jpg, image/jpeg, image/webp, image/gif) found without additional Compression. Not required because these images are already compressed
Warning: CSS / JavaScript files with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 0 external CSS / JavaScript files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 8 with Cache-Control max-age too short (minimum 7 days), 3 with Cache-Control long enough, 11 complete.
Warning: Images with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 0 image files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 1 with Cache-Control max-age too short (minimum 7 days), 1 with Cache-Control long enough, 2 complete.
AGood: All checked attribute values are enclosed in quotation marks (" or ').
AGood: All img-elements have a valid alt-attribute.: 2 img-elements found.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
4.410 seconds
Warning: 404 needs more then one second
ADuration: 321576 milliseconds, 321.576 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
dns.constellix.com
dns.constellix.com
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
dns.constellix.com
dns.constellix.com
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.constellix.com


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


dns.constellix.com
208.80.120.50
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

dns.constellix.com
208.80.120.50
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.constellix.com


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


auth.constellix.com
auth.constellix.com
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

auth.constellix.com
auth.constellix.com
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.constellix.com


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


auth.constellix.com
auth.constellix.com
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

auth.constellix.com
auth.constellix.com
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.constellix.com


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


dns.constellix.com
dns.constellix.com
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

dns.constellix.com
dns.constellix.com
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.constellix.com


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


208.80.120.50
208.80.120.50
443
name does not match
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

208.80.120.50
208.80.120.50
443
name does not match
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.constellix.net


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


dns-a.constellix.net
dns-a.constellix.net
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

dns-a.constellix.net
dns-a.constellix.net
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.constellix.net


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US

 

9. Certificates

1.
1.
CN=*.constellix.com
30.07.2024
31.08.2025
expires in 107 days
*.constellix.com - 1 entry
1.
1.
CN=*.constellix.com
30.07.2024

31.08.2025
expires in 107 days


*.constellix.com - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0C73AE2A62078EF099D229F80F73C270
Thumbprint:2F52C1D3AED3A4F0CC2C15D5F0AA5DE6FBC8B3B6
SHA256 / Certificate:5MrKwNZoD30OFpoWe3K86ALTWdmQpX9zCDknYfj3wU0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):7563cc4e457988449c858362e37dc65d32eef575a80300a702e659c447c502ce
SHA256 hex / Subject Public Key Information (SPKI):7563cc4e457988449c858362e37dc65d32eef575a80300a702e659c447c502ce (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://status.geotrust.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017
02.11.2027
expires in 900 days


2.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017

02.11.2027
expires in 900 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0D07782A133FC6F9A57296E131FFD179
Thumbprint:8B3C5B9B867D4BE46D1CB5A01D45D67DC8E94082
SHA256 / Certificate:wG4wf3z8HTL6cqTAM8h7kAGa8hbwd11kl4ouymyKIw4=
SHA256 hex / Cert (DANE * 0 1):c06e307f7cfc1d32fa72a4c033c87b90019af216f0775d64978a2eca6c8a230e
SHA256 hex / PublicKey (DANE * 1 1):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SHA256 hex / Subject Public Key Information (SPKI):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




3.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4627 days


3.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4627 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




2.
1.
CN=*.constellix.net
30.07.2024
31.08.2025
expires in 107 days
*.constellix.net - 1 entry
2.
1.
CN=*.constellix.net
30.07.2024

31.08.2025
expires in 107 days


*.constellix.net - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0B4CBC11A9FD68F751EEC8E8D9E86440
Thumbprint:D83928F94234FC9931871006D81E7C787EEA74E3
SHA256 / Certificate:DDcHwWfNm/ItyCHIvs/YLGfQBr8k1kD4MtvWtDJpJpY=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):95ce0f4eb09e9ccada9cad9c60fd35531b99becb99a17d3a639b12ed2774fdbe
SHA256 hex / Subject Public Key Information (SPKI):95ce0f4eb09e9ccada9cad9c60fd35531b99becb99a17d3a639b12ed2774fdbe (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://status.geotrust.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017
02.11.2027
expires in 900 days


2.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017

02.11.2027
expires in 900 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0D07782A133FC6F9A57296E131FFD179
Thumbprint:8B3C5B9B867D4BE46D1CB5A01D45D67DC8E94082
SHA256 / Certificate:wG4wf3z8HTL6cqTAM8h7kAGa8hbwd11kl4ouymyKIw4=
SHA256 hex / Cert (DANE * 0 1):c06e307f7cfc1d32fa72a4c033c87b90019af216f0775d64978a2eca6c8a230e
SHA256 hex / PublicKey (DANE * 1 1):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SHA256 hex / Subject Public Key Information (SPKI):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




3.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4627 days


3.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4627 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

No CertSpotter - CT-Log entries found

 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Issuerlast 7 daysactivenum Certs
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
0
1
2

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
13920772921
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2024-07-29 22:00:00
2025-08-30 21:59:59
*.constellix.com
1 entries


12462298535
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2024-03-20 23:00:00
2025-04-06 21:59:59
*.constellix.com
1 entries


 

11. Html-Content - Entries

Summary


Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://auth.constellix.com/login
a

6

0


0
0
0


form

1

0


0
0
0


img

1
3,878 Bytes
0
1
0
0
0
0


link
stylesheet
3
149,544 Bytes
0
3
0
0
0
0


link
other
1
4,286 Bytes
1
1
0
0
0
0


meta
other
5

0


0
0
0


script

5
140,292 Bytes
4
4
1
0
0
0

https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
img

1
2,501 Bytes
0
1
0
0
0
0


link
stylesheet
2
1,789 Bytes
0
2
0
0
0
0


link
other
1
1,393 Bytes
1
1
0
0
0
0


meta
other
2

0


0
0
0


script

1
81,285 Bytes
1
1
0
0
0
0

 

Details (currently limited to 500 rows - some problems with spam users)

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://auth.constellix.com/login

a

https://constellix.com/pdf/PrivacyPolicy-constellix.pdf


1
ok















a

https://manage.constellix.com/forgot


1
ok















a

https://plus.google.com/+ConstellixDNS


1
ok















a

https://twitter.com/Constellix


1
ok















a

https://www.facebook.com/Constellix/


1
ok















a

https://www.linkedin.com/company/constellix


1
ok















form
post



1
ok















img
src
/static/img/constellix-login-logo.png
200

1
ok
alt: Constellix logoimage/png
X-Content-Type-Options nosniff found





Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
No Compression - 3878 Bytes








link
icon
/static/img/favicon.ico
200

1
Problems with Content-Type - Header - see details
image/x-icon
X-Content-Type-Options nosniff found


This combination of Media Type "image" and MediaSubType "x-icon" was never defined. Use "image/vnd.microsoft.icon" instead. See https://www.iana.org/assignments/media-types/media-types.xhtml


Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
No Compression - 4286 Bytes








link
stylesheet
/static/css/bootstrap.min.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 122540 Bytes






local SRI possible, possible hash-values:

 

sha256-MfvZlkHCEqatNoGiOXveE8FIwMzZg4W85qfrfIFBfYc=
sha384-pdapHxIh7EYuwy6K7iE41uXVxGCXY0sAjBzaElYGJUrzwodck3Lx6IE2lA0rFREo
sha512-dTfge/zgoMYpP7QbHy4gWMEGsbsdZeCXz7irItjcC3sPUFtf0kuFbDz/ixG7ArTxmDjLXDmezHubeNikyKGVyQ==

 

<link rel="stylesheet" href="/static/css/bootstrap.min.css" crossorigin="anonymous" integrity="sha256-MfvZlkHCEqatNoGiOXveE8FIwMzZg4W85qfrfIFBfYc=" />



link
stylesheet
/static/css/font-awesome.min.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 21984 Bytes






local SRI possible, possible hash-values:

 

sha256-D7G7ynNkbo4rk8gujYshlkexPUtEDEjjOCkLmmhbjeE=
sha384-CmLV3WR+cw/TcN50vJSYAs2EAzhDD77tQvGcmoZ1KEzxtpl2K5xkrpFz9N2H9ClN
sha512-5kzQwP+NMBwPa9n+YJNDYtznvoWvV8nD4ccZ5C+HhM9we8kCW1j9HzQabe6ydJDj+oFkrtnMdmBTI6YCVEyCIA==

 

<link rel="stylesheet" href="/static/css/font-awesome.min.css" crossorigin="anonymous" integrity="sha256-D7G7ynNkbo4rk8gujYshlkexPUtEDEjjOCkLmmhbjeE=" />



link
stylesheet
/static/css/login-style.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 5020 Bytes






local SRI possible, possible hash-values:

 

sha256-ZsKFZ9eT18ZoPc7XBYR3quNfoMZBcCyM5C+tpnVureE=
sha384-nPwNhBENkPOoNVt2xNKhIHOweUJEZRRsXFCasBvVfDtJq4/brU2qoxcOTVuy4/81
sha512-EFFstODn/PDIQ3aXodQdUe3K3EtBINyGHsAftkj/GNEG7bTgPxF2ktqR3OspKNXd6Oy7JjT9CHaQov+kUL7Tbw==

 

<link rel="stylesheet" href="/static/css/login-style.css" crossorigin="anonymous" integrity="sha256-ZsKFZ9eT18ZoPc7XBYR3quNfoMZBcCyM5C+tpnVureE=" />



meta
charset
utf-8


1
ok















meta
X-UA-Compatible
IE=edge


1
ok















meta
author
Tiggee, LLC


1
ok















meta
description
Log into the Constellix suite


1
ok















meta
viewport
width=device-width, initial-scale=1


1
ok















script
src
/static/js/bootstrap.min.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript
X-Content-Type-Options nosniff found


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 36816 Bytes






local SRI possible, possible hash-values:

 

sha256-Sk3nkD6mLTMOF0EOpNtsIry+s1CsaqQC1rVLTAy+0yc=
sha384-pPttEvTHTuUJ9L2kCoMnNqCRcaMPMVMsWVO+RLaaaYDmfSP5//dP6eKRusbPcqhZ
sha512-K1qjQ+NcF2TYO/eI3M6v8EiNYZfA95pQumfvcVrTHtwQVDG+aHRqLi/ETn2uB+1JqwYqVG3LIvdm9lj6imS/pQ==

 

<script src="/static/js/bootstrap.min.js" crossorigin="anonymous" integrity="sha256-Sk3nkD6mLTMOF0EOpNtsIry+s1CsaqQC1rVLTAy+0yc=" />



script
src
/static/js/jquery.min.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript
X-Content-Type-Options nosniff found


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 89501 Bytes






local SRI possible, possible hash-values:

 

sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=
sha384-vtXRMe3mGCbOeY7l30aIg8H9p3GdeSe4IFlP6G8JMa7o7lXvnz3GFKzPxzJdPfGK
sha512-894YE6QWD5I59HgZOGReFYm4dnWc1Qt5NtvYSaNcOP+u1T9qYdvdihz0PPSiiqn/+/3e7Jo4EaG7TubfWGUrMQ==

 

<script src="/static/js/jquery.min.js" crossorigin="anonymous" integrity="sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=" />



script
src
/static/js/jquery.serialize-object.min.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript
X-Content-Type-Options nosniff found


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 1741 Bytes






local SRI possible, possible hash-values:

 

sha256-E8KRdFk/LTaaCBoQIV/rFNc0s3ICQQiOHFT4Cioifa8=
sha384-KYFeMOTAgIyQvYQLeL/yEyXmUj4ODI9UP6WmkioMPgI3/nQs+QhGtM2h/xWLpiPc
sha512-Gn0tSSjkIGAkaZQWjx3Ctl/0dVJuTmjW/f9QyB302kFjU4uTNP4HtA32U2qXs/TRlEsK5CoEqMEMs7LnzLOBsA==

 

<script src="/static/js/jquery.serialize-object.min.js" crossorigin="anonymous" integrity="sha256-E8KRdFk/LTaaCBoQIV/rFNc0s3ICQQiOHFT4Cioifa8=" />



script
src
/static/js/validator.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript
X-Content-Type-Options nosniff found


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


Cache-Control: no-store, must-revalidate, no-cache, max-age=0 - max-age too short.
Compression required: 11647 Bytes






local SRI possible, possible hash-values:

 

sha256-rhCiOU/Cwv/eI/pigP5onM4BVW4MFHG74v1maGlS2ck=
sha384-qFP0QR/Tc/Ym2ouMdLgAKuFCSv7VOJuubwIHZ9xXkh4rMNjLlbahGHEc8W3BeEcU
sha512-tYB946mXjrXFQVbrkHQZZXhZazZlXfhxW8Z37vv4EdHI4CNlSd/XY5UucwNa2f4mSNqDUTzoa24RCgdc2vvc9g==

 

<script src="/static/js/validator.js" crossorigin="anonymous" integrity="sha256-rhCiOU/Cwv/eI/pigP5onM4BVW4MFHG74v1maGlS2ck=" />



script
src
https://www.google.com/recaptcha/api.js
200

1
ok
defer attribute found async attribute found text/javascript; charset=utf-8
X-Content-Type-Options nosniff found





Cache-Control: max-age=300, private - max-age too short.
587 Bytes






Server-Header Access-Control-Allow-Origin: not found
Cross-Origin Resource Sharing (CORS) not supported


https://dns.constellix.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

img
src
/assets/images/layout/logo-2e05c0e8346a0305b263d0f3d370be4d.svg
200

1
ok
alt: Constelliximage/svg+xml; charset=UTF-8
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=31536000 with long duration found.
Wrong Compression (gzip): 2501/8880 Bytes






ETag: "images/layout/logo-2e05c0e8346a0305b263d0f3d370be4d.svg"



link
shortcut icon
/assets/images/favico-a397d972de8d553a5bd7b90595b3ad05.ico
200

1
Problems with Content-Type - Header - see details
image/x-icon; charset=UTF-8
missing X-Content-Type-Options nosniff


This combination of Media Type "image" and MediaSubType "x-icon" was never defined. Use "image/vnd.microsoft.icon" instead. See https://www.iana.org/assignments/media-types/media-types.xhtml


Cache-Control: public, max-age=31536000 with long duration found.
Wrong Compression (gzip): 1393/2457 Bytes






ETag: "images/favico-a397d972de8d553a5bd7b90595b3ad05.ico"



link
stylesheet
/assets/css/errors-dfebf56a1fa2f98eb287270461eed2e6.css
200

1
ok
text/css; charset=UTF-8
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=31536000 - with long duration found.
Compression (gzip): 504/1519 Bytes






ETag: "css/errors-dfebf56a1fa2f98eb287270461eed2e6.css"

local SRI possible, possible hash-values:

 

sha256-tuXCxDLsz9CpDEqi1gG12cAZletNm9D9xULn15Z1h2Q=
sha384-xgWutAQdVkSLCvyNWxYuqebG2DLE/bCefTawmhU0hw3YLL0eb8ofZIOYNEdabOP8
sha512-hOUjME74RTkMqdDzhKCuySVLfeboKJg8QfLZxu1dM4uk21qAUbVhf6YaXl9xSZIwxrFSBaux4eE9OxxwjEO5zA==

 

<link rel="stylesheet" href="/assets/css/errors-dfebf56a1fa2f98eb287270461eed2e6.css" crossorigin="anonymous" integrity="sha256-tuXCxDLsz9CpDEqi1gG12cAZletNm9D9xULn15Z1h2Q=" />



link
stylesheet
/assets/login-dbdf71fa05cf442deecfade1213f3b6b.css
200

1
ok
text/css; charset=UTF-8
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=31536000 - with long duration found.
Compression (gzip): 1285/3923 Bytes






ETag: "login-dbdf71fa05cf442deecfade1213f3b6b.css"

local SRI possible, possible hash-values:

 

sha256-7qpP6WmcTESkFT//Qkn/MHGiQDtOP8yD6hyzk8BX4RI=
sha384-dj+t3Ye0MEgXUcaDNf49QYjgZWtdE/jMHDFT/5DcRgCgLdTaNXuIqUs3xBTvk8P/
sha512-J72futyO2aqKENozYHIt52ZJ3qTmubskNMsJAw1fQ4bKHXmgF7Wvta7ll5sH3OujL7roz6ZyB01DbgnazzsG7g==

 

<link rel="stylesheet" href="/assets/login-dbdf71fa05cf442deecfade1213f3b6b.css" crossorigin="anonymous" integrity="sha256-7qpP6WmcTESkFT//Qkn/MHGiQDtOP8yD6hyzk8BX4RI=" />



meta
Content-Type
text/html; charset=utf-8


1
ok















meta
viewport
width=device-width, initial-scale=1.0


1
ok















script
src
/assets/login-d9c6cfeac88ae9167717b88d531fb47e.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript; charset=UTF-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


Cache-Control: public, max-age=31536000 - with long duration found.
Compression (gzip): 81285/273805 Bytes






ETag: "login-d9c6cfeac88ae9167717b88d531fb47e.js"

local SRI possible, possible hash-values:

 

sha256-goG5JyQmg+a9rOMwrp5yX4sWPSz9+HsC51qWwCYWUBo=
sha384-Jz4Jr5FVirXvrewji9dfur+wVK1OOo9PlNMMPSFPtbQ4+qSZOBkiwaDFB5Hvkk2R
sha512-h9e0MCm4D8GkfwhL2j4FeFunsrHeg7T5CvrYY1FiM+2aA35lZfeY67aU9AP0et408evmA3ud0lEc0uaGWr5WkQ==

 

<script src="/assets/login-d9c6cfeac88ae9167717b88d531fb47e.js" crossorigin="anonymous" integrity="sha256-goG5JyQmg+a9rOMwrp5yX4sWPSz9+HsC51qWwCYWUBo=" />


 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://auth.constellix.com/login

Summary

Good: No non-document-errors
3 errors
6 warnings

TypeMessagenum found
1.errorAttribute href not allowed on element button at this point.2
2.errorStray end tag b.1
3.warningThe type attribute is unnecessary for JavaScript resources.4
4.warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.2

Details


TypeMessage + Sample
1errorStray end tag b.

From line 130, column 105 to line 130, column 108

s"></span></b></p>
2errorAttribute href not allowed on element button at this point.

From line 136, column 61 to line 136, column 119

<button type="button" class="btn" href="#" id="backButton">
3errorAttribute href not allowed on element button at this point.

From line 143, column 61 to line 144, column 88

<button type="submit" class="btn" href="#" id="loginButton" disabled="disabled">Login
4warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.

From line 27, column 1 to line 27, column 18

- Nav --> <section id="nav"> <
5warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.

From line 178, column 1 to line 178, column 21

Footer--> <section id="footer"> <
6warningThe type attribute is unnecessary for JavaScript resources.

From line 203, column 1 to line 203, column 31

</script> <script type="text/javascript"> $
7warningThe type attribute is unnecessary for JavaScript resources.

From line 223, column 1 to line 223, column 31

</script> <script type="text/javascript"> $
8warningThe type attribute is unnecessary for JavaScript resources.

From line 228, column 1 to line 228, column 31

</script> <script type="text/javascript"> $
9warningThe type attribute is unnecessary for JavaScript resources.

From line 232, column 1 to line 232, column 31

/script> <script type="text/javascript"> l

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns11.constellix.com, ns21.constellix.com, ns31.constellix.com, ns41.constellix.net, ns51.constellix.net, ns61.constellix.net

 

QNr.DomainTypeNS used
1
com
NS
g.root-servers.net (2001:500:12::d0d)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
ns11.constellix.com: 2600:180a:1001::1, 96.45.80.1
NS
l.gtld-servers.net (2001:500:d937::30)

Answer: ns21.constellix.com
2600:180b:2001::1, 46.31.236.1

Answer: ns31.constellix.com
2600:180c:3001::1, 43.247.170.1
3
net
NS
b.root-servers.net (2001:500:200::b)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
4
ns41.constellix.net: 2600:180a:4001::1, 96.45.81.1
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns51.constellix.net
2600:180b:5001::1, 46.31.237.1

Answer: ns61.constellix.net
2600:180c:6001::1, 43.247.171.1

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
dns.constellix.com
0

no CAA entry found
1
0
constellix.com
0

no CAA entry found
1
0
com
0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
constellix.com
_9k3dnuzo6la4qcpgdjccx7yu3i4ytaf
ok
1
0
constellix.com
google-site-verification=372YOO2mwjm4oRWusl0KfhC1ME7gHNuT5UspKuJoy78
ok
1
0
constellix.com
google-site-verification=GrttWZY8MqvxV3JF5Mt98jsQlrB5iyjTZzya-XdG1qM
ok
1
0
constellix.com
v=spf1 ip4:208.80.120.33/32 ip4:208.80.120.29/32 ip4:208.94.144.0/22 include:_spf.google.com include:fdspfus.freshemail.io include:mail.zendesk.com -all
ok
1
0
constellix.com
ZOOM_verify_eVuQXitvTCq7nrB3sCHsBQ
ok
1
0
dns.constellix.com

ok
1
0
_acme-challenge.dns.constellix.com

Name Error - The domain name does not exist
1
0
_acme-challenge.dns.constellix.com.constellix.com

Name Error - The domain name does not exist
1
0
_acme-challenge.dns.constellix.com.dns.constellix.com

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

No DomainServiceEntries entries found

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
dns.constellix.com
208.80.120.50
443
27 Ciphers136.21 sec
16 without, 11 FS
40.74 %
Complete

1
27 Ciphers
27.00 Ciphers/Check
136.21 sec136.21 sec/Check
16 without, 11 FS
40.74 %

Details
DomainIPPortCipher (OpenSsl / IANA)
dns.constellix.com
208.80.120.50
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
27 Ciphers, 136.21 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x61
FS

TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384

ECDH
RSA
ARIAGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x60
FS

TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256

ECDH
RSA
ARIAGCM(128)
AEAD




ECDHE-RSA-CAMELLIA256-SHA384
(Weak)
TLSv1.2
0xC0,0x77
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384

ECDH
RSA
Camellia(256)
SHA384




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC0
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256

RSA
RSA
Camellia(256)
SHA256




ARIA256-GCM-SHA384
(Weak)
TLSv1.2
0xC0,0x51
No FS

TLS_RSA_WITH_ARIA_256_GCM_SHA384

RSA
RSA
ARIAGCM(256)
AEAD




AES256-GCM-SHA384
(Weak)
TLSv1.2
0x00,0x9D
No FS

TLS_RSA_WITH_AES_256_GCM_SHA384

RSA
RSA
AESGCM(256)
AEAD




AES256-SHA256
(Weak)
TLSv1.2
0x00,0x3D
No FS

TLS_RSA_WITH_AES_256_CBC_SHA256

RSA
RSA
AES(256)
SHA256




AES256-CCM8
(Weak)
TLSv1.2
0xC0,0xA1
No FS

TLS_RSA_WITH_AES_256_CCM_8

RSA
RSA
AESCCM8(256)
AEAD




AES256-CCM
(Weak)
TLSv1.2
0xC0,0x9D
No FS

TLS_RSA_WITH_AES_256_CCM

RSA
RSA
AESCCM(256)
AEAD




ECDHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0xC0,0x76
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

ECDH
RSA
Camellia(128)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBA
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256

RSA
RSA
Camellia(128)
SHA256




ARIA128-GCM-SHA256
(Weak)
TLSv1.2
0xC0,0x50
No FS

TLS_RSA_WITH_ARIA_128_GCM_SHA256

RSA
RSA
ARIAGCM(128)
AEAD




AES128-GCM-SHA256
(Weak)
TLSv1.2
0x00,0x9C
No FS

TLS_RSA_WITH_AES_128_GCM_SHA256

RSA
RSA
AESGCM(128)
AEAD




AES128-SHA256
(Weak)
TLSv1.2
0x00,0x3C
No FS

TLS_RSA_WITH_AES_128_CBC_SHA256

RSA
RSA
AES(128)
SHA256




AES128-CCM8
(Weak)
TLSv1.2
0xC0,0xA0
No FS

TLS_RSA_WITH_AES_128_CCM_8

RSA
RSA
AESCCM8(128)
AEAD




AES128-CCM
(Weak)
TLSv1.2
0xC0,0x9C
No FS

TLS_RSA_WITH_AES_128_CCM

RSA
RSA
AESCCM(128)
AEAD




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x84
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA

RSA
RSA
Camellia(256)
SHA1




AES256-SHA
(Weak)
SSLv3
0x00,0x35
No FS

TLS_RSA_WITH_AES_256_CBC_SHA

RSA
RSA
AES(256)
SHA1




CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x41
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA

RSA
RSA
Camellia(128)
SHA1




AES128-SHA
(Weak)
SSLv3
0x00,0x2F
No FS

TLS_RSA_WITH_AES_128_CBC_SHA

RSA
RSA
AES(128)
SHA1

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=46984824-836d-4cce-a74a-e8221b70c738

 

Last Result: https://check-your-website.server-daten.de/?q=dns.constellix.com - 2025-05-09 20:55:48

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=dns.constellix.com" target="_blank">Check this Site: dns.constellix.com</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=dns.constellix.com