Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

N

 

No trusted Certificate

 

Checked:
09.05.2025 15:45:26

 

Older results

No older results found

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
drfr.org
A
194.48.203.173
Dublin/Leinster/Ireland (IE) - Tilda Publishing Ltd.
No Hostname found
yes
2
0

AAAA

yes


www.drfr.org
CNAME
drfr.org
yes
1
0

A
194.48.203.173
Dublin/Leinster/Ireland (IE) - Tilda Publishing Ltd.
No Hostname found
yes


*.drfr.org
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 53148, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: org

org
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=






1 RRSIG RR to validate DS RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.05.2025, 05:00:00 +, Signature-Inception: 09.05.2025, 04:00:00 +, KeyTag 53148, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 53148 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 46023, Flags 256






Public Key with Algorithm 8, KeyTag 48111, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 22.05.2025, 15:22:42 +, Signature-Inception: 01.05.2025, 14:22:42 +, KeyTag 26974, Signer-Name: org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: drfr.org

drfr.org
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "5ebatq2dpdp8sh0em8d3lkc28despdsj" between the hashed NSEC3-owner "5eb81s9k10a1jr21p5d8peqpl4er3u54" and the hashed NextOwner "5ebctfkcleu5dfo6ppo9143fbi9qd45t". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 5eb81s9k10a1jr21p5d8peqpl4er3u54.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.05.2025, 13:12:01 +, Signature-Inception: 09.05.2025, 12:12:01 +, KeyTag 46023, Signer-Name: org






DS-Query in the parent zone sends valid NSEC3 RR with the Hash "gdtpongmpok61u9lvnipqor8lra9l4t0" as Owner. That's the Hash of "org" with the NextHashedOwnerName "gdtrea8kmj2rneqen4m2ogj26kfsukj7". So that domain name is the Closest Encloser of "drfr.org". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner gdtpongmpok61u9lvnipqor8lra9l4t0.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.05.2025, 13:44:58 +, Signature-Inception: 09.05.2025, 12:44:58 +, KeyTag 46023, Signer-Name: org






1 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 20722, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 20722 used to validate the DNSKEY RRSet






Error: DNSKEY 20722 signs DNSKEY RRset, but no confirming DS RR in the parent zone found. No chain of trust created.






RRSIG Type 1 validates the A - Result: 194.48.203.173
Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






CNAME-Query sends a valid NSEC RR as result with the query name "drfr.org" equal the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good. NoData-Proof required and found.






TXT-Query sends a valid NSEC RR as result with the query name "drfr.org" equal the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good. NoData-Proof required and found.






AAAA-Query sends a valid NSEC RR as result with the query name "drfr.org" equal the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.drfr.org) sends a valid NSEC RR as result with the owner name drfr.org. So that's the Closest Encloser of the query name. TLSA-Query sends a valid NSEC RR as result and covers the Wildcard expansion of the ClosestEncloser with the owner "drfr.org" and the NextOwner "www.drfr.org". So that NSEC confirms the not-existence of the Wildcard expansion. TLSA-Query (_443._tcp.drfr.org) sends a valid NSEC RR as result with the query name "_443._tcp.drfr.org" between the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that TLSA RR.TLSA-Query (_443._tcp.drfr.org) sends a valid NSEC RR as result with the parent Wildcard "*._tcp.drfr.org" between the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that Wildcard-expansion.
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good. NXDomain-Proof required and found.






CAA-Query sends a valid NSEC RR as result with the query name "drfr.org" equal the NSEC-owner "drfr.org" and the NextOwner "www.drfr.org". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner drfr.org., Algorithm: 13, 2 Labels, original TTL: 7200 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org






Status: Good. NoData-Proof required and found.



Zone: www.drfr.org

www.drfr.org
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "drfr.org" and the NextOwner "www.drfr.org". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, NS, SOA, RRSIG, NSEC, DNSKEY






RRSIG Type 5 validates the CNAME - Result: drfr.org
Validated: RRSIG-Owner www.drfr.org., Algorithm: 13, 3 Labels, original TTL: 900 sec, Signature-expiration: 22.05.2025, 00:00:00 +, Signature-Inception: 01.05.2025, 00:00:00 +, KeyTag 20722, Signer-Name: drfr.org

 

3. Name Servers

DomainNameserverNS-IP
drfr.org
  ns1.tildadns.com / 67m109
162.159.26.196
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1ac4
San Francisco/California/United States (US) - Cloudflare


  ns2.tildadns.com / 67m60
162.159.27.221
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:1bdd
San Francisco/California/United States (US) - Cloudflare

org
  a0.org.afilias-nst.info / app14.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  a2.org.afilias-nst.info / FRA5


  b0.org.afilias-nst.org / app10.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  b2.org.afilias-nst.org / FRA4


  c0.org.afilias-nst.info / app23.nrt1.hosts.meta.redstone.afilias-nst.info-1615580861


  d0.org.afilias-nst.org / app4.ams2.hosts.meta.redstone.afilias-nst.info-1615580861

 

4. SOA-Entries


Domain:org
Zone-Name:org
Primary:a0.org.afilias-nst.info
Mail:hostmaster.donuts.email
Serial:1746797948
Refresh:7200
Retry:900
Expire:1209600
TTL:3600
num Entries:6


Domain:drfr.org
Zone-Name:drfr.org
Primary:ns1.tildadns.com
Mail:ns.tilda.team
Serial:2025050904
Refresh:10800
Retry:7200
Expire:1209600
TTL:7200
num Entries:4


5. Screenshots

Startaddress: https://drfr.org/, address used: https://drfr.org/, Screenshot created 2025-05-09 15:49:01 +00:0 url is insecure, certificate invalid

 

Mobil (412px x 732px)

 

1114 milliseconds

 

Screenshot mobile - https://drfr.org/
Mobil + Landscape (732px x 412px)

 

1117 milliseconds

 

Screenshot mobile landscape - https://drfr.org/
Screen (1280px x 1680px)

 

1263 milliseconds

 

Screenshot Desktop - https://drfr.org/

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport396732
content Size3962468

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://drfr.org/
194.48.203.173 gzip used - 8277 / 34593 - 76.07 %
200

Html is minified: 178.32 %
0.120
H
Date: Fri, 09 May 2025 13:46:04 GMT
ETag: "8721-634b3d6fcc455-gzip"
X-Frame-Options: SAMEORIGIN
x-ws-id: 1
x-host: drfr.org
Accept-Ranges: bytes
x-tilda-server: 16
x-tilda-imprint: 179cf611-b15e-46a1-bbe3-79c58f16ddf6
Content-Type: text/html; charset=UTF-8
Content-Length: 8277
Last-Modified: Fri, 09 May 2025 13:21:10 GMT
Content-Encoding: gzip

• http://www.drfr.org/
194.48.203.173 gzip used - 8277 / 34593 - 76.07 %
200

Html is minified: 178.32 %
0.070
H
Date: Fri, 09 May 2025 13:46:04 GMT
ETag: "8721-634b3d7007d06-gzip"
X-Frame-Options: SAMEORIGIN
x-ws-id: 11
x-host: www.drfr.org
Accept-Ranges: bytes
x-tilda-server: 16
x-tilda-imprint: 4b3440d2-4cde-4367-961e-2b30a7e145b1
Content-Type: text/html; charset=UTF-8
Content-Length: 8277
Last-Modified: Fri, 09 May 2025 13:21:11 GMT
Content-Encoding: gzip

• https://drfr.org/
194.48.203.173 gzip used - 8277 / 34593 - 76.07 %
Inline-JavaScript (∑/total): 9/6146 Inline-CSS (∑/total): 21/8830
200

Html is minified: 178.32 %
Other inline scripts (∑/total): 0/0
2.963
N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Date: Fri, 09 May 2025 13:46:05 GMT
ETag: "8721-634b3d70161ed-gzip"
X-Frame-Options: SAMEORIGIN
x-ws-id: 9
x-host: drfr.org
Accept-Ranges: bytes
x-tilda-server: 22
x-tilda-imprint: b56db1d9-8dd5-4b45-80cf-a29e5388dcc9
Content-Type: text/html; charset=UTF-8
Content-Length: 8277
Last-Modified: Fri, 09 May 2025 13:21:11 GMT
Content-Encoding: gzip

• https://www.drfr.org/
194.48.203.173 gzip used - 8277 / 34593 - 76.07 %
Inline-JavaScript (∑/total): 9/6146 Inline-CSS (∑/total): 21/8830
200

Html is minified: 178.32 %
Other inline scripts (∑/total): 0/0
2.803
N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Date: Fri, 09 May 2025 13:46:10 GMT
ETag: "8721-634b3d6fd1283-gzip"
X-Frame-Options: SAMEORIGIN
x-ws-id: 13
x-host: www.drfr.org
Accept-Ranges: bytes
x-tilda-server: 7
x-tilda-imprint: ff6e4a0d-09b3-461a-b9b3-b97716f9295b
Content-Type: text/html; charset=UTF-8
Content-Length: 8277
Last-Modified: Fri, 09 May 2025 13:21:10 GMT
Content-Encoding: gzip

• http://drfr.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
194.48.203.173 gzip used - 107 / 146 - 26.71 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 110.61 %
Other inline scripts (∑/total): 0/0
0.154
A
Not Found
Visible Content:
Date: Fri, 09 May 2025 13:46:15 GMT
Transfer-Encoding: chunked
x-tilda-server: 5
x-tilda-imprint: 4fe6d11b-aa56-42f8-9ef1-ca4895e71af3
Content-Type: text/html
Content-Encoding: gzip
Content-Length: 107

• http://www.drfr.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
194.48.203.173 gzip used - 107 / 146 - 26.71 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 110.61 %
Other inline scripts (∑/total): 0/0
0.080
A
Not Found
Visible Content:
Date: Fri, 09 May 2025 13:46:16 GMT
Transfer-Encoding: chunked
x-tilda-server: 5
x-tilda-imprint: 84e941b6-cb4d-4fa1-975f-6fa53b1e9c98
Content-Type: text/html
Content-Encoding: gzip
Content-Length: 107

• https://194.48.203.173/
194.48.203.173
425

Html is minified: 100.00 %
2.447
N
Too Early
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Cache-Control: no-cache
Connection: close
Content-Type: text/plain
Content-Length: 5

 

7. Comments


1. General Results, most used to calculate the result

Aname "drfr.org" is domain, public suffix is ".org", top-level-domain is ".org", top-level-domain-type is "generic", tld-manager is "Public Interest Registry (PIR)", num .org-domains preloaded: 10122 (complete: 270180)
AGood: All ip addresses are public addresses
Warning: Only one ip address found: drfr.org has only one ip address.
Warning: Only one ip address found: www.drfr.org has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: drfr.org has no ipv6 address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: www.drfr.org has no ipv6 address.
AGood: No asked Authoritative Name Server had a timeout
AGood: No cookie sent via http.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):4 complete Content-Type - header (6 urls)
http://drfr.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 194.48.203.173


Url with incomplete Content-Type - header - missing charset
http://www.drfr.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 194.48.203.173


Url with incomplete Content-Type - header - missing charset
Bhttps://drfr.org/ 194.48.203.173
200

Missing HSTS-Header
Bhttps://www.drfr.org/ 194.48.203.173
200

Missing HSTS-Header
CError - no preferred version www or non-www. Select one version as preferred version, then add a redirect https + not-preferred version to https + preferred version. Perhaps in your port 443 vHost something like "RewriteEngine on" + "RewriteCond %{SERVER_NAME} = example.com" + "ReWriteRule ^ https://www.example.com%{REQUEST_URI} [END,QSA,R=permanent]" (three rows, without the "). That should create a redirect https + example.com ⇒ https + www.example.com. Or switch both values to use the non-www version as your preferred version.
CError - more then one version with Http-Status 200. After all redirects, all users (and search engines) should see the same https url: Non-www or www, but not both with http status 200.
HFatal error: http result with http-status 200, no encryption. Add a redirect http ⇒ https, so every connection is secure. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop.
Ihttps://drfr.org/ 194.48.203.173
200

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Ihttps://www.drfr.org/ 194.48.203.173
200

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Mhttps://194.48.203.173/ 194.48.203.173
425

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://drfr.org/ 194.48.203.173
200

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Nhttps://www.drfr.org/ 194.48.203.173
200

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Nhttps://194.48.203.173/ 194.48.203.173
425

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain drfr.org, 1 ip addresses, 1 different http results.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain www.drfr.org, 1 ip addresses, 1 different http results.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.drfr.org

2. Header-Checks

Adrfr.org 194.48.203.173
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
Awww.drfr.org 194.48.203.173
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
Fdrfr.org 194.48.203.173
Content-Security-Policy
Critical: Missing Header:
Fdrfr.org 194.48.203.173
X-Content-Type-Options
Critical: Missing Header:
Fdrfr.org 194.48.203.173
Referrer-Policy
Critical: Missing Header:
Fdrfr.org 194.48.203.173
Permissions-Policy
Critical: Missing Header:
Bdrfr.org 194.48.203.173
Cross-Origin-Embedder-Policy
Info: Missing Header
Bdrfr.org 194.48.203.173
Cross-Origin-Opener-Policy
Info: Missing Header
Bdrfr.org 194.48.203.173
Cross-Origin-Resource-Policy
Info: Missing Header
Fwww.drfr.org 194.48.203.173
Content-Security-Policy
Critical: Missing Header:
Fwww.drfr.org 194.48.203.173
X-Content-Type-Options
Critical: Missing Header:
Fwww.drfr.org 194.48.203.173
Referrer-Policy
Critical: Missing Header:
Fwww.drfr.org 194.48.203.173
Permissions-Policy
Critical: Missing Header:
Bwww.drfr.org 194.48.203.173
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.drfr.org 194.48.203.173
Cross-Origin-Opener-Policy
Info: Missing Header
Bwww.drfr.org 194.48.203.173
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 2 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 2 Name Servers.
AInfo:: 2 Queries complete, 2 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.ns1.tildadns.com (162.159.26.196, 2400:cb00:2049:1::a29f:1ac4), ns2.tildadns.com (162.159.27.221, 2400:cb00:2049:1::a29f:1bdd)
AGood (1 - 3.0):: An average of 1.0 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 2 different Name Servers found: ns1.tildadns.com, ns2.tildadns.com, 2 Name Servers included in Delegation: ns1.tildadns.com, ns2.tildadns.com, 2 Name Servers included in 1 Zone definitions: ns1.tildadns.com, ns2.tildadns.com, 1 Name Servers listed in SOA.Primary: ns1.tildadns.com.
AGood: Only one SOA.Primary Name Server found.: ns1.tildadns.com.
AGood: SOA.Primary Name Server included in the delegation set.: ns1.tildadns.com.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns1.tildadns.com, ns2.tildadns.com
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 2 different Name Servers found
AGood: All name servers have ipv4- and ipv6-addresses.: 2 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 2 Name Servers, 1 Top Level Domain: com
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: tildadns.com
AGood: Name servers with different Country locations found: 2 Name Servers, 2 Countries: CA, US
AInfo: Ipv4-Subnet-list: 2 Name Servers, 1 different subnets (first Byte): 162., 1 different subnets (first two Bytes): 162.159., 2 different subnets (first three Bytes): 162.159.26., 162.159.27.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 2 Name Servers with IPv6, 1 different subnets (first block): 2400:, 1 different subnets (first two blocks): 2400:cb00:, 1 different subnets (first three blocks): 2400:cb00:2049:, 1 different subnets (first four blocks): 2400:cb00:2049:0001:
Fatal: All Name Server IPv6 addresses from the same subnet.
AGood: Nameserver supports TCP connections: 4 good Nameserver
AGood: Nameserver supports Echo Capitalization: 4 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 4 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 6 good Nameserver
Nameserver doesn't pass all EDNS-Checks: ns1.tildadns.com / 162.159.26.196: OP100: ok. FLAGS: ok. V1: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. V1OP100: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. V1FLAGS: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. DNSSEC: ok. V1DNSSEC: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. NSID: ok (67m109). COOKIE: ok. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: ns1.tildadns.com / 2400:cb00:2049:1::a29f:1ac4: OP100: ok. FLAGS: ok. V1: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. V1OP100: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. V1FLAGS: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. DNSSEC: ok. V1DNSSEC: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. NSID: ok (67m109). COOKIE: ok. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: ns2.tildadns.com / 162.159.27.221: OP100: ok. FLAGS: ok. V1: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. V1OP100: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. V1FLAGS: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. DNSSEC: ok. V1DNSSEC: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. NSID: ok (67m60). COOKIE: ok. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: ns2.tildadns.com / 2400:cb00:2049:1::a29f:1bdd: OP100: ok. FLAGS: ok. V1: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. V1OP100: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. V1FLAGS: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. DNSSEC: ok. V1DNSSEC: SOA NOT expected and NOT found, BADVER expected, NOERR found, Version 0 expectend and found. NSID: ok (67m112). COOKIE: ok. CLIENTSUBNET: ok.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://drfr.org/ 194.48.203.173
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://www.drfr.org/ 194.48.203.173
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://drfr.org/ 194.48.203.173
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://www.drfr.org/ 194.48.203.173
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
AGood: Every https connection via port 443 supports the http/2 protocol via ALPN.
AGood: Some script Elements (type text/javascript) with a src-Attribute have a defer / async - Attribute. So loading and executing these JavaScripts doesn't block parsing and rendering the Html-Output.
https://drfr.org/ 194.48.203.173
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 1 script elements without defer/async.
https://www.drfr.org/ 194.48.203.173
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 1 script elements without defer/async.
AGood: All CSS / JavaScript files are sent compressed (gzip, deflate, br checked). That reduces the content of the files. 24 external CSS / JavaScript files found
AGood: All svg-Images greater 1024 Bytes without internal compression are compressed. Svg is an Xml-Application, so Compression reduces the size of the file. 2 images (type image/svg+xml, image/x-icon, image/vnd.microsoft.icon) found with compression.
AGood: All images with internal compression not compressed. Some Images (.png, .jpg, .jpeg, .webp, .gif) are already compressed, so an additional compression isn't helpful. 2 images (type image/png, image/jpg, image/jpeg, image/webp, image/gif) found without additional Compression. Not required because these images are already compressed
Warning: CSS / JavaScript files with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 24 external CSS / JavaScript files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 2 with Cache-Control max-age too short (minimum 7 days), 0 with Cache-Control long enough, 26 complete.
AGood: All images are sent with a long Cache-Control header (minimum 7 days). So the browser can reuse these files, no download is required. 4 image files with long Cache-Control max-age found
AGood: All checked attribute values are enclosed in quotation marks (" or ').
AGood: Some img-elements have a valid alt-attribute.: 4 img-elements found, 2 img-elements with correct alt-attributes (defined, not an empty value).
Wrong: img-elements without alt-attribute or empty alt-attribute found. The alt-attribute ("alternative") is required and should describe the img. So Screenreader and search engines are able to use these informations.: 0 img-elements without alt-attribute, 2 img-elements with empty alt-attribute found.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 222586 milliseconds, 222.586 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
drfr.org
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12
DiffieHellman
2048
Aes128
128
Sha256
not supported
ok
drfr.org
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12

DiffieHellman
2048
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Self signed certificate

1CN=root, OU=IT, O=ACME, L=D, C=EU, emailAddress=dummy@root.crt


www.drfr.org
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12
DiffieHellman
2048
Aes128
128
Sha256
not supported
ok

www.drfr.org
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12

DiffieHellman
2048
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Self signed certificate

1CN=root, OU=IT, O=ACME, L=D, C=EU, emailAddress=dummy@root.crt


194.48.203.173
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12
DiffieHellman
2048
Aes128
128
Sha256
not supported
ok

194.48.203.173
194.48.203.173
443
Certificate/chain invalid and wrong name
Tls12

DiffieHellman
2048
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Self signed certificate

1CN=root, OU=IT, O=ACME, L=D, C=EU, emailAddress=dummy@root.crt

 

9. Certificates

1.
1.
E=dummy@root.crt, CN=root, OU=IT, O=ACME, L=D, S=IE, C=EU
01.04.2022
31.03.2027
expires in 684 days

1.
1.
E=dummy@root.crt, CN=root, OU=IT, O=ACME, L=D, S=IE, C=EU
01.04.2022

31.03.2027
expires in 684 days




KeyalgorithmRSA encryption ( bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:6D608DBC320E376411A5BC80EFC3C79D2C8F1301
Thumbprint:3125F4F9114B69742BB3874F0D5B7B7F0869F0BB
SHA256 / Certificate:a0Pa8/y9xzItS3nRp+mhx5NKLmdBRWq6zSHPGG/1btQ=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):45dd477105910992f716bee94969f0b7acdc4660658ffc312b7a320e11a6ca70
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:


UntrustedRoot: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.


 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

No CertSpotter - CT-Log entries found

 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

No CRT - CT-Log entries found

 

11. Html-Content - Entries

Summary


Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://drfr.org/
194.48.203.173
a

11

0


0
0
0


img

2
86,052 Bytes
0
0
2
2
0
0
-2

link
dns-prefetch
2

0


0
0
0


link
stylesheet
4
8,252 Bytes
0
0
4
4
0
0
-4

link
other
3
292 Bytes
0
0
1
1
0
0
-1

meta
og
5
766 Bytes
1
0
1
1
0
0
-1

meta
other
8

0


0
0
0


script

9
89,293 Bytes
9
0
9
9
0
0
-9
https://www.drfr.org/
194.48.203.173
a

11

0


0
0
0


img

2
86,052 Bytes
0
0
2
2
0
0
-2

link
dns-prefetch
2

0


0
0
0


link
stylesheet
4
8,252 Bytes
0
0
4
4
0
0
-4

link
other
3
292 Bytes
0
0
1
1
0
0
-1

meta
og
5
766 Bytes
1
0
1
1
0
0
-1

meta
other
8

0


0
0
0


script

9
89,293 Bytes
9
0
9
9
0
0
-9

 

Details (currently limited to 500 rows - some problems with spam users)

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://drfr.org/
194.48.203.173
a

/


1
ok















a

/about


2
ok















a

/citizenship


1
ok















a

/faq


1
ok















a

/news


1
ok















a

/official_symbols


2
ok















a

/principles


2
ok















a

https://tilda.cc/


1
ok















img
src
https://static.tildacdn.net/img/tildacopy_black.png
200

1
ok
no alt-Attributeimage/png
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
No Compression - 816 Bytes






ETag: "517113fb58fc6628e68389d413d0e851"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-Bwn9Xqx6lAb/FvaB20+U64Ns4imxl34HC1yY0RNSMpE=
sha384-B4X5oOfoorPQ0fMcpEOWlFT3jZpC9iL7FgxhEPoex5z8XqVv17tv1X8Cp+FpYKna
sha512-SSi6AtpwObPTWvYg0LTOP/mmiyYzNGHxheV/JlCARf/XTY20tOZ8C+catEZXck9r8ceo7OVvnWEfxKU80R943Q==

 

<img src="https://static.tildacdn.net/img/tildacopy_black.png" crossorigin="anonymous" integrity="sha256-Bwn9Xqx6lAb/FvaB20+U64Ns4imxl34HC1yY0RNSMpE=" />



img
src
https://static.tildacdn.net/tild3764-3938-4430-b837-393232363537/Header-logo-vert.svg
200

1
ok
alt: Companyimage/svg+xml
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
Compression (gzip): 85236/199576 Bytes






ETag: W/"61578d36ee978a4c7829302a7471b365"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-zwWZwPDObfXcXL0fQn3KE7H36EoaPVdpUwSUHR6chr0=
sha384-V3i8aBln+9ZzCxg9Hl4UMfFsftNdDGk8lf6T4+0eZMRtWfdTm5ucCGGxLdsoyfiX
sha512-Nv4C/jLEsuV3tm6qB6ThBavX1tR2MA32Z5bGy6KrDLA7QtFrfXNe9RjctpyUlQh/IS9GgggMFR3x6XB1DEmMEw==

 

<img src="https://static.tildacdn.net/tild3764-3938-4430-b837-393232363537/Header-logo-vert.svg" crossorigin="anonymous" integrity="sha256-zwWZwPDObfXcXL0fQn3KE7H36EoaPVdpUwSUHR6chr0=" />



link
canonical
http://drfr.org


1
ok















link
dns-prefetch
https://static.tildacdn.net


1
ok















link
dns-prefetch
https://ws.tildacdn.com


1
ok















link
preconnect
https://fonts.gstatic.com


1
ok















link
shortcut icon
https://static.tildacdn.net/tild6632-3731-4564-b831-666162373733/favicon.svg
200

1
ok
image/svg+xml
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
292 Bytes






ETag: W/"63c8db7353fd739d3d3f3115a2a3cf0e"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-0tXq8mXpdXc9a8srzCNC14HkPVZxFnJVrLb17/XreXo=
sha384-03XX4FIWChMXpeFdA6Q3Wf5M2Rm8RvjL5hPNwQzy5onIFzTthGCTuPTJDkve5mZt
sha512-+rQ7hSsXEBf1n3bGgXPTY4C/Pv+h7Q5b7f6nMGxx421ysskaQBPtVPkZuAUYUfS2IoIUpoaVFTBAwv5zHUXS9g==

 

<link rel="shortcut icon" href="https://static.tildacdn.net/tild6632-3731-4564-b831-666162373733/favicon.svg" crossorigin="anonymous" integrity="sha256-0tXq8mXpdXc9a8srzCNC14HkPVZxFnJVrLb17/XreXo=" />



link
stylesheet
https://fonts.googleapis.com/css2?family=Roboto:wght@300;400;500;700&subset=latin,cyrillic
200

1
ok
text/css; charset=utf-8
X-Content-Type-Options nosniff found





Compression (gzip): 1742/21548 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-w/b7uvJB9Dhplj4EOG7+c2s/FaDnTPLOOdbKGGoZPhs=
sha384-yQsm9ZA0bGEbffrv5AQQusn1aNeCV1kqZEGUWsQ2iaRa3NtDMWFxC9lPxHgsiHWt
sha512-aJCmR6VwQHqoAyhWK+B5zJVaRLeDSDQFOCQs1w3EO2JfPr3JK+z96ZbQtAKPkZOCNXBELjdHSzTovRv/ntEatg==

 

<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Roboto:wght@300;400;500;700&subset=latin,cyrillic" crossorigin="anonymous" integrity="sha256-w/b7uvJB9Dhplj4EOG7+c2s/FaDnTPLOOdbKGGoZPhs=" />



link
stylesheet
https://static.tildacdn.net/css/tilda-cards-1.0.min.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
198 Bytes






ETag: W/"645d06e7-2f6"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-XR9qDF9Jz+rhR7Z1WZFTxRGKomkcyxwYk5+5A1Q2zIw=
sha384-TXd8K4jo862IV1DrF85wuf71EM6Wfq3uQi6H5HsPHfhsV1oa5F27EcPYxohhO0Pl
sha512-43GQ3RtQooNg5/fo2sPnWT3Xowzt6L+zThW52XTcC7ru0/m78ehwrjTRYzBTwSWj009cxmdd65/upbYVlfcOqQ==

 

<link rel="stylesheet" href="https://static.tildacdn.net/css/tilda-cards-1.0.min.css" crossorigin="anonymous" integrity="sha256-XR9qDF9Jz+rhR7Z1WZFTxRGKomkcyxwYk5+5A1Q2zIw=" />



link
stylesheet
https://static.tildacdn.net/css/tilda-grid-3.0.min.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
Compression (br): 857/4514 Bytes






ETag: W/"63f4be99-11a2"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-C19mTFKPRmYGyTGVl19nH8RsOpwQ/uVEJsLNHPibH+w=
sha384-8lzekcOmc2hprjghThcMg763ux7x/1PLMovjMLC2gdB2QxrR3PsLWv2VsqHzxoMu
sha512-OXnI5qz9/63BpVNK2bBScP3UNIQ0CXTgPZc+DHfRt7ckkqpl/W/SlsrPE1shi8B98PW1pYPwolu65nTVjzxstA==

 

<link rel="stylesheet" href="https://static.tildacdn.net/css/tilda-grid-3.0.min.css" crossorigin="anonymous" integrity="sha256-C19mTFKPRmYGyTGVl19nH8RsOpwQ/uVEJsLNHPibH+w=" />



link
stylesheet
https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.css?t=1746796870
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
Compression (br): 5455/25481 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-fNKkTseTjkeUgwaWrbj9NzVnkXKgKOZ/HIsNxr0xJS8=
sha384-Kd++AE1O1bbAAzn2zIvPJMhIAKW69z4G+jZetBKhOVoXqQywkDE5NYTdVMcSAXgk
sha512-vbfYILbdbYDTGt1ZGBu0cIWf5UFab8pjnjo2uteWgV4j9zluikXzLYjX0+DpwSbKspPNI5AW8AacNLSta9HRbg==

 

<link rel="stylesheet" href="https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.css?t=1746796870" crossorigin="anonymous" integrity="sha256-fNKkTseTjkeUgwaWrbj9NzVnkXKgKOZ/HIsNxr0xJS8=" />



meta
charset
utf-8


1
ok















meta

https://static.tildacdn.net/tild3031-6337-4664-b962-666363393131/noroot.png


1
ok















meta

https://static.tildacdn.net/tild3137-6533-4639-a236-306164373063/gal-item-constitutio.svg


1
ok















meta

https://static.tildacdn.net/tild6231-6232-4464-a661-373262323033/_2.svg


1
ok















meta
og:description



1
ok















meta
og:image
https://static.tildacdn.net/tild6366-6465-4361-a533-363466333762/photo.png
200

1
ok
image/png
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
No Compression - 766 Bytes






ETag: "8290cc6e77e58de47df64b3b91df4d25"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-SVKr98whEvKq67Q3ylRD10VJ5V2jXYqpsiHFrZuamvQ=
sha384-OQuiwvFSz4gJFF7kRukcJcrU6hSxm03Vah2rm0vM85Uk2U3QQBCok9rT2FSjSBi2
sha512-L98fWCwBe/DndXTe9VvzaV4kc4bITclDR0IFfj/3Gx/kSPBf+tPwtlWDXAhQIGzMngFPEPeUUZ4Dorw0IYjErQ==

 

<meta crossorigin="anonymous" integrity="sha256-SVKr98whEvKq67Q3ylRD10VJ5V2jXYqpsiHFrZuamvQ=" />



meta
og:title
ЦРФР - Главная


1
ok















meta
og:type
website


1
ok















meta
og:url
http://drfr.org


1
http-link, change to https















meta
Content-Type
text/html; charset=utf-8


1
ok















meta
x-dns-prefetch-control
on


1
ok















meta
format-detection
telephone=no


1
ok















meta
viewport
width=device-width, initial-scale=1.0


1
ok















script
src
https://neo.tildacdn.com/js/tilda-fallback-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (gzip): 836/1918 Bytes






ETag: W/"6811fecd-77e"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-zfZeJrkFplO85g3xgohrAytgaUA5G62x46ZV9DTKRGw=
sha384-2k9arg0zHARtspjqv49mVJzLGzerpAS3g6EZuquFCk8uYDYhgz/ROf8Oxaf4nChY
sha512-sokVm7TNgzFs6Kmp4OU6hFBlRUrIR+VPzd7L2yAe6EwKRiPFKIaA5HLlxHu071hSs5nfQ3hqHnRfQWXZmmsGRA==

 

<script src="https://neo.tildacdn.com/js/tilda-fallback-1.0.min.js" crossorigin="anonymous" integrity="sha256-zfZeJrkFplO85g3xgohrAytgaUA5G62x46ZV9DTKRGw=" />



script
src
https://static.tildacdn.net/js/tilda-cards-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 560/2163 Bytes






ETag: W/"66e03673-873"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-b6MHZfrYv+otOVr31CGEHYm+DAcj/ViTt0rtvW7dvj8=
sha384-KqYeqLCOozahzlB1vWZ/rSyk+XJ+6GYXai3gXPd0Tz4g/5L/2g7NPGRVYScGI0rr
sha512-44gCMktR26crtF5ohkXZTikMN0R4FteJEF/L/Uvu7tyMe6IfWLISm5ei+aTSH37ddbfU6yF42y9WcVCSOcoqww==

 

<script src="https://static.tildacdn.net/js/tilda-cards-1.0.min.js" crossorigin="anonymous" integrity="sha256-b6MHZfrYv+otOVr31CGEHYm+DAcj/ViTt0rtvW7dvj8=" />



script
src
https://static.tildacdn.net/js/tilda-events-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 3439/13408 Bytes






ETag: W/"67b32cec-3460"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-Zp+MuMI68/xqfZwy5eTsGWX4EDoTEvP9T6mB6gmZrTE=
sha384-BwJg1wIS04ldqtjUr6fQxgXd1TAztW/iNeqJPnV9dlELQ15gaDX9h4SNiHs9CxnA
sha512-PwTr0ij3Ca4uKVDmouzgMw9sjY1jXf8H7NPT25wicnH0OTpOY1V/Vb4AtZP8ZJKFNTKedqVSs5fzyRd8N9oghA==

 

<script src="https://static.tildacdn.net/js/tilda-events-1.0.min.js" crossorigin="anonymous" integrity="sha256-Zp+MuMI68/xqfZwy5eTsGWX4EDoTEvP9T6mB6gmZrTE=" />



script
src
https://static.tildacdn.net/js/tilda-lazyload-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 6684/19869 Bytes






ETag: W/"68186fcf-4d9d"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-bO+UcB0w0WHml8OrDo7u9hCLiLfDKxoQwD2LzwKppB4=
sha384-LGfocmAkvjxNhFlAbr6mP8Lg6MMwtSZ1ATYn8QC8WHP1b8fUivYuH1gS41igjwR/
sha512-K4gNY+XDyWGcsQgBZjvWhXUuA8MuCIDooejRmlfXFIpSQsjrSmEFd+afB13GUDJrECzs1pCFZPqs8lNMo4mK6Q==

 

<script src="https://static.tildacdn.net/js/tilda-lazyload-1.0.min.js" crossorigin="anonymous" integrity="sha256-bO+UcB0w0WHml8OrDo7u9hCLiLfDKxoQwD2LzwKppB4=" />



script
src
https://static.tildacdn.net/js/tilda-menu-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 3174/11155 Bytes






ETag: W/"67a34cd2-2b93"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-ZgaShuU/7eZ9Jj4QrsnBsHpMFD+Uz2UquIrnK3LEtPY=
sha384-9M+8Kd5aHh8KT4ycnohmjV7tSDHQehqk8ClD0G6aQoKrld86i35BEX+Eb9vi7znK
sha512-C3dLnSrd/OZyCKxWSou5UhWfmHCPF6tKWAnip19OQ514b8sOLsDjgf1Zz1bNjTJK3k3GO62Nd50tqhAgafqa4A==

 

<script src="https://static.tildacdn.net/js/tilda-menu-1.0.min.js" crossorigin="anonymous" integrity="sha256-ZgaShuU/7eZ9Jj4QrsnBsHpMFD+Uz2UquIrnK3LEtPY=" />



script
src
https://static.tildacdn.net/js/tilda-polyfill-1.0.min.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 66941/185608 Bytes






ETag: W/"67bdb45e-2d508"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-JcdXloeQH4qhN7g0KDvZlz64Ep2LSWr+8PxvCU3CfN4=
sha384-1moA9coGnmo/zs0YEy87AHbKZ5pKCGNzJOozJDXFXea50WP8GT5inB5HCYCJz/iL
sha512-wyRgbrrxpLeuAjBbYyQaQKGvZJ/jW8yg21EYMhqBAHWLMhJW0G0kn/k70d0BG6GrlEEP6hgzMDqTTxwkojuqRg==

 

<script src="https://static.tildacdn.net/js/tilda-polyfill-1.0.min.js" crossorigin="anonymous" integrity="sha256-JcdXloeQH4qhN7g0KDvZlz64Ep2LSWr+8PxvCU3CfN4=" />



script
src
https://static.tildacdn.net/js/tilda-scripts-3.0.min.js
200

1
Problems with Content-Type - Header - see details
defer attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 6017/22267 Bytes






ETag: W/"67f90c76-56fb"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-927HAAIVENIVc+SSgjYL7ZK+oJWHpDOzWTAaMRxKP1M=
sha384-dOb0R3Sm6jhW5vXUSkZS1Ffg4PHqYcLnXQrNXalfkvsulbmZDc2H5dLQAvDCGL8a
sha512-PJlp6da3wjP5B694v7HY942p+D1iHYDdnW8pLc5hWGbrUvxurqYxmm8GC+QeQVFO8OKzpnqRK0bhivbqIYdOIA==

 

<script src="https://static.tildacdn.net/js/tilda-scripts-3.0.min.js" crossorigin="anonymous" integrity="sha256-927HAAIVENIVc+SSgjYL7ZK+oJWHpDOzWTAaMRxKP1M=" />



script
src
https://static.tildacdn.net/js/tilda-skiplink-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 758/1879 Bytes






ETag: W/"6530dc3b-757"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-4wvijYX421VmB4Ap2EPSJ2h/1zzP1nV9N7abL8Br9I0=
sha384-dojKBSw+2X5PiL1Wp31PCzRXHeMLY/Fn7K248GixtkxfefQSaN9NRGAcBVIzlqO1
sha512-9x4yx4/iRLMmQAEvGLVLjNwZ89Q0AtvYFNEFEz09DtIp7D7FcJfO6W/Lh/wkjqtOyeBUwJfkUYbykdjjVS2JeQ==

 

<script src="https://static.tildacdn.net/js/tilda-skiplink-1.0.min.js" crossorigin="anonymous" integrity="sha256-4wvijYX421VmB4Ap2EPSJ2h/1zzP1nV9N7abL8Br9I0=" />



script
src
https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.js?t=1746796870
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 884/2890 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-udAoSwxn7rvpSHIzsRU8crt4PPCly/hPnGbIyKrJox0=
sha384-S9FJq382cuv2GPVFAPpEfTwPIplr2oKetcH/Hcp6b3zH47Yv0QPWvDGUAllzRnSV
sha512-baJf6jU3/VVszJmRbqBO3yvmyD83zXTWKROtnGvtIEwH3bWA+rsNsOVbzQZem0RnHQSCl+DkPrhjVi2OSWs+4w==

 

<script src="https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.js?t=1746796870" crossorigin="anonymous" integrity="sha256-udAoSwxn7rvpSHIzsRU8crt4PPCly/hPnGbIyKrJox0=" />


https://www.drfr.org/
194.48.203.173
a

/


1
ok















a

/about


2
ok















a

/citizenship


1
ok















a

/faq


1
ok















a

/news


1
ok















a

/official_symbols


2
ok















a

/principles


2
ok















a

https://tilda.cc/


1
ok















img
src
https://static.tildacdn.net/img/tildacopy_black.png
200

1
ok
no alt-Attributeimage/png
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
No Compression - 816 Bytes






ETag: "517113fb58fc6628e68389d413d0e851"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-Bwn9Xqx6lAb/FvaB20+U64Ns4imxl34HC1yY0RNSMpE=
sha384-B4X5oOfoorPQ0fMcpEOWlFT3jZpC9iL7FgxhEPoex5z8XqVv17tv1X8Cp+FpYKna
sha512-SSi6AtpwObPTWvYg0LTOP/mmiyYzNGHxheV/JlCARf/XTY20tOZ8C+catEZXck9r8ceo7OVvnWEfxKU80R943Q==

 

<img src="https://static.tildacdn.net/img/tildacopy_black.png" crossorigin="anonymous" integrity="sha256-Bwn9Xqx6lAb/FvaB20+U64Ns4imxl34HC1yY0RNSMpE=" />



img
src
https://static.tildacdn.net/tild3764-3938-4430-b837-393232363537/Header-logo-vert.svg
200

1
ok
alt: Companyimage/svg+xml
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
Compression (gzip): 85236/199576 Bytes






ETag: W/"61578d36ee978a4c7829302a7471b365"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-zwWZwPDObfXcXL0fQn3KE7H36EoaPVdpUwSUHR6chr0=
sha384-V3i8aBln+9ZzCxg9Hl4UMfFsftNdDGk8lf6T4+0eZMRtWfdTm5ucCGGxLdsoyfiX
sha512-Nv4C/jLEsuV3tm6qB6ThBavX1tR2MA32Z5bGy6KrDLA7QtFrfXNe9RjctpyUlQh/IS9GgggMFR3x6XB1DEmMEw==

 

<img src="https://static.tildacdn.net/tild3764-3938-4430-b837-393232363537/Header-logo-vert.svg" crossorigin="anonymous" integrity="sha256-zwWZwPDObfXcXL0fQn3KE7H36EoaPVdpUwSUHR6chr0=" />



link
canonical
http://drfr.org


1
ok















link
dns-prefetch
https://static.tildacdn.net


1
ok















link
dns-prefetch
https://ws.tildacdn.com


1
ok















link
preconnect
https://fonts.gstatic.com


1
ok















link
shortcut icon
https://static.tildacdn.net/tild6632-3731-4564-b831-666162373733/favicon.svg
200

1
ok
image/svg+xml
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
292 Bytes






ETag: W/"63c8db7353fd739d3d3f3115a2a3cf0e"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-0tXq8mXpdXc9a8srzCNC14HkPVZxFnJVrLb17/XreXo=
sha384-03XX4FIWChMXpeFdA6Q3Wf5M2Rm8RvjL5hPNwQzy5onIFzTthGCTuPTJDkve5mZt
sha512-+rQ7hSsXEBf1n3bGgXPTY4C/Pv+h7Q5b7f6nMGxx421ysskaQBPtVPkZuAUYUfS2IoIUpoaVFTBAwv5zHUXS9g==

 

<link rel="shortcut icon" href="https://static.tildacdn.net/tild6632-3731-4564-b831-666162373733/favicon.svg" crossorigin="anonymous" integrity="sha256-0tXq8mXpdXc9a8srzCNC14HkPVZxFnJVrLb17/XreXo=" />



link
stylesheet
https://fonts.googleapis.com/css2?family=Roboto:wght@300;400;500;700&subset=latin,cyrillic
200

1
ok
text/css; charset=utf-8
X-Content-Type-Options nosniff found





Compression (gzip): 1742/21548 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-w/b7uvJB9Dhplj4EOG7+c2s/FaDnTPLOOdbKGGoZPhs=
sha384-yQsm9ZA0bGEbffrv5AQQusn1aNeCV1kqZEGUWsQ2iaRa3NtDMWFxC9lPxHgsiHWt
sha512-aJCmR6VwQHqoAyhWK+B5zJVaRLeDSDQFOCQs1w3EO2JfPr3JK+z96ZbQtAKPkZOCNXBELjdHSzTovRv/ntEatg==

 

<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Roboto:wght@300;400;500;700&subset=latin,cyrillic" crossorigin="anonymous" integrity="sha256-w/b7uvJB9Dhplj4EOG7+c2s/FaDnTPLOOdbKGGoZPhs=" />



link
stylesheet
https://static.tildacdn.net/css/tilda-cards-1.0.min.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
198 Bytes






ETag: W/"645d06e7-2f6"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-XR9qDF9Jz+rhR7Z1WZFTxRGKomkcyxwYk5+5A1Q2zIw=
sha384-TXd8K4jo862IV1DrF85wuf71EM6Wfq3uQi6H5HsPHfhsV1oa5F27EcPYxohhO0Pl
sha512-43GQ3RtQooNg5/fo2sPnWT3Xowzt6L+zThW52XTcC7ru0/m78ehwrjTRYzBTwSWj009cxmdd65/upbYVlfcOqQ==

 

<link rel="stylesheet" href="https://static.tildacdn.net/css/tilda-cards-1.0.min.css" crossorigin="anonymous" integrity="sha256-XR9qDF9Jz+rhR7Z1WZFTxRGKomkcyxwYk5+5A1Q2zIw=" />



link
stylesheet
https://static.tildacdn.net/css/tilda-grid-3.0.min.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
Compression (br): 857/4514 Bytes






ETag: W/"63f4be99-11a2"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-C19mTFKPRmYGyTGVl19nH8RsOpwQ/uVEJsLNHPibH+w=
sha384-8lzekcOmc2hprjghThcMg763ux7x/1PLMovjMLC2gdB2QxrR3PsLWv2VsqHzxoMu
sha512-OXnI5qz9/63BpVNK2bBScP3UNIQ0CXTgPZc+DHfRt7ckkqpl/W/SlsrPE1shi8B98PW1pYPwolu65nTVjzxstA==

 

<link rel="stylesheet" href="https://static.tildacdn.net/css/tilda-grid-3.0.min.css" crossorigin="anonymous" integrity="sha256-C19mTFKPRmYGyTGVl19nH8RsOpwQ/uVEJsLNHPibH+w=" />



link
stylesheet
https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.css?t=1746796870
200

1
ok
text/css
missing X-Content-Type-Options nosniff





No Cache-Control - header
Compression (br): 5455/25481 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-fNKkTseTjkeUgwaWrbj9NzVnkXKgKOZ/HIsNxr0xJS8=
sha384-Kd++AE1O1bbAAzn2zIvPJMhIAKW69z4G+jZetBKhOVoXqQywkDE5NYTdVMcSAXgk
sha512-vbfYILbdbYDTGt1ZGBu0cIWf5UFab8pjnjo2uteWgV4j9zluikXzLYjX0+DpwSbKspPNI5AW8AacNLSta9HRbg==

 

<link rel="stylesheet" href="https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.css?t=1746796870" crossorigin="anonymous" integrity="sha256-fNKkTseTjkeUgwaWrbj9NzVnkXKgKOZ/HIsNxr0xJS8=" />



meta
charset
utf-8


1
ok















meta

https://static.tildacdn.net/tild3031-6337-4664-b962-666363393131/noroot.png


1
ok















meta

https://static.tildacdn.net/tild3137-6533-4639-a236-306164373063/gal-item-constitutio.svg


1
ok















meta

https://static.tildacdn.net/tild6231-6232-4464-a661-373262323033/_2.svg


1
ok















meta
og:description



1
ok















meta
og:image
https://static.tildacdn.net/tild6366-6465-4361-a533-363466333762/photo.png
200

1
ok
image/png
missing X-Content-Type-Options nosniff





Cache-Control: max-age=5184000 with long duration found.
No Compression - 766 Bytes






ETag: "8290cc6e77e58de47df64b3b91df4d25"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-SVKr98whEvKq67Q3ylRD10VJ5V2jXYqpsiHFrZuamvQ=
sha384-OQuiwvFSz4gJFF7kRukcJcrU6hSxm03Vah2rm0vM85Uk2U3QQBCok9rT2FSjSBi2
sha512-L98fWCwBe/DndXTe9VvzaV4kc4bITclDR0IFfj/3Gx/kSPBf+tPwtlWDXAhQIGzMngFPEPeUUZ4Dorw0IYjErQ==

 

<meta crossorigin="anonymous" integrity="sha256-SVKr98whEvKq67Q3ylRD10VJ5V2jXYqpsiHFrZuamvQ=" />



meta
og:title
ЦРФР - Главная


1
ok















meta
og:type
website


1
ok















meta
og:url
http://drfr.org


1
http-link, change to https















meta
Content-Type
text/html; charset=utf-8


1
ok















meta
x-dns-prefetch-control
on


1
ok















meta
format-detection
telephone=no


1
ok















meta
viewport
width=device-width, initial-scale=1.0


1
ok















script
src
https://neo.tildacdn.com/js/tilda-fallback-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (gzip): 836/1918 Bytes






ETag: W/"6811fecd-77e"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-zfZeJrkFplO85g3xgohrAytgaUA5G62x46ZV9DTKRGw=
sha384-2k9arg0zHARtspjqv49mVJzLGzerpAS3g6EZuquFCk8uYDYhgz/ROf8Oxaf4nChY
sha512-sokVm7TNgzFs6Kmp4OU6hFBlRUrIR+VPzd7L2yAe6EwKRiPFKIaA5HLlxHu071hSs5nfQ3hqHnRfQWXZmmsGRA==

 

<script src="https://neo.tildacdn.com/js/tilda-fallback-1.0.min.js" crossorigin="anonymous" integrity="sha256-zfZeJrkFplO85g3xgohrAytgaUA5G62x46ZV9DTKRGw=" />



script
src
https://static.tildacdn.net/js/tilda-cards-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 560/2163 Bytes






ETag: W/"66e03673-873"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-b6MHZfrYv+otOVr31CGEHYm+DAcj/ViTt0rtvW7dvj8=
sha384-KqYeqLCOozahzlB1vWZ/rSyk+XJ+6GYXai3gXPd0Tz4g/5L/2g7NPGRVYScGI0rr
sha512-44gCMktR26crtF5ohkXZTikMN0R4FteJEF/L/Uvu7tyMe6IfWLISm5ei+aTSH37ddbfU6yF42y9WcVCSOcoqww==

 

<script src="https://static.tildacdn.net/js/tilda-cards-1.0.min.js" crossorigin="anonymous" integrity="sha256-b6MHZfrYv+otOVr31CGEHYm+DAcj/ViTt0rtvW7dvj8=" />



script
src
https://static.tildacdn.net/js/tilda-events-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 3439/13408 Bytes






ETag: W/"67b32cec-3460"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-Zp+MuMI68/xqfZwy5eTsGWX4EDoTEvP9T6mB6gmZrTE=
sha384-BwJg1wIS04ldqtjUr6fQxgXd1TAztW/iNeqJPnV9dlELQ15gaDX9h4SNiHs9CxnA
sha512-PwTr0ij3Ca4uKVDmouzgMw9sjY1jXf8H7NPT25wicnH0OTpOY1V/Vb4AtZP8ZJKFNTKedqVSs5fzyRd8N9oghA==

 

<script src="https://static.tildacdn.net/js/tilda-events-1.0.min.js" crossorigin="anonymous" integrity="sha256-Zp+MuMI68/xqfZwy5eTsGWX4EDoTEvP9T6mB6gmZrTE=" />



script
src
https://static.tildacdn.net/js/tilda-lazyload-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 6684/19869 Bytes






ETag: W/"68186fcf-4d9d"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-bO+UcB0w0WHml8OrDo7u9hCLiLfDKxoQwD2LzwKppB4=
sha384-LGfocmAkvjxNhFlAbr6mP8Lg6MMwtSZ1ATYn8QC8WHP1b8fUivYuH1gS41igjwR/
sha512-K4gNY+XDyWGcsQgBZjvWhXUuA8MuCIDooejRmlfXFIpSQsjrSmEFd+afB13GUDJrECzs1pCFZPqs8lNMo4mK6Q==

 

<script src="https://static.tildacdn.net/js/tilda-lazyload-1.0.min.js" crossorigin="anonymous" integrity="sha256-bO+UcB0w0WHml8OrDo7u9hCLiLfDKxoQwD2LzwKppB4=" />



script
src
https://static.tildacdn.net/js/tilda-menu-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 3174/11155 Bytes






ETag: W/"67a34cd2-2b93"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-ZgaShuU/7eZ9Jj4QrsnBsHpMFD+Uz2UquIrnK3LEtPY=
sha384-9M+8Kd5aHh8KT4ycnohmjV7tSDHQehqk8ClD0G6aQoKrld86i35BEX+Eb9vi7znK
sha512-C3dLnSrd/OZyCKxWSou5UhWfmHCPF6tKWAnip19OQ514b8sOLsDjgf1Zz1bNjTJK3k3GO62Nd50tqhAgafqa4A==

 

<script src="https://static.tildacdn.net/js/tilda-menu-1.0.min.js" crossorigin="anonymous" integrity="sha256-ZgaShuU/7eZ9Jj4QrsnBsHpMFD+Uz2UquIrnK3LEtPY=" />



script
src
https://static.tildacdn.net/js/tilda-polyfill-1.0.min.js
200

1
Problems with Content-Type - Header - see details
Missing defer / async attribute. application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 66941/185608 Bytes






ETag: W/"67bdb45e-2d508"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-JcdXloeQH4qhN7g0KDvZlz64Ep2LSWr+8PxvCU3CfN4=
sha384-1moA9coGnmo/zs0YEy87AHbKZ5pKCGNzJOozJDXFXea50WP8GT5inB5HCYCJz/iL
sha512-wyRgbrrxpLeuAjBbYyQaQKGvZJ/jW8yg21EYMhqBAHWLMhJW0G0kn/k70d0BG6GrlEEP6hgzMDqTTxwkojuqRg==

 

<script src="https://static.tildacdn.net/js/tilda-polyfill-1.0.min.js" crossorigin="anonymous" integrity="sha256-JcdXloeQH4qhN7g0KDvZlz64Ep2LSWr+8PxvCU3CfN4=" />



script
src
https://static.tildacdn.net/js/tilda-scripts-3.0.min.js
200

1
Problems with Content-Type - Header - see details
defer attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 6017/22267 Bytes






ETag: W/"67f90c76-56fb"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-927HAAIVENIVc+SSgjYL7ZK+oJWHpDOzWTAaMRxKP1M=
sha384-dOb0R3Sm6jhW5vXUSkZS1Ffg4PHqYcLnXQrNXalfkvsulbmZDc2H5dLQAvDCGL8a
sha512-PJlp6da3wjP5B694v7HY942p+D1iHYDdnW8pLc5hWGbrUvxurqYxmm8GC+QeQVFO8OKzpnqRK0bhivbqIYdOIA==

 

<script src="https://static.tildacdn.net/js/tilda-scripts-3.0.min.js" crossorigin="anonymous" integrity="sha256-927HAAIVENIVc+SSgjYL7ZK+oJWHpDOzWTAaMRxKP1M=" />



script
src
https://static.tildacdn.net/js/tilda-skiplink-1.0.min.js
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 758/1879 Bytes






ETag: W/"6530dc3b-757"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-4wvijYX421VmB4Ap2EPSJ2h/1zzP1nV9N7abL8Br9I0=
sha384-dojKBSw+2X5PiL1Wp31PCzRXHeMLY/Fn7K248GixtkxfefQSaN9NRGAcBVIzlqO1
sha512-9x4yx4/iRLMmQAEvGLVLjNwZ89Q0AtvYFNEFEz09DtIp7D7FcJfO6W/Lh/wkjqtOyeBUwJfkUYbykdjjVS2JeQ==

 

<script src="https://static.tildacdn.net/js/tilda-skiplink-1.0.min.js" crossorigin="anonymous" integrity="sha256-4wvijYX421VmB4Ap2EPSJ2h/1zzP1nV9N7abL8Br9I0=" />



script
src
https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.js?t=1746796870
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript; charset=utf-8
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (br): 884/2890 Bytes






Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-udAoSwxn7rvpSHIzsRU8crt4PPCly/hPnGbIyKrJox0=
sha384-S9FJq382cuv2GPVFAPpEfTwPIplr2oKetcH/Hcp6b3zH47Yv0QPWvDGUAllzRnSV
sha512-baJf6jU3/VVszJmRbqBO3yvmyD83zXTWKROtnGvtIEwH3bWA+rsNsOVbzQZem0RnHQSCl+DkPrhjVi2OSWs+4w==

 

<script src="https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.js?t=1746796870" crossorigin="anonymous" integrity="sha256-udAoSwxn7rvpSHIzsRU8crt4PPCly/hPnGbIyKrJox0=" />


 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://drfr.org/

Summary

Good: No non-document-errors
47 errors
15 warnings

TypeMessagenum found
1.errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)20
2.errorAttribute field not allowed on element div at this point.17
3.errorCSS: too few values for the property width4
4.errorAttribute imgfield not allowed on element div at this point.3
5.errorA document must not include both a meta element with an http-equiv attribute whose value is content-type, and a meta element with a charset attribute.1
6.errorBad value x-dns-prefetch-control for attribute http-equiv on element meta.1
7.errorAttribute imgfield not allowed on element img at this point.1
8.warningThe charset attribute on the script element is obsolete.9
9.warningThe type attribute is unnecessary for JavaScript resources.4
10.warningThis document appears to be written in Russian. Consider adding lang="ru" (or variant) to the html start tag.1
11.warningThe list role is unnecessary for element ul.1

Details


TypeMessage + Sample
1errorA document must not include both a meta element with an http-equiv attribute whose value is content-type, and a meta element with a charset attribute.

From line 1, column 56 to line 1, column 124

utf-8" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta
2errorBad value x-dns-prefetch-control for attribute http-equiv on element meta.

From line 1, column 687 to line 1, column 741

ne=no" /> <meta http-equiv="x-dns-prefetch-control" content="on"> <link
3errorAttribute field not allowed on element div at this point.

From line 3, column 1052 to line 3, column 1123

ntainer"> <div class="tmenu-mobile__text t-name t-name_md" field="menu_mob_title"><div s
4errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 8, column 114 to line 8, column 120

</script> <style>.t-men
5errorCSS: too few values for the property width

From line 8, column 1768 to line 8, column 1768

,(min-width:0\0){.t-menuburger
6errorCSS: too few values for the property width

From line 8, column 2228 to line 8, column 2228

,(min-width:0\0){.t-menuburger
7errorCSS: too few values for the property width

From line 8, column 2846 to line 8, column 2846

,(min-width:0\0){.t-menuburger
8errorCSS: too few values for the property width

From line 8, column 3911 to line 8, column 3911

,(min-width:0\0){.t-menuburger
9errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 8, column 4864 to line 8, column 4870

v> </div> <style>.tmenu
10errorAttribute imgfield not allowed on element img at this point.

From line 8, column 6504 to line 12, column 14

href="/"> <img class="t454__imglogo t454__imglogomobile" src="https://static.tildacdn.net/tild3764-3938-4430-b837-393232363537/Header-logo-vert.svg" imgfield="img" style="max-width: 125px; width: 125px;" alt="Company"> </a>
11errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 752 to line 24, column 758

v> </div> <style>@media
12errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 1597 to line 24, column 1603

</script> <style>#rec99
13errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 2257 to line 24, column 2263

}</style> <style> #rec9
14errorAttribute field not allowed on element div at this point.

From line 24, column 2639 to line 24, column 2696

refix_1"> <div class="t015__title t-title t-title_lg" field="title">Добро
15errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 2766 to line 24, column 2772

v> </div> <style> #rec1
16errorAttribute field not allowed on element div at this point.

From line 24, column 3320 to line 24, column 3394

-col_12"> <div class="t059__text-impact t-text-impact t-text-impact_xs" field="text"><em>Ци
17errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 3535 to line 24, column 3541

v> </div> <style>#rec10
18errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 3600 to line 24, column 3606

}</style> <style> #rec1
19errorAttribute field not allowed on element div at this point.

From line 24, column 4007 to line 24, column 4067

t:-5px;"> <div field="text" class="t673__text t-heading t-heading_md "><stron
20errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 4633 to line 24, column 4639

v> </div> <style> #rec1
21errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 24, column 4740 to line 24, column 4746

}</style> <style> #rec1
22errorAttribute field not allowed on element div at this point.

From line 24, column 5155 to line 26, column 15

col_12 "> <div class="t-section__title t-title t-title_xs t-align_left " field="btitle"> Позна
23errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 28, column 22 to line 28, column 28

v> </div> <style>.t-sec
24errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 28, column 252 to line 28, column 258

}</style> <style> #rec9
25errorAttribute imgfield not allowed on element div at this point.

From line 28, column 1700 to line 30, column 124

tio.svg"> <div class="t688__img t-bgimg" data-original="https://static.tildacdn.net/tild3137-6533-4639-a236-306164373063/gal-item-constitutio.svg" imgfield="li_img__1494594985229" style="background-image: url('https://static.tildacdn.net/tild3137-6533-4639-a236-306164373063/gal-item-constitutio.svg');"> </div
26errorAttribute field not allowed on element div at this point.

From line 30, column 659 to line 30, column 734

688__sp"> <div class="t-card__title t-name t-name_xl" field="li_title__1494594985229"> <a hr
27errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 36, column 13 to line 36, column 19

a> </div> <style> #rec9
28errorAttribute imgfield not allowed on element div at this point.

From line 36, column 412 to line 38, column 106

/_2.svg"> <div class="t688__img t-bgimg" data-original="https://static.tildacdn.net/tild6231-6232-4464-a661-373262323033/_2.svg" imgfield="li_img__1494594986850" style="background-image: url('https://static.tildacdn.net/tild6231-6232-4464-a661-373262323033/_2.svg');"> </div
29errorAttribute field not allowed on element div at this point.

From line 38, column 641 to line 38, column 716

688__sp"> <div class="t-card__title t-name t-name_xl" field="li_title__1494594986850"> <a hr
30errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 44, column 13 to line 44, column 19

a> </div> <style> #rec9
31errorAttribute imgfield not allowed on element div at this point.

From line 44, column 416 to line 46, column 121

oot.png"> <div class="t688__img t-bgimg" data-original="https://static.tildacdn.net/tild3031-6337-4664-b962-666363393131/noroot.png" imgfield="li_img__1494594987926" style="background-image: url('https://thb.tildacdn.net/tild3031-6337-4664-b962-666363393131/-/resizeb/20x/noroot.png');"> </div
32errorAttribute field not allowed on element div at this point.

From line 46, column 656 to line 46, column 731

688__sp"> <div class="t-card__title t-name t-name_xl" field="li_title__1494594987926"> <a hr
33errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 52, column 13 to line 52, column 19

a> </div> <style> #rec9
34errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 52, column 729 to line 52, column 735

</script> <style>#rec99
35errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 52, column 827 to line 52, column 833

}</style> <style> #rec9
36errorAttribute field not allowed on element div at this point.

From line 52, column 1167 to line 54, column 15

col_12 "> <div class="t-section__title t-title t-title_xs t-align_left " field="btitle"> Что д
37errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 56, column 22 to line 56, column 28

v> </div> <style>.t-sec
38errorAttribute field not allowed on element div at this point.

From line 58, column 42 to line 58, column 116

gn_left"> <div class="t1106__title t-name t-name_md" field="li_title__9939946997060">Обозна
39errorAttribute field not allowed on element div at this point.

From line 58, column 139 to line 58, column 212

ебя</div> <div class="t1106__text t-text t-text_xs" field="li_descr__9939946997060">ЦРФР —
40errorAttribute field not allowed on element div at this point.

From line 60, column 42 to line 60, column 116

gn_left"> <div class="t1106__title t-name t-name_md" field="li_title__9949946997062">Собрат
41errorAttribute field not allowed on element div at this point.

From line 60, column 142 to line 60, column 215

ивы</div> <div class="t1106__text t-text t-text_xs" field="li_descr__9949946997062">Многие
42errorAttribute field not allowed on element div at this point.

From line 62, column 42 to line 62, column 116

gn_left"> <div class="t1106__title t-name t-name_md" field="li_title__3949946997061">Налади
43errorAttribute field not allowed on element div at this point.

From line 62, column 138 to line 62, column 211

язь</div> <div class="t1106__text t-text t-text_xs" field="li_descr__3949946997061">Без по
44errorAttribute field not allowed on element div at this point.

From line 64, column 42 to line 64, column 116

gn_left"> <div class="t1106__title t-name t-name_md" field="li_title__8949946997063">Укрепл
45errorAttribute field not allowed on element div at this point.

From line 64, column 145 to line 64, column 218

тие</div> <div class="t1106__text t-text t-text_xs" field="li_descr__8949946997063">Мы гот
46errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 64, column 399 to line 64, column 405

v> </div> <style>#rec10
47errorElement style not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 64, column 1548 to line 64, column 1554

v> </div> <style>#rec99
48warningThis document appears to be written in Russian. Consider adding lang="ru" (or variant) to the html start tag.

From line 1, column 16 to line 1, column 22

TYPE html> <html> <head
49warningThe charset attribute on the script element is obsolete.

From line 1, column 1010 to line 1, column 1099

ssets --> <script src="https://neo.tildacdn.com/js/tilda-fallback-1.0.min.js" async charset="utf-8"></scri
50warningThe charset attribute on the script element is obsolete.

From line 1, column 1760 to line 1, column 1855

='y';" /> <script nomodule src="https://static.tildacdn.net/js/tilda-polyfill-1.0.min.js" charset="utf-8"></scri
51warningThe type attribute is unnecessary for JavaScript resources.

From line 1, column 1866 to line 1, column 1896

</script> <script type="text/javascript">functi
52warningThe charset attribute on the script element is obsolete.

From line 2, column 286 to line 2, column 405

</script> <script src="https://static.tildacdn.net/js/tilda-scripts-3.0.min.js" charset="utf-8" defer onerror="this.loaderr='y';"></scri
53warningThe charset attribute on the script element is obsolete.

From line 2, column 416 to line 2, column 572

</script> <script src="https://static.tildacdn.net/ws/project13082721/tilda-blocks-page67793383.min.js?t=1746796870" charset="utf-8" async onerror="this.loaderr='y';"></scri
54warningThe charset attribute on the script element is obsolete.

From line 2, column 583 to line 2, column 703

</script> <script src="https://static.tildacdn.net/js/tilda-lazyload-1.0.min.js" charset="utf-8" async onerror="this.loaderr='y';"></scri
55warningThe charset attribute on the script element is obsolete.

From line 2, column 714 to line 2, column 831

</script> <script src="https://static.tildacdn.net/js/tilda-cards-1.0.min.js" charset="utf-8" async onerror="this.loaderr='y';"></scri
56warningThe charset attribute on the script element is obsolete.

From line 2, column 842 to line 2, column 958

</script> <script src="https://static.tildacdn.net/js/tilda-menu-1.0.min.js" charset="utf-8" async onerror="this.loaderr='y';"></scri
57warningThe charset attribute on the script element is obsolete.

From line 2, column 969 to line 2, column 1089

</script> <script src="https://static.tildacdn.net/js/tilda-skiplink-1.0.min.js" charset="utf-8" async onerror="this.loaderr='y';"></scri
58warningThe charset attribute on the script element is obsolete.

From line 2, column 1100 to line 2, column 1218

</script> <script src="https://static.tildacdn.net/js/tilda-events-1.0.min.js" charset="utf-8" async onerror="this.loaderr='y';"></scri
59warningThe type attribute is unnecessary for JavaScript resources.

From line 2, column 1229 to line 2, column 1259

</script> <script type="text/javascript">window
60warningThe type attribute is unnecessary for JavaScript resources.

From line 2, column 1308 to line 2, column 1338

</script> <script type="text/javascript">(funct
61warningThe list role is unnecessary for element ul.

From line 12, column 161 to line 12, column 208

wrapper"> <ul role="list" class="t454__list t-menu__list"> <li c
62warningThe type attribute is unnecessary for JavaScript resources.

From line 66, column 1022 to line 66, column 1052

Stat --> <script type="text/javascript">if(!wi

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.tildadns.com, ns2.tildadns.com

 

QNr.DomainTypeNS used
1
com
NS
g.root-servers.net (2001:500:12::d0d)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
ns1.tildadns.com: 162.159.26.196, 2400:cb00:2049:1::a29f:1ac4
NS
l.gtld-servers.net (2001:500:d937::30)

Answer: ns2.tildadns.com
162.159.27.221, 2400:cb00:2049:1::a29f:1bdd

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.drfr.org



1
0
drfr.org
0

no CAA entry found
1
0
org
0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
drfr.org

ok
1
0
www.drfr.org


1
0
_acme-challenge.drfr.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.drfr.org

Name Error - The domain name does not exist
1
0
_acme-challenge.drfr.org.drfr.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.drfr.org.drfr.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.drfr.org.www.drfr.org

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

No DomainServiceEntries entries found

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
drfr.org
194.48.203.173
443
12 Ciphers62.18 sec
0 without, 12 FS
100.00 %
www.drfr.org
194.48.203.173
443
12 Ciphers62.47 sec
0 without, 12 FS
100.00 %
Complete

2
24 Ciphers
12.00 Ciphers/Check
124.65 sec62.32 sec/Check
0 without, 24 FS
100.00 %

Details
DomainIPPortCipher (OpenSsl / IANA)
drfr.org
194.48.203.173
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
12 Ciphers, 62.18 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




DHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0x00,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

DH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




DHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0x00,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

DH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




DHE-RSA-AES256-SHA256
(Weak)
TLSv1.2
0x00,0x6B
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

DH
RSA
AES(256)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




DHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0x00,0x67
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

DH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




DHE-RSA-AES256-SHA
(Weak)
SSLv3
0x00,0x39
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

DH
RSA
AES(256)
SHA1




DHE-RSA-AES128-SHA
(Weak)
SSLv3
0x00,0x33
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

DH
RSA
AES(128)
SHA1

www.drfr.org
194.48.203.173
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
12 Ciphers, 62.47 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




DHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0x00,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

DH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




DHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0x00,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

DH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




DHE-RSA-AES256-SHA256
(Weak)
TLSv1.2
0x00,0x6B
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

DH
RSA
AES(256)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




DHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0x00,0x67
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

DH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




DHE-RSA-AES256-SHA
(Weak)
SSLv3
0x00,0x39
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

DH
RSA
AES(256)
SHA1




DHE-RSA-AES128-SHA
(Weak)
SSLv3
0x00,0x33
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

DH
RSA
AES(128)
SHA1

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=451004f4-0f11-455f-944a-6fbff0e40a9d

 

Last Result: https://check-your-website.server-daten.de/?q=drfr.org - 2025-05-09 15:45:26

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=drfr.org" target="_blank">Check this Site: drfr.org</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=drfr.org