Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

B

 

Missing HSTS or Cookie-warnings

 

Checked:
03.09.2025 08:24:41

 

Older results

 

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
gmx.com
A
82.165.229.87
Karlsruhe/Baden-Wurttemberg/Germany (DE) - IONOS SE
Hostname: redir-bs.web.de
yes
1
0

AAAA

yes


www.gmx.com
A
82.165.229.61
Karlsruhe/Baden-Wurttemberg/Germany (DE) - IONOS SE
Hostname: www.gmx.co.uk
yes
1
0

AAAA

yes


*.gmx.com
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


mta-sts.gmx.com
A
213.165.67.101
No Hostname found
yes



A
213.165.67.126
No Hostname found
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






4 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 46441, Flags 256






Public Key with Algorithm 8, KeyTag 53148, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 20.09.2025, 00:00:00 +, Signature-Inception: 30.08.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: com

com
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=






1 RRSIG RR to validate DS RR found






RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 16.09.2025, 05:00:00 +, Signature-Inception: 03.09.2025, 04:00:00 +, KeyTag 46441, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46441 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 19718, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 20545, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner com., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 14.09.2025, 14:02:35 +, Signature-Inception: 30.08.2025, 13:57:35 +, KeyTag 19718, Signer-Name: com






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 19718 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest "isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: gmx.com

gmx.com
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 32227, DigestType 2 and Digest 32vC2b868ZE7ottSybQLoDk1UhwBcXbeITy6TPjsfz0=






1 RRSIG RR to validate DS RR found






RRSIG-Owner gmx.com., Algorithm: 13, 2 Labels, original TTL: 86400 sec, Signature-expiration: 08.09.2025, 00:55:13 +, Signature-Inception: 31.08.2025, 23:45:13 +, KeyTag 20545, Signer-Name: com






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 20545 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20, Flags 256






Public Key with Algorithm 8, KeyTag 32227, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner gmx.com., Algorithm: 8, 2 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 32227, Signer-Name: gmx.com






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 32227 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 32227, DigestType 2 and Digest "32vC2b868ZE7ottSybQLoDk1UhwBcXbeITy6TPjsfz0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone






RRSIG Type 1 validates the A - Result: 82.165.229.87
Validated: RRSIG-Owner gmx.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






RRSIG Type 16 validates the TXT - Result: tpverification20190725 v=spf1 redirect=_spf.gmx.net cs2wypdfpjcvt13xc979nk7wbfyk732l facebook-domain-verification=rrwl4taoaitv2jrqmz719qv6f18jgo google-site-verification=H6aQ8xjy09XYRfh1DU6TEBFVxHITg-zIukkE7IIXP2g google-site-verification=YxvYPeuavgDRQDYTX-3dSD3JNMsDn5yO7loiNot-h0Q google-site-verification=hYUs91S-7d-Pk3wP56GUGUfwMQ22WpxcDT6QC_oAwX0
Validated: RRSIG-Owner gmx.com., Algorithm: 8, 2 Labels, original TTL: 300 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






RRSIG Type 257 validates the CAA - Result: 5|issueDigicert.com 5|issuesectigo.com 5|issuetelesec.de 9|issuewilddigicert.com 9|issuewildsectigo.com 9|issuewildtelesec.de
Validated: RRSIG-Owner gmx.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "t10dgjhs0a7ntm9bh638ae8n1r7nb54h" equal the hashed NSEC3-owner "t10dgjhs0a7ntm9bh638ae8n1r7nb54h" and the hashed NextOwner "t404bcik92gg2plg7l8apbhn30om1inl". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner t10dgjhs0a7ntm9bh638ae8n1r7nb54h.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.






AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "t10dgjhs0a7ntm9bh638ae8n1r7nb54h" equal the hashed NSEC3-owner "t10dgjhs0a7ntm9bh638ae8n1r7nb54h" and the hashed NextOwner "t404bcik92gg2plg7l8apbhn30om1inl". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner t10dgjhs0a7ntm9bh638ae8n1r7nb54h.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.gmx.com) sends a valid NSEC3 RR as result with the hashed owner name "95nedfca5e4u25af21krdtiackfnaod6" (unhashed: _tcp.gmx.com). So that's the Closest Encloser of the query name.
Bitmap: No Bitmap? Validated: RRSIG-Owner 95nedfca5e4u25af21krdtiackfnaod6.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.






TLSA-Query (_443._tcp.gmx.com) sends a valid NSEC3 RR as result with the hashed query name "8invnjg35ujjllq9aq6omcugrhn2fhp1" between the hashed NSEC3-owner "8ff5441ldhe974b9rl3ogrfff7b6s5fr" and the hashed NextOwner "8o326lmo0are9uqlg11u3v9om6fletdp". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner 8ff5441ldhe974b9rl3ogrfff7b6s5fr.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "omb8eb1b2bg51n48sc2lrk44fql8cgfi" (unhashed: *._tcp.gmx.com) with the owner "oka4smjhpqtbt34o3e90v8u2qsket35v" and the NextOwner "ongmobi0j41m0oikn17e4hmv0j7bljmn". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: A, RRSIG Validated: RRSIG-Owner oka4smjhpqtbt34o3e90v8u2qsket35v.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.



Zone: www.gmx.com

www.gmx.com
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" between the hashed NSEC3-owner "nihfdk9nc2spkjm1457l1ge7l97fdfuh" and the hashed NextOwner "njbfdk5ekp4quaapeh4h5jk8ohmg6a88". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






RRSIG Type 1 validates the A - Result: 82.165.229.61
Validated: RRSIG-Owner www.gmx.com., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" equal the hashed NSEC3-owner "nihfdk9nc2spkjm1457l1ge7l97fdfuh" and the hashed NextOwner "njbfdk5ekp4quaapeh4h5jk8ohmg6a88". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.






TXT-Query sends a valid NSEC3 RR as result with the hashed query name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" equal the hashed NSEC3-owner "nihfdk9nc2spkjm1457l1ge7l97fdfuh" and the hashed NextOwner "njbfdk5ekp4quaapeh4h5jk8ohmg6a88". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.






AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" equal the hashed NSEC3-owner "nihfdk9nc2spkjm1457l1ge7l97fdfuh" and the hashed NextOwner "njbfdk5ekp4quaapeh4h5jk8ohmg6a88". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.www.gmx.com) sends a valid NSEC3 RR as result with the hashed owner name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" (unhashed: www.gmx.com). So that's the Closest Encloser of the query name.
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "tb31bse6k3lh2eqm9oml969t1tn39c3o" (unhashed: _tcp.www.gmx.com) with the owner "t9igv72qe6bu1tfen9g3k79g93sb14g4" and the NextOwner "tbp998jcvgcikupnt5slc8a3p4p0ko1o". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: A, RRSIG Validated: RRSIG-Owner t9igv72qe6bu1tfen9g3k79g93sb14g4.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "vam49sduroviv1dlac9jjnj8rhbqhaoc" (unhashed: *.www.gmx.com) with the owner "v6sob91r4l222u8je2ljabuacm1tqnvs" and the NextOwner "vbl80pqr718v3me29qnpt1gbct17ld5u". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: A, RRSIG Validated: RRSIG-Owner v6sob91r4l222u8je2ljabuacm1tqnvs.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NXDomain-Proof required and found.






CAA-Query sends a valid NSEC3 RR as result with the hashed query name "nihfdk9nc2spkjm1457l1ge7l97fdfuh" equal the hashed NSEC3-owner "nihfdk9nc2spkjm1457l1ge7l97fdfuh" and the hashed NextOwner "njbfdk5ekp4quaapeh4h5jk8ohmg6a88". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner nihfdk9nc2spkjm1457l1ge7l97fdfuh.gmx.com., Algorithm: 8, 3 Labels, original TTL: 600 sec, Signature-expiration: 13.09.2025, 06:53:36 +, Signature-Inception: 30.08.2025, 06:53:36 +, KeyTag 20, Signer-Name: gmx.com






Status: Good. NoData-Proof required and found.

 

3. Name Servers

DomainNameserverNS-IP
www.gmx.com
  dns.gmx.net

gmx.com
  dns.gmx.net


  ns-gmx.ui-dns.biz
185.132.33.199
Frankfurt am Main/Hesse/Germany (DE) - DNSAS (eBGP DNS)


 
217.160.81.199
Frankfurt am Main/Hesse/Germany (DE) - IONOS SE


 
2001:8d8:fe:53:0:d9a0:51c7:100
Frankfurt am Main/Hesse/Germany (DE) - 1&1 IONOS SE


 
2607:f1c0:fe:53:185:132:33:199
Kansas City/Missouri/United States (US) - Fasthosts Internet Limited


  ns-gmx.ui-dns.com
185.132.34.199
Frankfurt am Main/Hesse/Germany (DE) - DNSAS (eBGP DNS)


 
217.160.82.199
Frankfurt am Main/Hesse/Germany (DE) - IONOS SE


 
2001:8d8:fe:53:0:d9a0:52c7:100
Frankfurt am Main/Hesse/Germany (DE) - 1&1 IONOS SE


 
2607:f1c0:fe:53:185:132:34:199
Kansas City/Missouri/United States (US) - Fasthosts Internet Limited


  ns-gmx.ui-dns.de
185.132.32.199
Frankfurt am Main/Hesse/Germany (DE) - DNSAS (eBGP DNS)


 
217.160.80.199
Frankfurt am Main/Hesse/Germany (DE) - IONOS SE


 
2001:8d8:fe:53:0:d9a0:50c7:100
Frankfurt am Main/Hesse/Germany (DE) - 1&1 IONOS SE


 
2607:f1c0:fe:53:185:132:32:199
Kansas City/Missouri/United States (US) - Fasthosts Internet Limited


  ns-gmx.ui-dns.org
185.132.35.199
Frankfurt am Main/Hesse/Germany (DE) - DNSAS (eBGP DNS)


 
217.160.83.199
Frankfurt am Main/Hesse/Germany (DE) - IONOS SE


 
2001:8d8:fe:53:0:d9a0:53c7:100
Frankfurt am Main/Hesse/Germany (DE) - 1&1 IONOS SE


 
2607:f1c0:fe:53:185:132:35:199
Kansas City/Missouri/United States (US) - Fasthosts Internet Limited

com
  a.gtld-servers.net


  b.gtld-servers.net


  c.gtld-servers.net


  d.gtld-servers.net


  e.gtld-servers.net


  f.gtld-servers.net


  g.gtld-servers.net


  h.gtld-servers.net


  i.gtld-servers.net


  j.gtld-servers.net


  k.gtld-servers.net


  l.gtld-servers.net


  m.gtld-servers.net

 

4. SOA-Entries


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1756880650
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:5


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1756880665
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:8


Domain:gmx.com
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:gmx.com
Zone-Name:gmx.com
Primary:dns.gmx.net
Mail:hostmaster.gmx.net
Serial:2013074601
Refresh:28800
Retry:7200
Expire:604800
TTL:600
num Entries:16


Domain:www.gmx.com
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


5. Screenshots

Startaddress: https://www.gmx.com/, address used: https://www.gmx.com/, Screenshot created 2025-09-03 08:27:45 +00:0

 

Mobil (412px x 732px)

 

1128 milliseconds

 

Screenshot mobile - https://www.gmx.com/
Mobil + Landscape (732px x 412px)

 

1138 milliseconds

 

Screenshot mobile landscape - https://www.gmx.com/
Screen (1280px x 1680px)

 

1324 milliseconds

 

Screenshot Desktop - https://www.gmx.com/

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport397732
content Size3978265

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://gmx.com/
82.165.229.87
301
https://gmx.com/
Html is minified: 103.23 %
0.034
A
Date: Wed, 03 Sep 2025 06:25:30 GMT
Server: Apache
Location: https://gmx.com/
Connection: close
Content-Length: 224
Content-Type: text/html; charset=iso-8859-1

• http://www.gmx.com/
82.165.229.61
301
https://www.gmx.com/

0.030
A
Location: https://www.gmx.com/
Server: BigIP
Connection: Keep-Alive
Content-Length: 0

• https://gmx.com/
82.165.229.87
301
https://www.gmx.com/
Html is minified: 103.17 %
2.073
A
Date: Wed, 03 Sep 2025 06:25:30 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Location: https://www.gmx.com/
Connection: close
Content-Length: 228
Content-Type: text/html; charset=iso-8859-1

• https://www.gmx.com/
82.165.229.61 gzip used - 46787 / 237128 - 80.27 %
200

Html is minified: 405.65 %
2.300
B
Date: Wed, 03 Sep 2025 06:25:33 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Vary: X-Forwarded-Proto,Accept-Encoding
Cache-Control: no-store, must-revalidate, no-cache
Pragma: no-cache
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Content-Security-Policy: block-all-mixed-content;frame-ancestors *.mail.com
X-Frame-Options: DENY
Set-Cookie: JSESSIONID=83AD2979E54E39864D275D24424D6A4E; Path=/gmxcom-webapp; HttpOnly
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Language: en-US
Content-Encoding: gzip
Content-Length: 46787
Content-Type: text/html; charset=UTF-8

• https://mta-sts.gmx.com/.well-known/mta-sts.txt
213.165.67.101 gzip used - 83 / 79 - -5.06 %
200



B
0 None CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rhineland-Palatinate, C=DE
Date: Wed, 03 Sep 2025 06:26:14 GMT
Server: Apache
ETag: "4f-6152c8cc9399e-gzip"
Accept-Ranges: bytes
Vary: Accept-Encoding
Connection: close
Last-Modified: Wed, 03 Apr 2024 07:55:45 GMT
Content-Encoding: gzip
Content-Length: 83
Content-Type: text/plain

• https://mta-sts.gmx.com/.well-known/mta-sts.txt
213.165.67.126 gzip used - 83 / 79 - -5.06 %
200



B
0 None CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rhineland-Palatinate, C=DE
Date: Wed, 03 Sep 2025 06:26:09 GMT
Server: Apache
ETag: "4f-62588d8bb1100-gzip"
Accept-Ranges: bytes
Vary: Accept-Encoding
Connection: close
Last-Modified: Mon, 28 Oct 2024 12:45:42 GMT
Content-Encoding: gzip
Content-Length: 83
Content-Type: text/plain

• http://gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
82.165.229.87
301
https://gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 102.45 %
0.033
A
Visible Content:
Date: Wed, 03 Sep 2025 06:25:37 GMT
Server: Apache
Location: https://gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Connection: close
Content-Length: 293
Content-Type: text/html; charset=iso-8859-1

• http://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
82.165.229.61
301
https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

0.017
A
Visible Content:
Location: https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Server: BigIP
Connection: Keep-Alive
Content-Length: 0

• https://gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

301
https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 102.41 %
2.037
A
Visible Content:
Date: Wed, 03 Sep 2025 06:25:45 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Location: https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Connection: close
Content-Length: 297
Content-Type: text/html; charset=iso-8859-1

• https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
gzip used - 40606 / 194217 - 79.09 %
404

Html is minified: 1060.66 %
2.230
B
Visible Content:
Date: Wed, 03 Sep 2025 06:25:48 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Cache-Control: no-store, must-revalidate, no-cache
Pragma: no-cache
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Content-Security-Policy: block-all-mixed-content;frame-ancestors *.mail.com
X-Frame-Options: DENY
Vary: accept-encoding
Set-Cookie: JSESSIONID=63D742FED3CCCA9942EBA17571BA551A; Path=/gmxcom-webapp; HttpOnly
Transfer-Encoding: chunked
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Encoding: gzip
Content-Type: text/html; charset=UTF-8
Content-Language: en-US
Content-Length: 40606

• https://82.165.229.87/
82.165.229.87
301
https://web.de/
Html is minified: 103.24 %
2.237
N
Certificate error: RemoteCertificateNameMismatch
Date: Wed, 03 Sep 2025 06:25:37 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Location: https://web.de/
Connection: close
Content-Length: 223
Content-Type: text/html; charset=iso-8859-1

• https://82.165.229.61/
82.165.229.61
404

Html is minified: 103.70 %
2.066
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Date: Wed, 03 Sep 2025 06:25:41 GMT
Server: Apache
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1

• https://web.de/
gzip used - 67611 / 365442 - 81.50 %
200

Html is minified: 147.13 %
3.580
B
Date: Wed, 03 Sep 2025 06:25:52 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Cache-Control: no-store, must-revalidate, no-cache
Content-Security-Policy: frame-ancestors 'self' www.united-internet-media.de adimg.uimserv.net advideo.uimserv.net
Feature-Policy: microphone 'none'; camera 'none'; geolocation 'none'; usb 'none'
Permissions-Policy: microphone 'none'; camera 'none'; geolocation 'none'; usb 'none'
Pragma: no-cache
Referrer-Policy: strict-origin-when-cross-origin
Vary: accept-encoding
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 0
Set-Cookie: euconsent-bypass=1756880752; Max-Age=120; Expires=Wed, 03 Sep 2025 06:27:52 GMT; Domain=web.de; Path=/; Secure,allin_segment=; Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:10 GMT; Domain=web.de; Path=/; Secure; SameSite=Lax,ui_cid=OPTOUT; Max-Age=31536000; Expires=Thu, 03 Sep 2026 06:25:52 GMT; Path=/; Secure; HttpOnly,SSLB=.0; domain=.web.de ;path=/
Transfer-Encoding: chunked
Content-Encoding: gzip
Content-Type: text/html; charset=UTF-8
Expires: 0
Content-Length: 67611

 

7. Comments


1. General Results, most used to calculate the result

Aname "gmx.com" is domain, public suffix is ".com", top-level-domain is ".com", top-level-domain-type is "generic", tld-manager is "VeriSign Global Registry Services", num .com-domains preloaded: 108094 (complete: 276475)
AGood: All ip addresses are public addresses
Warning: Only one ip address found: gmx.com has only one ip address.
Warning: Only one ip address found: www.gmx.com has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: gmx.com has no ipv6 address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: www.gmx.com has no ipv6 address.
AGood: No asked Authoritative Name Server had a timeout
Ahttps://82.165.229.87/ 82.165.229.87
301
https://web.de/
Correct redirect https to https
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: www is preferred
AGood: No cookie sent via http.
AGood: HSTS has preload directive
AExcellent: Domain is in the Google-Preload-List
AExcellent: Domain is in the Mozilla/Firefox-Preload-List
AHSTS-Preload-Status: Preloaded. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):4 complete Content-Type - header (6 urls)
https://mta-sts.gmx.com/.well-known/mta-sts.txt 213.165.67.101


Url with incomplete Content-Type - header - missing charset
https://mta-sts.gmx.com/.well-known/mta-sts.txt 213.165.67.126


Url with incomplete Content-Type - header - missing charset
Ahttp://gmx.com/ 82.165.229.87
301
https://gmx.com/
Correct redirect http - https with the same domain name
Ahttp://www.gmx.com/ 82.165.229.61
301
https://www.gmx.com/
Correct redirect http - https with the same domain name
Bhttps://www.gmx.com/ 82.165.229.61
200
JSESSIONID=83AD2979E54E39864D275D24424D6A4E; Path=/gmxcom-webapp; HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
JSESSIONID=63D742FED3CCCA9942EBA17571BA551A; Path=/gmxcom-webapp; HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://web.de/
200
SSLB=.0; domain=.web.de ;path=/
Cookie sent via https, but not marked as secure
Bhttps://www.gmx.com/ 82.165.229.61
200
JSESSIONID=83AD2979E54E39864D275D24424D6A4E; Path=/gmxcom-webapp; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
JSESSIONID=63D742FED3CCCA9942EBA17571BA551A; Path=/gmxcom-webapp; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://web.de/
200
euconsent-bypass=1756880752; Max-Age=120; Expires=Wed, 03 Sep 2025 06:27:52 GMT; Domain=web.de; Path=/; Secure
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://web.de/
200
ui_cid=OPTOUT; Max-Age=31536000; Expires=Thu, 03 Sep 2026 06:25:52 GMT; Path=/; Secure; HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://web.de/
200
SSLB=.0; domain=.web.de ;path=/
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Mhttps://82.165.229.61/ 82.165.229.61
404

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://82.165.229.87/ 82.165.229.87
301
https://web.de/
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://82.165.229.61/ 82.165.229.61
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain www.gmx.com, 1 ip addresses, 1 different http results.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain gmx.com, 1 ip addresses.
AGood: _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Domainname: _mta-sts.gmx.com
AGood: _mta-sts TXT record is valid.
AGood: Subdomain mta-sts found: Subdomain-name: mta-sts.gmx.com, ip : 213.165.67.126
AGood: Subdomain mta-sts found: Subdomain-name: mta-sts.gmx.com, ip : 213.165.67.101
AGood: Certificate of subdomain is valid. mta-sts.gmx.com, ip : 213.165.67.101
AGood: Certificate of subdomain is valid. mta-sts.gmx.com, ip : 213.165.67.126
AGood: /.well-known/mta-sts.txt with http status 200 found. Complete path: https://mta-sts.gmx.com/.well-known/mta-sts.txt - ip : 213.165.67.101
AGood: /.well-known/mta-sts.txt with http status 200 found. Complete path: https://mta-sts.gmx.com/.well-known/mta-sts.txt - ip : 213.165.67.126
AGood: mta-sts.txt has the required names "version", "mode", "max_age". mta-sts.gmx.com, ip : 213.165.67.126
AGood: mta-sts.txt has the required names "version", "mode", "max_age". mta-sts.gmx.com, ip : 213.165.67.101
AGood: Minimal one mx definition found. mta-sts.gmx.com, ip : 213.165.67.126
AGood: Minimal one mx definition found. mta-sts.gmx.com, ip : 213.165.67.101
AExcellent: Complete and valid MTA-STS found!

2. Header-Checks

Awww.gmx.com 82.165.229.61
Content-Security-Policy
Ok: Header without syntax errors found: block-all-mixed-content;frame-ancestors *.mail.com
B

Info: Header-Element is deprecated. block-all-mixed-content
F

Bad: Missing default-src directive. A default-src directive is used if one of the specialized fetch directives (child-src, connect-src, font-src, frame-src, img-src, manifest-src, media-src, object-src, prefetch-src, script-src, style-src, worker-src) isn't defined. Missing default-src, all sources are allowed, that's bad. A default-src with 'none' or 'self' blocks that.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
A

Good: frame-ancestors directive found. That limits pages who are allowed to use this page in a frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
E

Bad: No base-uri directive found. Use one to limit the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
F

Critical: No object-src and no default-src as fallback defined. So object / embed / applet can load every resource. That's fatal.
F

Critical: No script-src and no default-src as fallback defined. So scripts are unlimited. That's fatal.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: strict-origin-when-cross-origin
A
X-Frame-Options
Ok: Header without syntax errors found: DENY
B

Info: Header is deprecated. May not longer work in modern browsers. DENY. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
X-Xss-Protection
Ok: Header without syntax errors found: 1; mode=block
B

Info: Header is deprecated. May not longer work in modern browsers. 1; mode=block
Fwww.gmx.com 82.165.229.61
Permissions-Policy
Critical: Missing Header:
Bwww.gmx.com 82.165.229.61
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.gmx.com 82.165.229.61
Cross-Origin-Opener-Policy
Info: Missing Header
Bwww.gmx.com 82.165.229.61
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 52 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 4 Name Servers.
AInfo:: 52 Queries complete, 52 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
Bad (greater 8):: An average of 13.0 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 5 different Name Servers found: dns.gmx.net, ns-gmx.ui-dns.biz, ns-gmx.ui-dns.com, ns-gmx.ui-dns.de, ns-gmx.ui-dns.org, 4 Name Servers included in Delegation: ns-gmx.ui-dns.biz, ns-gmx.ui-dns.com, ns-gmx.ui-dns.de, ns-gmx.ui-dns.org, 4 Name Servers included in 2 Zone definitions: ns-gmx.ui-dns.biz, ns-gmx.ui-dns.com, ns-gmx.ui-dns.de, ns-gmx.ui-dns.org, 1 Name Servers listed in SOA.Primary: dns.gmx.net.
AGood: Only one SOA.Primary Name Server found.: dns.gmx.net.
Error: SOA.Primary Name Server not included in the delegation set.: dns.gmx.net.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns-gmx.ui-dns.biz, ns-gmx.ui-dns.com, ns-gmx.ui-dns.de, ns-gmx.ui-dns.org
AGood: All Name Server Domain Names have a Public Suffix.
Error: Name Server Domain Names with Public Suffix and without ip address found.: 1 Name Servers without ipv4 and ipv6: 1

AGood: Minimal 2 different name servers (public suffix and public ip address) found: 4 different Name Servers found
AGood: Name servers with different Top Level Domains / Public Suffix List entries found: 4 Name Servers, 4 Top Level Domains: de, org, com, biz
AGood: Name Servers with different domain names found.: 5 different Domains found
AGood: Name servers with different Country locations found: 4 Name Servers, 2 Countries: DE, US
AInfo: Ipv4-Subnet-list: 8 Name Servers, 2 different subnets (first Byte): 185., 217., 2 different subnets (first two Bytes): 185.132., 217.160., 8 different subnets (first three Bytes): 185.132.32., 185.132.33., 185.132.34., 185.132.35., 217.160.80., 217.160.81., 217.160.82., 217.160.83.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 8 Name Servers with IPv6, 2 different subnets (first block): 2001:, 2607:, 2 different subnets (first two blocks): 2001:08d8:, 2607:f1c0:, 2 different subnets (first three blocks): 2001:08d8:00fe:, 2607:f1c0:00fe:, 2 different subnets (first four blocks): 2001:08d8:00fe:0053:, 2607:f1c0:00fe:0053:
AGood: Name Server IPv6 addresses from different subnets found.
AInfo: Nameserver mit different domain names found. May be a problem with DNS-Updates
AGood: Nameserver supports TCP connections: 16 good Nameserver
AGood: Nameserver supports Echo Capitalization: 16 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 16 good Nameserver
AGood: All SOA have the same Serial Number
AGood: CAA entries found, creating certificate is limited: Digicert.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: telesec.de is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: digicert.com is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: telesec.de is allowed to create wildcard-certificates

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://www.gmx.com/ 82.165.229.61
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://web.de/
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://mta-sts.gmx.com/.well-known/mta-sts.txt 213.165.67.101
200

Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
https://mta-sts.gmx.com/.well-known/mta-sts.txt 213.165.67.126
200

Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://www.gmx.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
2.230 seconds
Warning: 404 needs more then one second
https://82.165.229.61/ 82.165.229.61
404
2.066 seconds
Warning: 404 needs more then one second
AInfo: Different Server-Headers found
ADuration: 192900 milliseconds, 192.900 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
gmx.com
82.165.229.87
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
gmx.com
82.165.229.87
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.gmx.com, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


www.gmx.com
82.165.229.61
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

www.gmx.com
82.165.229.61
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.gmx.com, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


gmx.com
gmx.com
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

gmx.com
gmx.com
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.gmx.com, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


www.gmx.com
www.gmx.com
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

www.gmx.com
www.gmx.com
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.gmx.com, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


mta-sts.gmx.com
213.165.67.101
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

mta-sts.gmx.com
213.165.67.101
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, C=DE, ST=Rhineland-Palatinate


2CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE


mta-sts.gmx.com
213.165.67.126
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

mta-sts.gmx.com
213.165.67.126
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, C=DE, ST=Rhineland-Palatinate


2CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE


web.de
web.de
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

web.de
web.de
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.web.de, O=1&1 Mail & Media GmbH, L=Montabaur, C=DE, ST=Rheinland-Pfalz


2CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE


82.165.229.61
82.165.229.61
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

82.165.229.61
82.165.229.61
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=*.gmx.com, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


82.165.229.87
82.165.229.87
443
name does not match
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok

82.165.229.87
82.165.229.87
443
name does not match
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=gmx.net, O=1&1 Mail & Media GmbH, C=DE, ST=Rheinland-Pfalz


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester

 

9. Certificates

1.
1.
CN=*.gmx.com, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
08.04.2025
09.04.2026
152 days expired
*.gmx.com, gmx.com - 2 entries
1.
1.
CN=*.gmx.com, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
08.04.2025

09.04.2026
152 days expired


*.gmx.com, gmx.com - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:1D293C0E9E795079E1EBFBCC7BB4FB7B
Thumbprint:671FFA1FD35229D40DFF44475AA2151FE2775406
SHA256 / Certificate:HmmQX5XvWV0HbmPGR4Mu/9kNDazoxQJfAQ9nvm1ewK0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):81545d372a638725c5a073e4f8c4170601e0745cc7c63abb9a75ee27e5b569f7
SHA256 hex / Subject Public Key Information (SPKI):81545d372a638725c5a073e4f8c4170601e0745cc7c63abb9a75ee27e5b569f7 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=*.gmx.com, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
08.04.2025
09.04.2026
152 days expired
*.gmx.com, gmx.com - 2 entries

2.
CN=*.gmx.com, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
08.04.2025

09.04.2026
152 days expired


*.gmx.com, gmx.com - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:1D293C0E9E795079E1EBFBCC7BB4FB7B
Thumbprint:671FFA1FD35229D40DFF44475AA2151FE2775406
SHA256 / Certificate:HmmQX5XvWV0HbmPGR4Mu/9kNDazoxQJfAQ9nvm1ewK0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):81545d372a638725c5a073e4f8c4170601e0745cc7c63abb9a75ee27e5b569f7
SHA256 hex / Subject Public Key Information (SPKI):81545d372a638725c5a073e4f8c4170601e0745cc7c63abb9a75ee27e5b569f7 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 1576 days


3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 1576 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):72a34ac2b424aed3f6b0b04755b88cc027dccc806fddb22b4cd7c47773973ec0
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 1576 days


4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 1576 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010
19.01.2038
expires in 4151 days


5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010

19.01.2038
expires in 4151 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:01FD6D30FCA3CA51A81BBC640E35032D
Thumbprint:2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
SHA256 / Certificate:55PJsC/YqhPiHDEiisywgRlkO3SciYlksXRtRsPUy9I=
SHA256 hex / Cert (DANE * 0 1):e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019
01.01.2029
expires in 846 days


6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019

01.01.2029
expires in 846 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:3972443AF922B751D7D36C10DD313595
Thumbprint:D89E3BD43D5D909B47A18977AA9D5CE36CEE184C
SHA256 / Certificate:aLnHYSGaWx8BMXhEdGZdthu9sQngDwXKn3QkTuX19Ss=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.comodoca.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004
01.01.2029
expires in 846 days


7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004

01.01.2029
expires in 846 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:01
Thumbprint:D1EB23A46D17D68FD92564C2F1F1601764D8E349
SHA256 / Certificate:16eg+11+JzHXcelITrze9x1fDD4KKUh4K8g+4OppnvQ=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SHA256 hex / Subject Public Key Information (SPKI):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




2.
1.
CN=gmx.net, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
11.03.2025
12.03.2026
180 days expired
gmx.net, gmx.at, gmx.biz, gmx.cc, gmx.ch, gmx.co.in, gmx.com.tr, gmx.de, gmx.dk, gmx.info, gmx.it, gmx.li, gmx.lu, gmx.org, gmx.ph, gmx.se, gmx.sg, gmx.tm, gmx.tw, www.gmx.net - 20 entries
2.
1.
CN=gmx.net, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
11.03.2025

12.03.2026
180 days expired


gmx.net, gmx.at, gmx.biz, gmx.cc, gmx.ch, gmx.co.in, gmx.com.tr, gmx.de, gmx.dk, gmx.info, gmx.it, gmx.li, gmx.lu, gmx.org, gmx.ph, gmx.se, gmx.sg, gmx.tm, gmx.tw, www.gmx.net - 20 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:422B2B599288DA0B4489CCB6C833D4E5
Thumbprint:CC8B032479D3CBBFE00C858AE1ECD57A6BA9B64E
SHA256 / Certificate:ZYbwLp50yUhp5anX3Gihleml8KaHM4QwObJNDAMklyY=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):ef89a232ff3429338f9df94a66c20ed8fe24326c16b9729d4df89710ff89640c
SHA256 hex / Subject Public Key Information (SPKI):ef89a232ff3429338f9df94a66c20ed8fe24326c16b9729d4df89710ff89640c (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=gmx.net, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
11.03.2025
12.03.2026
180 days expired
gmx.net, gmx.at, gmx.biz, gmx.cc, gmx.ch, gmx.co.in, gmx.com.tr, gmx.de, gmx.dk, gmx.info, gmx.it, gmx.li, gmx.lu, gmx.org, gmx.ph, gmx.se, gmx.sg, gmx.tm, gmx.tw, www.gmx.net - 20 entries

2.
CN=gmx.net, O=1&1 Mail & Media GmbH, S=Rheinland-Pfalz, C=DE
11.03.2025

12.03.2026
180 days expired


gmx.net, gmx.at, gmx.biz, gmx.cc, gmx.ch, gmx.co.in, gmx.com.tr, gmx.de, gmx.dk, gmx.info, gmx.it, gmx.li, gmx.lu, gmx.org, gmx.ph, gmx.se, gmx.sg, gmx.tm, gmx.tw, www.gmx.net - 20 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:422B2B599288DA0B4489CCB6C833D4E5
Thumbprint:CC8B032479D3CBBFE00C858AE1ECD57A6BA9B64E
SHA256 / Certificate:ZYbwLp50yUhp5anX3Gihleml8KaHM4QwObJNDAMklyY=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):ef89a232ff3429338f9df94a66c20ed8fe24326c16b9729d4df89710ff89640c
SHA256 hex / Subject Public Key Information (SPKI):ef89a232ff3429338f9df94a66c20ed8fe24326c16b9729d4df89710ff89640c (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 1576 days


3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 1576 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):72a34ac2b424aed3f6b0b04755b88cc027dccc806fddb22b4cd7c47773973ec0
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 1576 days


4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 1576 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010
19.01.2038
expires in 4151 days


5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010

19.01.2038
expires in 4151 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:01FD6D30FCA3CA51A81BBC640E35032D
Thumbprint:2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
SHA256 / Certificate:55PJsC/YqhPiHDEiisywgRlkO3SciYlksXRtRsPUy9I=
SHA256 hex / Cert (DANE * 0 1):e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019
01.01.2029
expires in 846 days


6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019

01.01.2029
expires in 846 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:3972443AF922B751D7D36C10DD313595
Thumbprint:D89E3BD43D5D909B47A18977AA9D5CE36CEE184C
SHA256 / Certificate:aLnHYSGaWx8BMXhEdGZdthu9sQngDwXKn3QkTuX19Ss=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.comodoca.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004
01.01.2029
expires in 846 days


7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004

01.01.2029
expires in 846 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:01
Thumbprint:D1EB23A46D17D68FD92564C2F1F1601764D8E349
SHA256 / Certificate:16eg+11+JzHXcelITrze9x1fDD4KKUh4K8g+4OppnvQ=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SHA256 hex / Subject Public Key Information (SPKI):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




3.
1.
CN=*.web.de, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rheinland-Pfalz, C=DE
20.11.2024
25.11.2025
287 days expired
*.web.de, web.de - 2 entries
3.
1.
CN=*.web.de, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rheinland-Pfalz, C=DE
20.11.2024

25.11.2025
287 days expired


*.web.de, web.de - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:3603F6AA93BA6116E3F26E40D4E98E5D
Thumbprint:3D754FE81067A08FA80EB725FF9F4589E6C904DD
SHA256 / Certificate:FDwG1tKBruSxoVo3ZJakkaTFYA1eKb1bpo/nDFnFjMw=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):cbbc5aa3349839238da6e5859e6150027493723995312541d9daf0a86a5c0295
SHA256 hex / Subject Public Key Information (SPKI):cbbc5aa3349839238da6e5859e6150027493723995312541d9daf0a86a5c0295 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.serverid.telesec.de/ocspr
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




2.
CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE
02.08.2022
03.08.2027
expires in 329 days


2.
CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE
02.08.2022

03.08.2027
expires in 329 days




KeyalgorithmRSA encryption ( bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0E5D298915C40431A4E1C4CA488B8EA3
Thumbprint:52869CEF1A2195C416820C183B80C995BBBFBEDC
SHA256 / Certificate:lErOlh2zFr62lOAcMCxG/tQNwCkXKefa9YVQw8tV55E=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):f4ae11c0a420cddf883a6fafbd59c7905c2f955d760382cebaeb89effd96a3c4
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://grcl2.ocsp.telesec.de/ocspr
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE
01.10.2008
02.10.2033
expires in 2581 days


3.
CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE
01.10.2008

02.10.2033
expires in 2581 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:01
Thumbprint:590D2D7D884F402E617EA562321765CF17D894E9
SHA256 / Certificate:keL1eI1YEOunulhzfeFUio7KzQFFmLwLFD4EGxcFJVI=
SHA256 hex / Cert (DANE * 0 1):91e2f5788d5810eba7ba58737de1548a8ecacd014598bc0b143e041b17052552
SHA256 hex / PublicKey (DANE * 1 1):6106c0e3a0a299831875127bd7d3cc1859803d511cac11eb6e0840dd166fc10e
SHA256 hex / Subject Public Key Information (SPKI):6106c0e3a0a299831875127bd7d3cc1859803d511cac11eb6e0840dd166fc10e
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




4.
1.
CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rhineland-Palatinate, C=DE
10.04.2025
15.04.2026
146 days expired
mta-sts.gmx.net, mta-sts.gmx.de, mta-sts.web.de, mta-sts.gmx.com - 4 entries
4.
1.
CN=mta-sts.gmx.net, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rhineland-Palatinate, C=DE
10.04.2025

15.04.2026
146 days expired


mta-sts.gmx.net, mta-sts.gmx.de, mta-sts.web.de, mta-sts.gmx.com - 4 entries

KeyalgorithmRSA encryption ( bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:02141A0977F71127B314784EEAD05929
Thumbprint:E2F996E686BB716E1C70EC4EDB4DE281FD11E47F
SHA256 / Certificate:G6g19nItasSmZkNdSp+hLiMF9k7XF8VcrXXBS+JCrcg=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):eeb385d8e111e749275902aa40c5a0f435cbe4ab7eaa81d3b1167b08a8ea3469
SHA256 hex / Subject Public Key Information (SPKI):eeb385d8e111e749275902aa40c5a0f435cbe4ab7eaa81d3b1167b08a8ea3469 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.serverid.telesec.de/ocspr
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




2.
CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE
02.08.2022
03.08.2027
expires in 329 days


2.
CN=Telekom Security ServerID OV Class 2 CA, O=Deutsche Telekom Security GmbH, C=DE
02.08.2022

03.08.2027
expires in 329 days




KeyalgorithmRSA encryption ( bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0E5D298915C40431A4E1C4CA488B8EA3
Thumbprint:52869CEF1A2195C416820C183B80C995BBBFBEDC
SHA256 / Certificate:lErOlh2zFr62lOAcMCxG/tQNwCkXKefa9YVQw8tV55E=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):f4ae11c0a420cddf883a6fafbd59c7905c2f955d760382cebaeb89effd96a3c4
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://grcl2.ocsp.telesec.de/ocspr
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE
01.10.2008
02.10.2033
expires in 2581 days


3.
CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE
01.10.2008

02.10.2033
expires in 2581 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:01
Thumbprint:590D2D7D884F402E617EA562321765CF17D894E9
SHA256 / Certificate:keL1eI1YEOunulhzfeFUio7KzQFFmLwLFD4EGxcFJVI=
SHA256 hex / Cert (DANE * 0 1):91e2f5788d5810eba7ba58737de1548a8ecacd014598bc0b143e041b17052552
SHA256 hex / PublicKey (DANE * 1 1):6106c0e3a0a299831875127bd7d3cc1859803d511cac11eb6e0840dd166fc10e
SHA256 hex / Subject Public Key Information (SPKI):6106c0e3a0a299831875127bd7d3cc1859803d511cac11eb6e0840dd166fc10e
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
0
2
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
0
0
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
10039678375
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2025-04-08 00:00:00
2026-04-08 23:59:59
*.gmx.com, gmx.com - 2 entries


10040304495
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2025-04-08 00:00:00
2026-04-08 23:59:59
*.www.gmx.com, www.gmx.com - 2 entries


7131055351
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2024-04-15 00:00:00
2025-05-16 23:59:59
*.gmx.com, gmx.com - 2 entries


 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Issuerlast 7 daysactivenum Certs
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
0
2
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
0
0
1

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
17715488463
precert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2025-04-07 22:00:00
2026-04-08 21:59:59
*.gmx.com, gmx.com
2 entries


17717023673
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2025-04-07 22:00:00
2026-04-08 21:59:59
*.www.gmx.com, www.gmx.com
2 entries


12731411486
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2024-04-14 22:00:00
2025-05-16 21:59:59
*.gmx.com, gmx.com
2 entries


 

11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404

 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://www.gmx.com/

Summary

Good: No non-document-errors
0 errors
0 warnings

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns-gmx.ui-dns.biz, ns-gmx.ui-dns.com, ns-gmx.ui-dns.de, ns-gmx.ui-dns.org

 

QNr.DomainTypeNS used
1
biz
NS
d.root-servers.net (2001:500:2d::d)

Answer: a.gtld.biz, b.gtld.biz, c.gtld.biz, m.gtld.biz, n.gtld.biz, w.gtld.biz, x.gtld.biz, y.gtld.biz
2
ns-gmx.ui-dns.biz
NS
a.gtld.biz (2001:502:ad09::30)

Answer: ns-biz.ui-dns.biz, ns-biz.ui-dns.com, ns-biz.ui-dns.de, ns-biz.ui-dns.org

Answer: ns-biz.ui-dns.biz
185.132.33.195, 2001:8d8:fe:53:0:d9a0:51c3:100, 217.160.81.195, 2607:f1c0:fe:53:185:132:33:195
3
com
NS
h.root-servers.net (2001:500:1::53)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
4
ns-gmx.ui-dns.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-com.ui-dns.biz, ns-com.ui-dns.com, ns-com.ui-dns.de, ns-com.ui-dns.org

Answer: ns-com.ui-dns.com
185.132.34.214, 2001:8d8:fe:53:0:d9a0:52d6:100, 217.160.82.214, 2607:f1c0:fe:53:185:132:34:214
5
de
NS
m.root-servers.net (2001:dc3::35)

Answer: a.nic.de, f.nic.de, l.de.net, n.de.net, s.de.net, z.nic.de
6
ns-gmx.ui-dns.de
NS
a.nic.de (2001:678:2::53)

Answer: ns-de.ui-dns.biz, ns-de.ui-dns.com, ns-de.ui-dns.de, ns-de.ui-dns.org

Answer: ns-de.ui-dns.de
185.132.32.193, 2001:8d8:fe:53:0:d9a0:50c1:100, 217.160.80.193, 2607:f1c0:fe:53:185:132:32:193
7
org
NS
d.root-servers.net (2001:500:2d::d)

Answer: a0.org.afilias-nst.info, a2.org.afilias-nst.info, b0.org.afilias-nst.org, b2.org.afilias-nst.org, c0.org.afilias-nst.info, d0.org.afilias-nst.org
8
ns-gmx.ui-dns.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: ns-org.ui-dns.biz, ns-org.ui-dns.com, ns-org.ui-dns.de, ns-org.ui-dns.org

Answer: ns-org.ui-dns.org
185.132.34.194, 2001:8d8:fe:53:0:d9a0:52c2:100, 217.160.82.194, 2607:f1c0:fe:53:185:132:34:194
9
ns-biz.ui-dns.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-com.ui-dns.biz, ns-com.ui-dns.com, ns-com.ui-dns.de, ns-com.ui-dns.org

Answer: ns-com.ui-dns.com
185.132.34.214, 2001:8d8:fe:53:0:d9a0:52d6:100, 217.160.82.214, 2607:f1c0:fe:53:185:132:34:214
10
ns-biz.ui-dns.de
NS
a.nic.de (2001:678:2::53)

Answer: ns-de.ui-dns.biz, ns-de.ui-dns.com, ns-de.ui-dns.de, ns-de.ui-dns.org

Answer: ns-de.ui-dns.de
185.132.32.193, 2001:8d8:fe:53:0:d9a0:50c1:100, 217.160.80.193, 2607:f1c0:fe:53:185:132:32:193
11
ns-biz.ui-dns.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: ns-org.ui-dns.biz, ns-org.ui-dns.com, ns-org.ui-dns.de, ns-org.ui-dns.org

Answer: ns-org.ui-dns.org
185.132.34.194, 2001:8d8:fe:53:0:d9a0:52c2:100, 217.160.82.194, 2607:f1c0:fe:53:185:132:34:194
12
ns-com.ui-dns.biz
NS
a.gtld.biz (2001:502:ad09::30)

Answer: ns-biz.ui-dns.biz, ns-biz.ui-dns.com, ns-biz.ui-dns.de, ns-biz.ui-dns.org

Answer: ns-biz.ui-dns.biz
185.132.33.195, 2001:8d8:fe:53:0:d9a0:51c3:100, 217.160.81.195, 2607:f1c0:fe:53:185:132:33:195
13
ns-com.ui-dns.de
NS
a.nic.de (2001:678:2::53)

Answer: ns-de.ui-dns.biz, ns-de.ui-dns.com, ns-de.ui-dns.de, ns-de.ui-dns.org

Answer: ns-de.ui-dns.de
185.132.32.193, 2001:8d8:fe:53:0:d9a0:50c1:100, 217.160.80.193, 2607:f1c0:fe:53:185:132:32:193
14
ns-com.ui-dns.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: ns-org.ui-dns.biz, ns-org.ui-dns.com, ns-org.ui-dns.de, ns-org.ui-dns.org

Answer: ns-org.ui-dns.org
185.132.34.194, 2001:8d8:fe:53:0:d9a0:52c2:100, 217.160.82.194, 2607:f1c0:fe:53:185:132:34:194
15
ns-de.ui-dns.biz
NS
a.gtld.biz (2001:502:ad09::30)

Answer: ns-biz.ui-dns.biz, ns-biz.ui-dns.com, ns-biz.ui-dns.de, ns-biz.ui-dns.org

Answer: ns-biz.ui-dns.biz
185.132.33.195, 2001:8d8:fe:53:0:d9a0:51c3:100, 217.160.81.195, 2607:f1c0:fe:53:185:132:33:195
16
ns-de.ui-dns.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-com.ui-dns.biz, ns-com.ui-dns.com, ns-com.ui-dns.de, ns-com.ui-dns.org

Answer: ns-com.ui-dns.com
185.132.34.214, 2001:8d8:fe:53:0:d9a0:52d6:100, 217.160.82.214, 2607:f1c0:fe:53:185:132:34:214
17
ns-de.ui-dns.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: ns-org.ui-dns.biz, ns-org.ui-dns.com, ns-org.ui-dns.de, ns-org.ui-dns.org

Answer: ns-org.ui-dns.org
185.132.34.194, 2001:8d8:fe:53:0:d9a0:52c2:100, 217.160.82.194, 2607:f1c0:fe:53:185:132:34:194
18
ns-org.ui-dns.biz
NS
a.gtld.biz (2001:502:ad09::30)

Answer: ns-biz.ui-dns.biz, ns-biz.ui-dns.com, ns-biz.ui-dns.de, ns-biz.ui-dns.org

Answer: ns-biz.ui-dns.biz
185.132.33.195, 2001:8d8:fe:53:0:d9a0:51c3:100, 217.160.81.195, 2607:f1c0:fe:53:185:132:33:195
19
ns-org.ui-dns.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-com.ui-dns.biz, ns-com.ui-dns.com, ns-com.ui-dns.de, ns-com.ui-dns.org

Answer: ns-com.ui-dns.com
185.132.34.214, 2001:8d8:fe:53:0:d9a0:52d6:100, 217.160.82.214, 2607:f1c0:fe:53:185:132:34:214
20
ns-org.ui-dns.de
NS
a.nic.de (2001:678:2::53)

Answer: ns-de.ui-dns.biz, ns-de.ui-dns.com, ns-de.ui-dns.de, ns-de.ui-dns.org

Answer: ns-de.ui-dns.de
185.132.32.193, 2001:8d8:fe:53:0:d9a0:50c1:100, 217.160.80.193, 2607:f1c0:fe:53:185:132:32:193
21
ns-biz.ui-dns.com: 185.132.34.195, 217.160.82.195
A
ns-com.ui-dns.com (2001:8d8:fe:53:0:d9a0:52d6:100)
22
ns-biz.ui-dns.com: 2001:8d8:fe:53:0:d9a0:52c3:100, 2607:f1c0:fe:53:185:132:34:195
AAAA
ns-com.ui-dns.com (2001:8d8:fe:53:0:d9a0:52d6:100)
23
ns-biz.ui-dns.de: 185.132.32.195, 217.160.80.195
A
ns-de.ui-dns.de (2001:8d8:fe:53:0:d9a0:50c1:100)
24
ns-biz.ui-dns.de: 2001:8d8:fe:53:0:d9a0:50c3:100, 2607:f1c0:fe:53:185:132:32:195
AAAA
ns-de.ui-dns.de (2001:8d8:fe:53:0:d9a0:50c1:100)
25
ns-biz.ui-dns.org: 185.132.35.195, 217.160.83.195
A
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
26
ns-biz.ui-dns.org: 2001:8d8:fe:53:0:d9a0:53c3:100, 2607:f1c0:fe:53:185:132:35:195
AAAA
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
27
ns-com.ui-dns.biz: 185.132.33.194, 217.160.81.194
A
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
28
ns-com.ui-dns.biz: 2001:8d8:fe:53:0:d9a0:51c2:100, 2607:f1c0:fe:53:185:132:33:194
AAAA
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
29
ns-com.ui-dns.de: 185.132.32.194, 217.160.80.194
A
ns-de.ui-dns.de (2001:8d8:fe:53:0:d9a0:50c1:100)
30
ns-com.ui-dns.de: 2001:8d8:fe:53:0:d9a0:50c2:100, 2607:f1c0:fe:53:185:132:32:194
AAAA
ns-de.ui-dns.de (2001:8d8:fe:53:0:d9a0:50c1:100)
31
ns-com.ui-dns.org: 185.132.35.194, 217.160.83.194
A
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
32
ns-com.ui-dns.org: 2001:8d8:fe:53:0:d9a0:53c2:100, 2607:f1c0:fe:53:185:132:35:194
AAAA
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
33
ns-de.ui-dns.biz: 185.132.33.193, 217.160.81.193
A
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
34
ns-de.ui-dns.biz: 2001:8d8:fe:53:0:d9a0:51c1:100, 2607:f1c0:fe:53:185:132:33:193
AAAA
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
35
ns-de.ui-dns.com: 185.132.34.193, 217.160.82.193
A
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
36
ns-de.ui-dns.com: 2001:8d8:fe:53:0:d9a0:52c1:100, 2607:f1c0:fe:53:185:132:34:193
AAAA
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
37
ns-de.ui-dns.org: 185.132.35.193, 217.160.83.193
A
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
38
ns-de.ui-dns.org: 2001:8d8:fe:53:0:d9a0:53c1:100, 2607:f1c0:fe:53:185:132:35:193
AAAA
ns-org.ui-dns.org (2001:8d8:fe:53:0:d9a0:52c2:100)
39
ns-org.ui-dns.biz: 185.132.33.196, 217.160.81.196
A
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
40
ns-org.ui-dns.biz: 2001:8d8:fe:53:0:d9a0:51c4:100, 2607:f1c0:fe:53:185:132:33:196
AAAA
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
41
ns-org.ui-dns.com: 185.132.34.196, 217.160.82.196
A
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
42
ns-org.ui-dns.com: 2001:8d8:fe:53:0:d9a0:52c4:100, 2607:f1c0:fe:53:185:132:34:196
AAAA
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
43
ns-org.ui-dns.de: 185.132.32.196, 217.160.80.196
A
ns-de.ui-dns.biz (2607:f1c0:fe:53:185:132:33:193)
44
ns-org.ui-dns.de: 2001:8d8:fe:53:0:d9a0:50c4:100, 2607:f1c0:fe:53:185:132:32:196
AAAA
ns-de.ui-dns.biz (2607:f1c0:fe:53:185:132:33:193)
45
ns-gmx.ui-dns.biz: 185.132.33.199, 217.160.81.199
A
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
46
ns-gmx.ui-dns.biz: 2001:8d8:fe:53:0:d9a0:51c7:100, 2607:f1c0:fe:53:185:132:33:199
AAAA
ns-biz.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c3:100)
47
ns-gmx.ui-dns.com: 185.132.34.199, 217.160.82.199
A
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
48
ns-gmx.ui-dns.com: 2001:8d8:fe:53:0:d9a0:52c7:100, 2607:f1c0:fe:53:185:132:34:199
AAAA
ns-com.ui-dns.biz (2001:8d8:fe:53:0:d9a0:51c2:100)
49
ns-gmx.ui-dns.de: 185.132.32.199, 217.160.80.199
A
ns-de.ui-dns.biz (2607:f1c0:fe:53:185:132:33:193)
50
ns-gmx.ui-dns.de: 2001:8d8:fe:53:0:d9a0:50c7:100, 2607:f1c0:fe:53:185:132:32:199
AAAA
ns-de.ui-dns.biz (2607:f1c0:fe:53:185:132:33:193)
51
ns-gmx.ui-dns.org: 185.132.35.199, 217.160.83.199
A
ns-org.ui-dns.biz (2607:f1c0:fe:53:185:132:33:196)
52
ns-gmx.ui-dns.org: 2001:8d8:fe:53:0:d9a0:53c7:100, 2607:f1c0:fe:53:185:132:35:199
AAAA
ns-org.ui-dns.biz (2607:f1c0:fe:53:185:132:33:196)

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.gmx.com
0

no CAA entry found
1
0
gmx.com
5
issue
Digicert.com
1
0

9
issuewild
digicert.com
1
0

5
issue
sectigo.com
1
0

9
issuewild
sectigo.com
1
0

5
issue
telesec.de
1
0

9
issuewild
telesec.de
1
0
com
0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
gmx.com
cs2wypdfpjcvt13xc979nk7wbfyk732l
ok
1
0
gmx.com
facebook-domain-verification=rrwl4taoaitv2jrqmz719qv6f18jgo
ok
1
0
gmx.com
google-site-verification=H6aQ8xjy09XYRfh1DU6TEBFVxHITg-zIukkE7IIXP2g
ok
1
0
gmx.com
google-site-verification=hYUs91S-7d-Pk3wP56GUGUfwMQ22WpxcDT6QC_oAwX0
ok
1
0
gmx.com
google-site-verification=YxvYPeuavgDRQDYTX-3dSD3JNMsDn5yO7loiNot-h0Q
ok
1
0
gmx.com
tpverification20190725
ok
1
0
gmx.com
v=spf1 redirect=_spf.gmx.net
ok
1
0
www.gmx.com

ok
1
0
_acme-challenge.gmx.com

Name Error - The domain name does not exist
1
0
_acme-challenge.www.gmx.com

Name Error - The domain name does not exist
1
0
_acme-challenge.gmx.com.gmx.com

Name Error - The domain name does not exist
1
0
_acme-challenge.www.gmx.com.gmx.com

Name Error - The domain name does not exist
1
0
_acme-challenge.www.gmx.com.www.gmx.com

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

gmx.com
10
mx00.gmx.net
02ok

A


212.227.15.10
01ok

CNAME


00ok
MX

gmx.com
10
mx01.gmx.net
02ok

A


212.227.17.4
01ok

CNAME


00ok
_mta-sts
TXT
_mta-sts.gmx.com

v=STSv1;id=20190416142000Z;
ok

A
mta-sts.gmx.com

213.165.67.126
ok

mta-sts.txt file
Content of https://mta-sts.gmx.com/.well-known/mta-sts.txt - see RFC 8461 text/plainok




version: STSv1
ok




mode: testing
ok




mx: mx00.gmx.net
ok




mx: mx01.gmx.net
ok




max_age: 604800
ok

A
mta-sts.gmx.com

213.165.67.101
ok

mta-sts.txt file
Content of https://mta-sts.gmx.com/.well-known/mta-sts.txt - see RFC 8461 text/plainok




version: STSv1
ok




mode: testing
ok




mx: mx00.gmx.net
ok




mx: mx01.gmx.net
ok




max_age: 604800
ok
SMTP-TLS Reporting
TXT
_smtp._tls.gmx.com

v=TLSRPTv1;rua=mailto:smtp-tlsrpt@1und1.de
ok
SPF
TXT
gmx.com

v=spf1 redirect=_spf.gmx.net
ok

TXT
_spf.gmx.net

v=spf1 a:mout.gmx.net a:mout-xforward.gmx.net a:mout-bounce.gmx.net a:mout-csbulk.1and1.com a:mout-cscorp.1and1.com ~all
ok

A
mout.gmx.net

212.227.17.20
ok

A
mout.gmx.net

212.227.15.19
ok

A
mout.gmx.net

212.227.17.21
ok

A
mout.gmx.net

212.227.15.18
ok

A
mout.gmx.net

212.227.15.15
ok

A
mout.gmx.net

212.227.17.22
ok

A
mout-xforward.gmx.net

82.165.159.12
ok

A
mout-xforward.gmx.net

82.165.159.14
ok

A
mout-xforward.gmx.net

82.165.159.13
ok

A
mout-xforward.gmx.net

82.165.159.42
ok

A
mout-xforward.gmx.net

82.165.159.40
ok

A
mout-xforward.gmx.net

82.165.159.41
ok

A
mout-bounce.gmx.net

212.227.17.28
ok

A
mout-bounce.gmx.net

212.227.15.45
ok

A
mout-bounce.gmx.net

212.227.15.44
ok

A
mout-bounce.gmx.net

212.227.15.46
ok

A
mout-bounce.gmx.net

212.227.17.29
ok

A
mout-bounce.gmx.net

212.227.17.26
ok

A
mout-csbulk.1and1.com

212.227.126.225
ok

A
mout-csbulk.1and1.com

212.227.15.47
ok

A
mout-csbulk.1and1.com

212.227.15.53
ok

A
mout-csbulk.1and1.com

212.227.126.227
ok

A
mout-csbulk.1and1.com

212.227.126.226
ok

A
mout-csbulk.1and1.com

212.227.126.224
ok

A
mout-cscorp.1and1.com

212.227.15.50
ok

A
mout-cscorp.1and1.com

212.227.15.52
ok
_dmarc
TXT
_dmarc.gmx.com

v=DMARC1; p=quarantine; rua=mailto:dmarcreport@gmx.net
ok

TXT
gmx.com._report._dmarc.gmx.net

mailto:dmarcreport@gmx.net
okMail domain unequal current domain. Check required, if there is a confirming _report._dmarc-Record. See RFC 7489, 7.1.

TXT
gmx.com._report._dmarc.gmx.net

v=DMARC1;
okConfirmed. Sending reports to external domain is allowed.

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
gmx.com
82.165.229.87
443
3 Ciphers26.81 sec
0 without, 3 FS
100.00 %
www.gmx.com
82.165.229.61
443
3 Ciphers26.72 sec
0 without, 3 FS
100.00 %
Complete

2
6 Ciphers
3.00 Ciphers/Check
53.53 sec26.77 sec/Check
0 without, 6 FS
100.00 %

Details
DomainIPPortCipher (OpenSsl / IANA)
gmx.com
82.165.229.87
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
3 Ciphers, 26.81 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD

www.gmx.com
82.165.229.61
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
3 Ciphers, 26.72 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=e3dee6e0-1e1e-4a73-b127-be3409b2af1a

 

Last Result: https://check-your-website.server-daten.de/?q=gmx.com - 2025-09-03 08:24:41

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=gmx.com" target="_blank">Check this Site: gmx.com</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=gmx.com