Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
iana.org
A
192.0.43.8
Anthony/Kansas/United States (US) - ICANN
Hostname: 43-8.any.icann.org
yes
1
0

AAAA
2001:500:88:200::8
Los Angeles/California/United States (US) - ICANN

yes


www.iana.org
CNAME
ianawww.vip.icann.org
yes
1
0

A
192.0.46.8
Washington/District of Columbia/United States (US) - ICANN
Hostname: 46-8.dc.icann.org
yes



AAAA
2620:0:2830:200::b:8
Los Angeles/California/United States (US) - ICANN

yes


*.iana.org
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 26470, Flags 256






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.02.2025, 00:00:00 +, Signature-Inception: 11.01.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: org

org
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=






2 RRSIG RR to validate DS RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 26.01.2025, 17:00:00 +, Signature-Inception: 13.01.2025, 16:00:00 +, KeyTag 26470, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26470 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 11409, Flags 256






Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 55899, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 30.01.2025, 15:32:47 +, Signature-Inception: 09.01.2025, 14:32:47 +, KeyTag 26974, Signer-Name: org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: iana.org

iana.org
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 39229, DigestType 2 and Digest Hn5yCDXGhKmmQ4eqq8YvCVi8PWGPcEJcG6mOGWpDFeY=






1 RRSIG RR to validate DS RR found






RRSIG-Owner iana.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.01.2025, 15:32:47 +, Signature-Inception: 09.01.2025, 14:32:47 +, KeyTag 11409, Signer-Name: org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 11409 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 29853, Flags 256






Public Key with Algorithm 13, KeyTag 39229, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 47346, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner iana.org., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2025, 22:17:37 +, Signature-Inception: 12.01.2025, 16:34:09 +, KeyTag 39229, Signer-Name: iana.org






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 39229 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 39229, DigestType 2 and Digest "Hn5yCDXGhKmmQ4eqq8YvCVi8PWGPcEJcG6mOGWpDFeY=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone






RRSIG Type 16 validates the TXT - Result: MS=ms22660639 v=spf1 redirect=icann.org c9e864a6c53444038d34fe3a22513b74 docusign=b2d7c7b0-4627-494b-a7aa-682ee87c265d smartsheet-site-validation=CcnvONgQ2ibuzf2zHZxgPaWUqTwt-Sjr google-site-verification=iIqTTcUxND4wZOeVe5Ho728rH3JOSDnssYsYJ7pUtQQ
Validated: RRSIG-Owner iana.org., Algorithm: 13, 2 Labels, original TTL: 86400 sec, Signature-expiration: 04.02.2025, 06:04:31 +, Signature-Inception: 14.01.2025, 02:35:08 +, KeyTag 29853, Signer-Name: iana.org






RRSIG Type 1 validates the A - Result: 192.0.43.8
Validated: RRSIG-Owner iana.org., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 20.01.2025, 10:11:56 +, Signature-Inception: 30.12.2024, 17:23:54 +, KeyTag 47346, Signer-Name: iana.org






RRSIG Type 28 validates the AAAA - Result: 2001:0500:0088:0200:0000:0000:0000:0008
Validated: RRSIG-Owner iana.org., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 23.01.2025, 11:09:45 +, Signature-Inception: 02.01.2025, 20:57:03 +, KeyTag 47346, Signer-Name: iana.org






CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "2s5ih8jagmesqief4f80a7kfc8mr7c67" equal the hashed NSEC3-owner "2s5ih8jagmesqief4f80a7kfc8mr7c67" and the hashed NextOwner "3s5h3jcjvjs2h4l4o90126li2k694ocr". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 2s5ih8jagmesqief4f80a7kfc8mr7c67.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 22.01.2025, 17:08:45 +, Signature-Inception: 01.01.2025, 12:35:08 +, KeyTag 47346, Signer-Name: iana.org






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.iana.org) sends a valid NSEC3 RR as result with the hashed owner name "2s5ih8jagmesqief4f80a7kfc8mr7c67" (unhashed: iana.org). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 2s5ih8jagmesqief4f80a7kfc8mr7c67.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 22.01.2025, 17:08:45 +, Signature-Inception: 01.01.2025, 12:35:08 +, KeyTag 47346, Signer-Name: iana.org






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "nbcq18qucvuic5qkgheqcrh1fjlv2jf8" (unhashed: _tcp.iana.org) with the owner "n93futhncru1f2m82vcfrvkk4o4vm3g5" and the NextOwner "o0nebgk51an8bqjj6tbmpmub864busko". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: TXT, RRSIG Validated: RRSIG-Owner n93futhncru1f2m82vcfrvkk4o4vm3g5.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 21.01.2025, 21:06:01 +, Signature-Inception: 01.01.2025, 04:35:08 +, KeyTag 47346, Signer-Name: iana.org






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "q5spjiln52ep9ucuhen6rtskv2bm7827" (unhashed: *.iana.org) with the owner "pmfs32ih114ajngl887itg6p1hnv284m" and the NextOwner "qi5u8383h3e3h9fhqko22639uv8bol9a". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner pmfs32ih114ajngl887itg6p1hnv284m.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 22.01.2025, 21:12:16 +, Signature-Inception: 01.01.2025, 12:35:08 +, KeyTag 47346, Signer-Name: iana.org






Status: Good. NXDomain-Proof required and found.






CAA-Query sends a valid NSEC3 RR as result with the hashed query name "2s5ih8jagmesqief4f80a7kfc8mr7c67" equal the hashed NSEC3-owner "2s5ih8jagmesqief4f80a7kfc8mr7c67" and the hashed NextOwner "3s5h3jcjvjs2h4l4o90126li2k694ocr". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 2s5ih8jagmesqief4f80a7kfc8mr7c67.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 22.01.2025, 17:08:45 +, Signature-Inception: 01.01.2025, 12:35:08 +, KeyTag 47346, Signer-Name: iana.org






Status: Good. NoData-Proof required and found.



Zone: www.iana.org

www.iana.org
0 DS RR in the parent zone found






RRSIG Type 5 validates the CNAME - Result: ianawww.vip.icann.org
Validated: RRSIG-Owner www.iana.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 25.01.2025, 14:07:39 +, Signature-Inception: 04.01.2025, 05:01:03 +, KeyTag 47346, Signer-Name: iana.org



Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 26470, Flags 256






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.02.2025, 00:00:00 +, Signature-Inception: 11.01.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: org

org
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=






2 RRSIG RR to validate DS RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 26.01.2025, 17:00:00 +, Signature-Inception: 13.01.2025, 16:00:00 +, KeyTag 26470, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26470 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 11409, Flags 256






Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 55899, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 30.01.2025, 15:32:47 +, Signature-Inception: 09.01.2025, 14:32:47 +, KeyTag 26974, Signer-Name: org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: icann.org

icann.org
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 32859, DigestType 2 and Digest JxRFsHmFzPuOtC2qCQ6pKNcjDiFBBUtPyIUE9GyX0z0=






1 RRSIG RR to validate DS RR found






RRSIG-Owner icann.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.01.2025, 15:32:47 +, Signature-Inception: 09.01.2025, 14:32:47 +, KeyTag 11409, Signer-Name: org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 11409 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 32859, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 49717, Flags 256






Public Key with Algorithm 13, KeyTag 58411, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner icann.org., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 03.02.2025, 16:49:17 +, Signature-Inception: 13.01.2025, 19:08:58 +, KeyTag 32859, Signer-Name: icann.org






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 32859 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 32859, DigestType 2 and Digest "JxRFsHmFzPuOtC2qCQ6pKNcjDiFBBUtPyIUE9GyX0z0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: vip.icann.org

vip.icann.org
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 6025, DigestType 2 and Digest Tar9xiUozvyMj1K1DXDYIhFb2cD2ZiplBWA+8YQB/kk=






1 RRSIG RR to validate DS RR found






RRSIG-Owner vip.icann.org., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 28.01.2025, 21:55:24 +, Signature-Inception: 08.01.2025, 03:13:30 +, KeyTag 49717, Signer-Name: icann.org






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 49717 used to validate the DS RRSet in the parent zone






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 2253, Flags 256






Public Key with Algorithm 8, KeyTag 6025, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 53541, Flags 256






3 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner vip.icann.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 2253, Signer-Name: vip.icann.org






RRSIG-Owner vip.icann.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 6025, Signer-Name: vip.icann.org






RRSIG-Owner vip.icann.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 2253 used to validate the DNSKEY RRSet






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 6025 used to validate the DNSKEY RRSet






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 53541 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 6025, DigestType 2 and Digest "Tar9xiUozvyMj1K1DXDYIhFb2cD2ZiplBWA+8YQB/kk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: ianawww.vip.icann.org

ianawww.vip.icann.org
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "mn05h9vobh4dorkv6pp3bqkfti1hkuge" between the hashed NSEC3-owner "mn05h9vobh4dorkv6pp3bqkfti1hkuge" and the hashed NextOwner "mn05h9vobh4dorkv6pp3bqkfti1hkugf". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, RRSIG Validated: RRSIG-Owner mn05h9vobh4dorkv6pp3bqkfti1hkuge.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:22:06 +, Signature-Inception: 14.01.2025, 03:22:06 +, KeyTag 2253, Signer-Name: vip.icann.org






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "mn05h9vobh4dorkv6pp3bqkfti1hkuge" between the hashed NSEC3-owner "mn05h9vobh4dorkv6pp3bqkfti1hkuge" and the hashed NextOwner "mn05h9vobh4dorkv6pp3bqkfti1hkugf". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, RRSIG Validated: RRSIG-Owner mn05h9vobh4dorkv6pp3bqkfti1hkuge.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:22:06 +, Signature-Inception: 14.01.2025, 03:22:06 +, KeyTag 53541, Signer-Name: vip.icann.org






0 DNSKEY RR found












RRSIG Type 1 validates the A - Result: 192.0.46.8
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 20.01.2025, 08:11:53 +, Signature-Inception: 13.01.2025, 07:11:53 +, KeyTag 2253, Signer-Name: vip.icann.org






RRSIG Type 1 validates the A - Result: 192.0.46.8
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 20.01.2025, 08:11:53 +, Signature-Inception: 13.01.2025, 07:11:53 +, KeyTag 2253, Signer-Name: vip.icann.org






RRSIG Type 28 validates the AAAA - Result: 2620:0000:2830:0200:0000:0000:000B:0008
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 20.01.2025, 08:11:54 +, Signature-Inception: 13.01.2025, 07:11:54 +, KeyTag 2253, Signer-Name: vip.icann.org






RRSIG Type 28 validates the AAAA - Result: 2620:0000:2830:0200:0000:0000:000B:0008
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 20.01.2025, 08:11:54 +, Signature-Inception: 13.01.2025, 07:11:54 +, KeyTag 2253, Signer-Name: vip.icann.org






RRSIG Type 1 validates the A - Result: 192.0.46.8
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 53541, Signer-Name: vip.icann.org






RRSIG Type 1 validates the A - Result: 192.0.46.8
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 53541, Signer-Name: vip.icann.org






RRSIG Type 28 validates the AAAA - Result: 2620:0000:2830:0200:0000:0000:000B:0008
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 53541, Signer-Name: vip.icann.org






RRSIG Type 28 validates the AAAA - Result: 2620:0000:2830:0200:0000:0000:000B:0008
Validated: RRSIG-Owner ianawww.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 30 sec, Signature-expiration: 17.01.2025, 00:11:33 +, Signature-Inception: 09.01.2025, 23:11:33 +, KeyTag 53541, Signer-Name: vip.icann.org






CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "idf0su2t1ptr1ebfro6o9l2jn0rh4p4c" equal the hashed NSEC3-owner "idf0su2t1ptr1ebfro6o9l2jn0rh4p4c" and the hashed NextOwner "idf0su2t1ptr1ebfro6o9l2jn0rh4p4d". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner idf0su2t1ptr1ebfro6o9l2jn0rh4p4c.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:26:26 +, Signature-Inception: 14.01.2025, 03:26:26 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NoData-Proof required and found.






TXT-Query sends a valid NSEC3 RR as result with the hashed query name "idf0su2t1ptr1ebfro6o9l2jn0rh4p4c" equal the hashed NSEC3-owner "idf0su2t1ptr1ebfro6o9l2jn0rh4p4c" and the hashed NextOwner "idf0su2t1ptr1ebfro6o9l2jn0rh4p4d". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, 13, MX, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner idf0su2t1ptr1ebfro6o9l2jn0rh4p4c.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:33:14 +, Signature-Inception: 14.01.2025, 03:33:14 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.ianawww.vip.icann.org) sends a valid NSEC3 RR as result with the hashed owner name "os86ngm0d6fn9rvg2jon3ksfbtaktsnf" (unhashed: _tcp.ianawww.vip.icann.org). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner os86ngm0d6fn9rvg2jon3ksfbtaktsnf.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:33:13 +, Signature-Inception: 14.01.2025, 03:33:13 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NXDomain-Proof required and found.






TLSA-Query (_443._tcp.ianawww.vip.icann.org) sends a valid NSEC3 RR as result with the hashed query name "3k27v5bt1mv94ugs4n1p3gcvtnv6ev3m" between the hashed NSEC3-owner "3k27v5bt1mv94ugs4n1p3gcvtnv6ev3l" and the hashed NextOwner "3k27v5bt1mv94ugs4n1p3gcvtnv6ev3n". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner 3k27v5bt1mv94ugs4n1p3gcvtnv6ev3l.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:33:13 +, Signature-Inception: 14.01.2025, 03:33:13 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NXDomain-Proof required and found.






TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "4h5jc41rkfvsucv2m7ehdno4130mqh1k" (unhashed: *._tcp.ianawww.vip.icann.org) with the owner "4h5jc41rkfvsucv2m7ehdno4130mqh1j" and the NextOwner "4h5jc41rkfvsucv2m7ehdno4130mqh1l". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: No Bitmap? Validated: RRSIG-Owner 4h5jc41rkfvsucv2m7ehdno4130mqh1j.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:33:13 +, Signature-Inception: 14.01.2025, 03:33:13 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NXDomain-Proof required and found.






CAA-Query sends a valid NSEC3 RR as result with the hashed query name "mn05h9vobh4dorkv6pp3bqkfti1hkuge" equal the hashed NSEC3-owner "mn05h9vobh4dorkv6pp3bqkfti1hkuge" and the hashed NextOwner "mn05h9vobh4dorkv6pp3bqkfti1hkugf". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner mn05h9vobh4dorkv6pp3bqkfti1hkuge.vip.icann.org., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 21.01.2025, 04:22:02 +, Signature-Inception: 14.01.2025, 03:22:02 +, KeyTag 53541, Signer-Name: vip.icann.org






Status: Good. NoData-Proof required and found.

 

3. Name Servers

DomainNameserverNS-IP
iana.org
  a.iana-servers.net / iad.aservers.dns.icann.org
199.43.135.53
Washington/District of Columbia/United States (US) - ICANN


 
2001:500:8f::53
Los Angeles/California/United States (US) - ICANN


  b.iana-servers.net / iad.bservers.dns.icann.org
199.43.133.53
Washington/District of Columbia/United States (US) - ICANN


 
2001:500:8d::53
Los Angeles/California/United States (US) - ICANN


  c.iana-servers.net / app5.ams2.hosts.meta.redstone.afilias-nst.info-1615580861
199.43.134.53
Miami/Florida/United States (US) - Afilias, Inc.


 
2001:500:8e::53
Sterling/Virginia/United States (US) - Afilias, Inc.


  ns.icann.org / iad.nsicann.dns.icann.org
199.4.138.53
Los Angeles/California/United States (US) - ICANN


 
2001:500:89::53
Los Angeles/California/United States (US) - ICANN


T  sns.dns.icann.org
192.0.32.162
Los Angeles/California/United States (US) - ICANN

org
  a0.org.afilias-nst.info / app12.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  a2.org.afilias-nst.info / FRA3


  b0.org.afilias-nst.org / app5.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  b2.org.afilias-nst.org / FRA3


T  c0.org.afilias-nst.info / app11.nrt1.hosts.meta.redstone.afilias-nst.info-1615580861


  d0.org.afilias-nst.org / app11.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


ianawww.vip.icann.org
  gtm1.lax.icann.org
192.0.32.252
Los Angeles/California/United States (US) - ICANN


 
2620:0:2d0:296::252
Los Angeles/California/United States (US) - ICANN

vip.icann.org
  gtm1.dc.icann.org
192.0.47.252
Washington/District of Columbia/United States (US) - ICANN


 
2620:0:2830:296::252
Los Angeles/California/United States (US) - ICANN


  gtm1.lax.icann.org
192.0.32.252
Los Angeles/California/United States (US) - ICANN


 
2620:0:2d0:296::252
Los Angeles/California/United States (US) - ICANN


  gtm1.mdr.icann.org
192.0.36.252
Anchorage/Alaska/United States (US) - ICANN


 
2620:0:2ed0:296::252
Los Angeles/California/United States (US) - ICANN

icann.org
  a.icann-servers.net / iad.aservers.dns.icann.org
199.43.135.53
Washington/District of Columbia/United States (US) - ICANN


 
2001:500:8f::53
Los Angeles/California/United States (US) - ICANN


  b.icann-servers.net / iad.bservers.dns.icann.org
199.43.133.53
Washington/District of Columbia/United States (US) - ICANN


 
2001:500:8d::53
Los Angeles/California/United States (US) - ICANN


  c.icann-servers.net / app3.ams2.hosts.meta.redstone.afilias-nst.info-1615580861
199.43.134.53
Miami/Florida/United States (US) - Afilias, Inc.


 
2001:500:8e::53
Sterling/Virginia/United States (US) - Afilias, Inc.


  ns.icann.org / iad.nsicann.dns.icann.org
199.4.138.53
Los Angeles/California/United States (US) - ICANN


 
2001:500:89::53
Los Angeles/California/United States (US) - ICANN


  sns.dns.icann.org

org
  a0.org.afilias-nst.info / app6.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  a2.org.afilias-nst.info / FRA4


  b0.org.afilias-nst.org / app8.ams2.hosts.meta.redstone.afilias-nst.info-1615580861


  b2.org.afilias-nst.org / FRA6


  c0.org.afilias-nst.info / app6.nrt1.hosts.meta.redstone.afilias-nst.info-1615580861


  d0.org.afilias-nst.org / app8.ams2.hosts.meta.redstone.afilias-nst.info-1615580861

 

4. SOA-Entries


Domain:org
Zone-Name:org
Primary:a0.org.afilias-nst.info
Mail:hostmaster.donuts.email
Serial:1736828509
Refresh:7200
Retry:900
Expire:1209600
TTL:3600
num Entries:6


Domain:iana.org
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:iana.org
Zone-Name:iana.org
Primary:sns.dns.icann.org
Mail:noc.dns.icann.org
Serial:2025011010
Refresh:7200
Retry:3600
Expire:1209600
TTL:3600
num Entries:8



Domain:org
Zone-Name:org
Primary:a0.org.afilias-nst.info
Mail:hostmaster.donuts.email
Serial:1736828509
Refresh:7200
Retry:900
Expire:1209600
TTL:3600
num Entries:6


Domain:icann.org
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:icann.org
Zone-Name:icann.org
Primary:sns.dns.icann.org
Mail:noc.dns.icann.org
Serial:2025011303
Refresh:10800
Retry:3600
Expire:1209600
TTL:3600
num Entries:8


Domain:vip.icann.org
Zone-Name:vip.icann.org
Primary:gtm1.lax.icann.org
Mail:hostmaster.gtm1.lax.icann.org
Serial:2025010910
Refresh:10800
Retry:3600
Expire:604800
TTL:60
num Entries:6


Domain:ianawww.vip.icann.org
Zone-Name:vip.icann.org
Primary:gtm1.lax.icann.org
Mail:hostmaster.gtm1.lax.icann.org
Serial:2025010910
Refresh:10800
Retry:3600
Expire:604800
TTL:60
num Entries:2


5. Screenshots

Startaddress: https://www.iana.org/, address used: https://www.iana.org/, Screenshot created 2025-01-14 05:41:02 +00:0

 

Mobil (412px x 732px)

 

1048 milliseconds

 

Screenshot mobile - https://www.iana.org/
Mobil + Landscape (732px x 412px)

 

1053 milliseconds

 

Screenshot mobile landscape - https://www.iana.org/
Screen (1280px x 1680px)

 

1174 milliseconds

 

Screenshot Desktop - https://www.iana.org/

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport396732
content Size3961278

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://iana.org/
192.0.43.8
301
https://www.iana.org/
Html is minified: 103.15 %
0.660
E
Date: Tue, 14 Jan 2025 04:34:12 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:12 GMT
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

• http://iana.org/
2001:500:88:200::8
301
https://www.iana.org/
Html is minified: 103.15 %
0.230
E
Date: Tue, 14 Jan 2025 04:34:12 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:12 GMT
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

• http://www.iana.org/
192.0.46.8 br used - 1182 / 6173 - 80.85 %
200

Html is minified: 160.50 %
0.240
H
Date: Tue, 14 Jan 2025 04:33:55 GMT
Server: Apache
Vary: Accept-Encoding
X-Frame-Options: DENY
X-Content-Type-Options: nosniff,nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Age: 96
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Last-Modified: Fri, 09 Jun 2023 00:31:13 GMT
Expires: Tue, 14 Jan 2025 05:32:36 GMT
Content-Encoding: br
Content-Length: 1182
Content-Type: text/html; charset=UTF-8

• http://www.iana.org/
2620:0:2830:200::b:8 br used - 1182 / 6173 - 80.85 %
200

Html is minified: 160.50 %
0.243
H
Date: Tue, 14 Jan 2025 04:33:36 GMT
Server: Apache
Vary: Accept-Encoding
X-Frame-Options: DENY
X-Content-Type-Options: nosniff,nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Age: 96
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Last-Modified: Fri, 09 Jun 2023 00:31:13 GMT
Expires: Tue, 14 Jan 2025 05:32:36 GMT
Content-Encoding: br
Content-Length: 1182
Content-Type: text/html; charset=UTF-8

• https://iana.org/
192.0.43.8
301
https://www.iana.org/
Html is minified: 103.15 %
5.440
B
Date: Tue, 14 Jan 2025 04:34:13 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:13 GMT
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

• https://iana.org/
2001:500:88:200::8
301
https://www.iana.org/
Html is minified: 103.15 %
5.563
B
Date: Tue, 14 Jan 2025 04:34:20 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:20 GMT
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

• https://www.iana.org/
192.0.46.8 br used - 1182 / 6173 - 80.85 %
Inline-JavaScript (∑/total): 1/339 Inline-CSS (∑/total): 0/0
200

Html is minified: 160.50 %
Other inline scripts (∑/total): 0/0
5.323
A
Date: Tue, 14 Jan 2025 04:33:36 GMT
Server: Apache
Vary: Accept-Encoding
X-Frame-Options: DENY
X-Content-Type-Options: nosniff,nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Age: 110
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Strict-Transport-Security: max-age=48211200; preload
Last-Modified: Fri, 09 Jun 2023 00:31:13 GMT
Expires: Tue, 14 Jan 2025 05:32:36 GMT
Content-Encoding: br
Content-Length: 1182
Content-Type: text/html; charset=UTF-8

• https://www.iana.org/
2620:0:2830:200::b:8 br used - 1182 / 6173 - 80.85 %
Inline-JavaScript (∑/total): 1/339 Inline-CSS (∑/total): 0/0
200

Html is minified: 160.50 %
Other inline scripts (∑/total): 0/0
4.327
A
Date: Tue, 14 Jan 2025 04:33:36 GMT
Server: Apache
Vary: Accept-Encoding
X-Frame-Options: DENY
X-Content-Type-Options: nosniff,nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Age: 117
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Strict-Transport-Security: max-age=48211200; preload
Last-Modified: Fri, 09 Jun 2023 00:31:13 GMT
Expires: Tue, 14 Jan 2025 05:32:36 GMT
Content-Encoding: br
Content-Length: 1182
Content-Type: text/html; charset=UTF-8

• http://iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
192.0.43.8
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 102.41 %
Other inline scripts (∑/total): 0/0
0.240
E
Visible Content:
Date: Tue, 14 Jan 2025 04:34:40 GMT
Server: Apache
Location: https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:40 GMT
Content-Length: 298
Content-Type: text/html; charset=iso-8859-1

• http://iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2001:500:88:200::8
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 102.41 %
Other inline scripts (∑/total): 0/0
0.840
E
Visible Content:
Date: Tue, 14 Jan 2025 04:34:41 GMT
Server: Apache
Location: https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:41 GMT
Content-Length: 298
Content-Type: text/html; charset=iso-8859-1

• http://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
192.0.46.8
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 148.58 %
Other inline scripts (∑/total): 0/0
0.260
A
Not Found
Visible Content:
Date: Tue, 14 Jan 2025 04:34:43 GMT
Server: Apache
X-Content-Type-Options: nosniff,nosniff
Vary: Accept-Encoding
X-Frame-Options: DENY
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Content-Length: 3924
Content-Type: text/html; charset=utf-8

• http://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2620:0:2830:200::b:8
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 148.58 %
Other inline scripts (∑/total): 0/0
0.254
A
Not Found
Visible Content:
Date: Tue, 14 Jan 2025 04:34:44 GMT
Server: Apache
X-Content-Type-Options: nosniff,nosniff
Vary: Accept-Encoding
X-Frame-Options: DENY
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Content-Length: 3924
Content-Type: text/html; charset=utf-8

• https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 148.58 %
Other inline scripts (∑/total): 0/0
5.000
A
Not Found
Visible Content:
Date: Tue, 14 Jan 2025 04:35:10 GMT
Server: Apache
X-Content-Type-Options: nosniff,nosniff
Vary: Accept-Encoding
X-Frame-Options: DENY
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, max-age=3600
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Strict-Transport-Security: max-age=48211200; preload
Content-Length: 3924
Content-Type: text/html; charset=utf-8

• https://192.0.43.8/
192.0.43.8
302
https://www.iana.org/
Html is minified: 103.54 %
5.400
N
Certificate error: RemoteCertificateNameMismatch
Date: Tue, 14 Jan 2025 04:34:45 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:45 GMT
Content-Length: 205
Content-Type: text/html; charset=iso-8859-1

• https://192.0.46.8/
192.0.46.8
301
https://www.iana.org/
Html is minified: 103.15 %
5.340
N
Certificate error: RemoteCertificateNameMismatch
Date: Tue, 14 Jan 2025 04:34:57 GMT
Server: Apache
Location: https://www.iana.org/
Strict-Transport-Security: max-age=48211200; preload
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

• https://[2001:0500:0088:0200:0000:0000:0000:0008]/
2001:500:88:200::8
302
https://www.iana.org/
Html is minified: 103.54 %
5.073
N
Certificate error: RemoteCertificateNameMismatch
Date: Tue, 14 Jan 2025 04:34:51 GMT
Server: Apache
Location: https://www.iana.org/
Cache-Control: max-age=345600
Expires: Sat, 18 Jan 2025 04:34:51 GMT
Content-Length: 205
Content-Type: text/html; charset=iso-8859-1

• https://[2620:0000:2830:0200:0000:0000:000b:0008]/
2620:0:2830:200::b:8
301
https://www.iana.org/
Html is minified: 103.15 %
4.857
N
Certificate error: RemoteCertificateNameMismatch
Date: Tue, 14 Jan 2025 04:35:04 GMT
Server: Apache
Location: https://www.iana.org/
Strict-Transport-Security: max-age=48211200; preload
Content-Length: 229
Content-Type: text/html; charset=iso-8859-1

 

7. Comments


1. General Results, most used to calculate the result

Aname "iana.org" is domain, public suffix is ".org", top-level-domain is ".org", top-level-domain-type is "generic", tld-manager is "Public Interest Registry (PIR)", num .org-domains preloaded: 9857 (complete: 263653)
AGood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: iana.org has 2 different ip addresses (authoritative).
AGood: Minimal 2 ip addresses per domain name found: www.iana.org has 2 different ip addresses (authoritative).
AGood: Ipv4 and Ipv6 addresses per domain name found: iana.org has 1 ipv4, 1 ipv6 addresses
AGood: Ipv4 and Ipv6 addresses per domain name found: www.iana.org has 1 ipv4, 1 ipv6 addresses
AGood: No asked Authoritative Name Server had a timeout
Ahttps://192.0.46.8/ 192.0.46.8
301
https://www.iana.org/
Correct redirect https to https
Ahttps://192.0.46.8/ 192.0.46.8
301
https://www.iana.org/
Correct redirect https to https
Ahttps://[2620:0000:2830:0200:0000:0000:000b:0008]/ 2620:0:2830:200::b:8
301
https://www.iana.org/
Correct redirect https to https
Ahttps://[2620:0000:2830:0200:0000:0000:000b:0008]/ 2620:0:2830:200::b:8
301
https://www.iana.org/
Correct redirect https to https
AGood: one preferred version: www is preferred
AGood: No cookie sent via http.
Warning: HSTS preload sent, but not in Preload-List. Never send a preload directive if you don't know what preload means. Check https://hstspreload.org/ to learn the basics about the Google-Preload list. If you send a preload directive, you should **immediately** add your domain to the HSTS preload list via https://hstspreload.org/ . If Google accepts the domain, so the status is "pending": Note that new entries are hardcoded into the Chrome source code and can take several months before they reach the stable version. So you will see this message some months. If you don't want that or if you don't understand "preload", but if you send a preload directive and if you have correct A-redirects, everybody can add your domain to that list. Then you may have problems, it's not easy to undo that. So if you don't want your domain preloaded, remove the preload directive.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: All urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset)
Bhttps://iana.org/ 192.0.43.8
301

Missing HSTS-Header
Bhttps://iana.org/ 2001:500:88:200::8
301

Missing HSTS-Header
Ehttp://iana.org/ 192.0.43.8
301
https://www.iana.org/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Ehttp://iana.org/ 2001:500:88:200::8
301
https://www.iana.org/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
HFatal error: http result with http-status 200, no encryption. Add a redirect http ⇒ https, so every connection is secure. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop.
Nhttps://192.0.43.8/ 192.0.43.8
302
https://www.iana.org/
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://[2001:0500:0088:0200:0000:0000:0000:0008]/ 2001:500:88:200::8
302
https://www.iana.org/
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://192.0.46.8/ 192.0.46.8
301
https://www.iana.org/
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://[2620:0000:2830:0200:0000:0000:000b:0008]/ 2620:0:2830:200::b:8
301
https://www.iana.org/
Error - Certificate isn't trusted, RemoteCertificateNameMismatch
XFatal error: Nameserver doesn't support TCP connection: sns.dns.icann.org / 192.0.32.162: Timeout
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain iana.org, 2 ip addresses.
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain www.iana.org, 2 ip addresses.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain iana.org, 2 ip addresses, 1 different http results.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are the same. So that domain doesn't require Server Name Indication (SNI), it's the primary certificate of that set of ip addresses.: Domain www.iana.org, 2 ip addresses, 1 different http results.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.iana.org

2. Header-Checks

Awww.iana.org 192.0.46.8
Content-Security-Policy
Ok: Header without syntax errors found: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
A

Good: default-src without 'unsafe-inline' or 'unsave-eval'.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
E

Bad: No frame-ancestors directive found. Use one to limit the pages allowed to use this page in frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
E

Bad: No base-uri directive found. Use one to limit the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
E

Critical: No object-src defined, the default-src used as fallback allows too much. object / embed / applet shouldn't be able to load these resources.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A

Good: frame-src without data: defined or frame-src missing and the default-src used as fallback not allows the data: schema. That blocks hidden code injection. Insert <iframe src="data:text/html;charset=utf-8;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGJvZHk+PHA+YmVmb3JlPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPmFsZXJ0KCdYU1MnKTwvc2NyaXB0PjxwPmFmdGVyPC9ib2R5PjwvaHRtbD4="></iframe> in your page and see what happens.
F
X-Content-Type-Options
Critical: Header with syntax errors found: nosniff,nosniff
F

Critical: Duplicated values found. Looks like the page sends multiple headers with the same name. nosniff,nosniff
F

Critical: Unknown token found. Standard-token with additional characters are not defined. nosniff,nosniff
F

Critical: Unknown token found. Standard-token with additional characters are not defined. nosniff,nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
X-Frame-Options
Ok: Header without syntax errors found: DENY
B

Info: Header is deprecated. May not longer work in modern browsers. DENY. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
Cross-Origin-Opener-Policy
Ok: Header without syntax errors found: same-origin
Awww.iana.org 2620:0:2830:200::b:8
Content-Security-Policy
Ok: Header without syntax errors found: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
A

Good: default-src without 'unsafe-inline' or 'unsave-eval'.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
E

Bad: No frame-ancestors directive found. Use one to limit the pages allowed to use this page in frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
E

Bad: No base-uri directive found. Use one to limit the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
E

Critical: No object-src defined, the default-src used as fallback allows too much. object / embed / applet shouldn't be able to load these resources.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A

Good: frame-src without data: defined or frame-src missing and the default-src used as fallback not allows the data: schema. That blocks hidden code injection. Insert <iframe src="data:text/html;charset=utf-8;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGJvZHk+PHA+YmVmb3JlPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPmFsZXJ0KCdYU1MnKTwvc2NyaXB0PjxwPmFmdGVyPC9ib2R5PjwvaHRtbD4="></iframe> in your page and see what happens.
F
X-Content-Type-Options
Critical: Header with syntax errors found: nosniff,nosniff
F

Critical: Duplicated values found. Looks like the page sends multiple headers with the same name. nosniff,nosniff
F

Critical: Unknown token found. Standard-token with additional characters are not defined. nosniff,nosniff
F

Critical: Unknown token found. Standard-token with additional characters are not defined. nosniff,nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
X-Frame-Options
Ok: Header without syntax errors found: DENY
B

Info: Header is deprecated. May not longer work in modern browsers. DENY. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
Cross-Origin-Opener-Policy
Ok: Header without syntax errors found: same-origin
Fwww.iana.org 192.0.46.8
Permissions-Policy
Critical: Missing Header:
Bwww.iana.org 192.0.46.8
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.iana.org 192.0.46.8
Cross-Origin-Resource-Policy
Info: Missing Header
Fwww.iana.org 2620:0:2830:200::b:8
Permissions-Policy
Critical: Missing Header:
Bwww.iana.org 2620:0:2830:200::b:8
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.iana.org 2620:0:2830:200::b:8
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 8 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 5 Name Servers.
AInfo:: 8 Queries complete, 8 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.a.iana-servers.net (199.43.135.53, 2001:500:8f::53), ns.icann.org (199.4.138.53, 2001:500:89::53), b.iana-servers.net (199.43.133.53, 2001:500:8d::53), c.iana-servers.net (199.43.134.53, 2001:500:8e::53), ns.icann.org (199.4.138.53, 2001:500:89::53)
AGood (1 - 3.0):: An average of 1.6 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 5 different Name Servers found: a.iana-servers.net, b.iana-servers.net, c.iana-servers.net, ns.icann.org, sns.dns.icann.org, 4 Name Servers included in Delegation: a.iana-servers.net, b.iana-servers.net, c.iana-servers.net, ns.icann.org, 4 Name Servers included in 2 Zone definitions: a.iana-servers.net, b.iana-servers.net, c.iana-servers.net, ns.icann.org, 1 Name Servers listed in SOA.Primary: sns.dns.icann.org.
AGood: Only one SOA.Primary Name Server found.: sns.dns.icann.org.
Error: SOA.Primary Name Server not included in the delegation set.: sns.dns.icann.org.
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 5 different Name Servers found
AGood: Some Name Servers have IPv6 addresses: 4 Name Servers with IPv6 found (1 Name Servers without IPv6)
AGood: Name servers with different Top Level Domains / Public Suffix List entries found: 5 Name Servers, 2 Top Level Domains: org, net
AGood: Name Servers with different domain names found.: 2 different Domains found
Warning: All Name Servers from the same Country / IP location.: 5 Name Servers, 1 Countries: US
AInfo: Ipv4-Subnet-list: 5 Name Servers, 2 different subnets (first Byte): 192., 199., 3 different subnets (first two Bytes): 192.0., 199.4., 199.43., 5 different subnets (first three Bytes): 192.0.32., 199.4.138., 199.43.133., 199.43.134., 199.43.135.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 4 Name Servers with IPv6, 1 different subnets (first block): 2001:, 1 different subnets (first two blocks): 2001:0500:, 4 different subnets (first three blocks): 2001:0500:0089:, 2001:0500:008d:, 2001:0500:008e:, 2001:0500:008f:, 4 different subnets (first four blocks): 2001:0500:0089:0000:, 2001:0500:008d:0000:, 2001:0500:008e:0000:, 2001:0500:008f:0000:
AGood: Name Server IPv6 addresses from different subnets found.
AInfo: Nameserver mit different domain names found. May be a problem with DNS-Updates
XNameserver Timeout checking Echo Capitalization: sns.dns.icann.org / 192.0.32.162
XNameserver Timeout checking EDNS512: c0.org.afilias-nst.info
XNameserver Timeout checking EDNS512: sns.dns.icann.org / 192.0.32.162
Nameserver doesn't pass all EDNS-Checks: a2.org.afilias-nst.info: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found (FRA3). COOKIE: ok. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: sns.dns.icann.org: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: sns.dns.icann.org / 192.0.32.162: OP100: fatal timeout. FLAGS: fatal timeout. V1: fatal timeout. V1OP100: fatal timeout. V1FLAGS: fatal timeout. DNSSEC: fatal timeout. V1DNSSEC: fatal timeout. NSID: fatal timeout. COOKIE: fatal timeout. CLIENTSUBNET: fatal timeout.
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://www.iana.org/ 192.0.46.8
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://www.iana.org/ 2620:0:2830:200::b:8
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://www.iana.org/ 192.0.46.8
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://www.iana.org/ 2620:0:2830:200::b:8
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://www.iana.org/ 192.0.46.8
200

Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
https://www.iana.org/ 2620:0:2830:200::b:8
200

Warning: Https connections (Standard Port 443) found without support of the http/2 protocol via ALPN. Http/2 is the new Http-Version (old: http 1.1) with some important new features. Update your server software so http/2 is available. Only one TCP-connection per Server (that's a performance boost), Header-Compression and Server Pushs are available. Domain Sharding and Inline-CSS/Javascript shouldn't used with http/2.
https://www.iana.org/ 192.0.46.8
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 2 script elements without defer/async.
https://www.iana.org/ 2620:0:2830:200::b:8
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 2 script elements without defer/async.
http://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 192.0.46.8
404

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 2 script elements without defer/async.
http://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2620:0:2830:200::b:8
404

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 2 script elements without defer/async.
https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 2 script elements without defer/async.
AGood: All CSS / JavaScript files are sent compressed (gzip, deflate, br checked). That reduces the content of the files. 10 external CSS / JavaScript files found
AGood: All svg-Images greater 1024 Bytes without internal compression are compressed. Svg is an Xml-Application, so Compression reduces the size of the file. 3 images (type image/svg+xml, image/x-icon, image/vnd.microsoft.icon) found with compression.
AGood: All CSS / JavaScript files are sent with a long Cache-Control header (minimum 7 days). So the browser can re-use these files, no download is required. 15 external CSS / JavaScript files with long Cache-Control max-age found
AGood: All images are sent with a long Cache-Control header (minimum 7 days). So the browser can reuse these files, no download is required. 3 image files with long Cache-Control max-age found
AGood: All checked attribute values are enclosed in quotation marks (" or ').
AGood: All img-elements have a valid alt-attribute.: 3 img-elements found.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://www.iana.org/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
5.000 seconds
Warning: 404 needs more then one second
ADuration: 649356 milliseconds, 649.356 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
iana.org
192.0.43.8
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
iana.org
192.0.43.8
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


iana.org
2001:500:88:200::8
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

iana.org
2001:500:88:200::8
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


www.iana.org
192.0.46.8
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

www.iana.org
192.0.46.8
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


www.iana.org
2620:0:2830:200::b:8
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

www.iana.org
2620:0:2830:200::b:8
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


www.iana.org
www.iana.org
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

www.iana.org
www.iana.org
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


192.0.43.8
192.0.43.8
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

192.0.43.8
192.0.43.8
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


192.0.46.8
192.0.46.8
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

192.0.46.8
192.0.46.8
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


[2001:0500:0088:0200:0000:0000:0000:0008]
2001:500:88:200::8
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

[2001:0500:0088:0200:0000:0000:0000:0008]
2001:500:88:200::8
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey


[2620:0000:2830:0200:0000:0000:000b:0008]
2620:0:2830:200::b:8
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok

[2620:0000:2830:0200:0000:0000:000b:0008]
2620:0:2830:200::b:8
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
not supported
ok
no http/2 via ALPN 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
no http/2 via ALPN
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, C=US, ST=California


2CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester


3CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, C=US, ST=New Jersey

 

9. Certificates

1.
1.
CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, S=California, C=US
06.12.2024
06.01.2026
expires in 204 days
*.iana.org, iana.org - 2 entries
1.
1.
CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, S=California, C=US
06.12.2024

06.01.2026
expires in 204 days


*.iana.org, iana.org - 2 entries

KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:008D0890662012FA172B1E7265B9A58722
Thumbprint:4A61BA8336F80B38FAD16A77A72B7446171217AF
SHA256 / Certificate:GEx6a+KLxhUaGOlVeJ6oDPB+3DUHZX9BZY8AnRV/fn4=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):d56f85824b6ed2ab15b9040c20b574515d9a0ab415ca253b42cbc915a11de18d
SHA256 hex / Subject Public Key Information (SPKI):d56f85824b6ed2ab15b9040c20b574515d9a0ab415ca253b42cbc915a11de18d (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, S=California, C=US
06.12.2024
06.01.2026
expires in 204 days
*.iana.org, iana.org - 2 entries

2.
CN=*.iana.org, O=Internet Corporation For Assigned Names and Numbers, S=California, C=US
06.12.2024

06.01.2026
expires in 204 days


*.iana.org, iana.org - 2 entries

KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:008D0890662012FA172B1E7265B9A58722
Thumbprint:4A61BA8336F80B38FAD16A77A72B7446171217AF
SHA256 / Certificate:GEx6a+KLxhUaGOlVeJ6oDPB+3DUHZX9BZY8AnRV/fn4=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):d56f85824b6ed2ab15b9040c20b574515d9a0ab415ca253b42cbc915a11de18d
SHA256 hex / Subject Public Key Information (SPKI):d56f85824b6ed2ab15b9040c20b574515d9a0ab415ca253b42cbc915a11de18d (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.sectigo.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 2025 days


3.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 2025 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):72a34ac2b424aed3f6b0b04755b88cc027dccc806fddb22b4cd7c47773973ec0
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018
01.01.2031
expires in 2025 days


4.
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
02.11.2018

01.01.2031
expires in 2025 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:137D539CAA7C31A9A433701968847A8D
Thumbprint:40CEF3046C916ED7AE557F60E76842828B51DE53
SHA256 / Certificate:cqNKwrQkrtP2sLBHVbiMwCfczIBv3bIrTNfEd3OXPsA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SHA256 hex / Subject Public Key Information (SPKI):4648564dc7c901037f631391d765643e8f8f86622849f59dfc9564838e1e8a76
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.usertrust.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010
19.01.2038
expires in 4600 days


5.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
01.02.2010

19.01.2038
expires in 4600 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:01FD6D30FCA3CA51A81BBC640E35032D
Thumbprint:2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
SHA256 / Certificate:55PJsC/YqhPiHDEiisywgRlkO3SciYlksXRtRsPUy9I=
SHA256 hex / Cert (DANE * 0 1):e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019
01.01.2029
expires in 1295 days


6.
CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US
12.03.2019

01.01.2029
expires in 1295 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA384 With RSA Encryption
Serial Number:3972443AF922B751D7D36C10DD313595
Thumbprint:D89E3BD43D5D909B47A18977AA9D5CE36CEE184C
SHA256 / Certificate:aLnHYSGaWx8BMXhEdGZdthu9sQngDwXKn3QkTuX19Ss=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SHA256 hex / Subject Public Key Information (SPKI):c784333d20bcd742b9fdc3236f4e509b8937070e73067e254dd3bf9c45bf4dde
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.comodoca.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004
01.01.2029
expires in 1295 days


7.
CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB
01.01.2004

01.01.2029
expires in 1295 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:01
Thumbprint:D1EB23A46D17D68FD92564C2F1F1601764D8E349
SHA256 / Certificate:16eg+11+JzHXcelITrze9x1fDD4KKUh4K8g+4OppnvQ=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SHA256 hex / Subject Public Key Information (SPKI):bd153ed7b0434f6886b17bce8bbe84ed340c7132d702a8f4fa318f756ecbd6f3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
1
2
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
1
CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
0
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
8858404930
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2024-12-06 00:00:00
2026-01-05 23:59:59
*.iana.org, iana.org - 2 entries


7133335212
leaf cert
CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2024-04-15 00:00:00
2024-07-14 23:59:59
iana.org, www.iana.org - 2 entries


6315258489
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2023-12-05 00:00:00
2025-01-03 23:59:59
*.iana.org, iana.org - 2 entries


4542097464
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2022-12-12 00:00:00
2024-01-12 23:59:59
*.iana.org, iana.org - 2 entries


 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Issuerlast 7 daysactivenum Certs
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
1
2
CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
0
0
1
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
1

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
15643910423
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2024-12-05 23:00:00
2026-01-05 22:59:59
*.iana.org, iana.org
2 entries


12735413039
precert
CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2024-04-14 22:00:00
2024-07-14 21:59:59
iana.org, www.iana.org
2 entries


11327610078
leaf cert
CN=Sectigo RSA Organization Validation Secure Server CA, O=Sectigo Limited, L=Salford, C=GB, ST=Greater Manchester
2023-12-04 23:00:00
2025-01-03 22:59:59
*.iana.org, iana.org
2 entries


8915956011
leaf cert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2022-12-11 23:00:00
2024-01-12 22:59:59
*.iana.org, iana.org
2 entries


 

11. Html-Content - Entries

Summary


Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://www.iana.org/
192.0.46.8
a

34

0


0
0
0


link
stylesheet
1
7,595 Bytes
0
1
0
0
0
0


link
other
2
7,406 Bytes
0
1
0
0
0
0


meta
other
3

0


0
0
0


script

2
28,713 Bytes
0
2
0
0
0
0

https://www.iana.org/
2620:0:2830:200::b:8
a

34

0


0
0
0


link
stylesheet
1
7,595 Bytes
0
1
0
0
0
0


link
other
2
7,406 Bytes
0
1
0
0
0
0


meta
other
3

0


0
0
0


script

2
28,501 Bytes
0
2
0
0
0
0

 

Details (currently limited to 500 rows - some problems with spam users)

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://www.iana.org/
192.0.46.8
a

/about


1
ok















a

/about/excellence


1
ok















a

/abuse


2
ok















a

/contact


1
ok















a

/domains


2
ok















a

/domains/arpa


2
ok















a

/domains/idn-tables


2
ok















a

/domains/int


2
ok















a

/domains/root


2
ok















a

/domains/root/db


1
ok















a

/numbers


3
ok















a

/performance


1
ok















a

/protocols


4
ok















a

/protocols/apply


1
ok















a

/reports


1
ok















a

/reviews


1
ok















a

/time-zones


2
ok















a

about/


1
ok















a

http://pti.icann.org


1
ok















a

http://www.icann.org/


1
ok















a

https://www.icann.org/privacy/policy


1
ok















a

https://www.icann.org/privacy/tos


1
ok















link
canonical
https://iana.org/


1
ok















link
shortcut icon
/_img/bookmark_icon.ico
200

1
ok
image/vnd.microsoft.icon
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 with long duration found.
No Compression - 7406 Bytes








link
stylesheet
/_css/2022/iana_website.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
Compression (br): 7595/42327 Bytes






local SRI possible, possible hash-values:

 

sha256-mql12eeShHulRBETqjSqKrC3onSz+1u1tp+bSsh8Yb8=
sha384-/8Zbwg4qxM9Qed+EOWAZhkHzQlFUTGtTMa80Z+RHL9O3C2a17TgrdPkuVotr5KvY
sha512-74p2h2NmIb3ANX0oxpYjfyPJo1FzjUQgIVacdtRWSDTir0ZkwjpMbnrNIvSSveiCBfnI/CJmWZVhLhX2SnKTxQ==

 

<link rel="stylesheet" href="/_css/2022/iana_website.css" crossorigin="anonymous" integrity="sha256-mql12eeShHulRBETqjSqKrC3onSz+1u1tp+bSsh8Yb8=" />



meta
charset
utf-8


1
ok















meta
Content-type
text/html; charset=utf-8


1
ok















meta
viewport
width=device-width, initial-scale=1


1
ok















script
src
/_js/iana.js
200

1
ok
Missing defer / async attribute. text/javascript
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
59 Bytes






local SRI possible, possible hash-values:

 

sha256-QyglbUDNqgR9mUYLQ/bXc2aYKXXokaky744Ac2/YLho=
sha384-YHoX2g/hbU7JG4iM5VOtWnFnkHst6Lqub+piTUpM6SGbp+z7jf13muAZnhztJXtf
sha512-Odxwt9EUvU+Q45iET6joG0p576jhOXGl0zOchG/bmPV0tlaZTxFQ+2pOtw50c3j/lKCmHBlM6Wmr7QCzWOUGnw==

 

<script src="/_js/iana.js" crossorigin="anonymous" integrity="sha256-QyglbUDNqgR9mUYLQ/bXc2aYKXXokaky744Ac2/YLho=" />



script
src
/_js/jquery.js
200

1
ok
Missing defer / async attribute. text/javascript
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
Compression (br): 28654/89501 Bytes






local SRI possible, possible hash-values:

 

sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=
sha384-vtXRMe3mGCbOeY7l30aIg8H9p3GdeSe4IFlP6G8JMa7o7lXvnz3GFKzPxzJdPfGK
sha512-894YE6QWD5I59HgZOGReFYm4dnWc1Qt5NtvYSaNcOP+u1T9qYdvdihz0PPSiiqn/+/3e7Jo4EaG7TubfWGUrMQ==

 

<script src="/_js/jquery.js" crossorigin="anonymous" integrity="sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=" />


2620:0:2830:200::b:8
a

/about


1
ok















a

/about/excellence


1
ok















a

/abuse


2
ok















a

/contact


1
ok















a

/domains


2
ok















a

/domains/arpa


2
ok















a

/domains/idn-tables


2
ok















a

/domains/int


2
ok















a

/domains/root


2
ok















a

/domains/root/db


1
ok















a

/numbers


3
ok















a

/performance


1
ok















a

/protocols


4
ok















a

/protocols/apply


1
ok















a

/reports


1
ok















a

/reviews


1
ok















a

/time-zones


2
ok















a

about/


1
ok















a

http://pti.icann.org


1
ok















a

http://www.icann.org/


1
ok















a

https://www.icann.org/privacy/policy


1
ok















a

https://www.icann.org/privacy/tos


1
ok















link
canonical
https://iana.org/


1
ok















link
shortcut icon
/_img/bookmark_icon.ico
200

1
ok
image/vnd.microsoft.icon
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 with long duration found.
No Compression - 7406 Bytes








link
stylesheet
/_css/2022/iana_website.css
200

1
ok
text/css
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
Compression (br): 7595/42327 Bytes






local SRI possible, possible hash-values:

 

sha256-mql12eeShHulRBETqjSqKrC3onSz+1u1tp+bSsh8Yb8=
sha384-/8Zbwg4qxM9Qed+EOWAZhkHzQlFUTGtTMa80Z+RHL9O3C2a17TgrdPkuVotr5KvY
sha512-74p2h2NmIb3ANX0oxpYjfyPJo1FzjUQgIVacdtRWSDTir0ZkwjpMbnrNIvSSveiCBfnI/CJmWZVhLhX2SnKTxQ==

 

<link rel="stylesheet" href="/_css/2022/iana_website.css" crossorigin="anonymous" integrity="sha256-mql12eeShHulRBETqjSqKrC3onSz+1u1tp+bSsh8Yb8=" />



meta
charset
utf-8


1
ok















meta
Content-type
text/html; charset=utf-8


1
ok















meta
viewport
width=device-width, initial-scale=1


1
ok















script
src
/_js/iana.js
200

1
ok
Missing defer / async attribute. text/javascript
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
59 Bytes






local SRI possible, possible hash-values:

 

sha256-QyglbUDNqgR9mUYLQ/bXc2aYKXXokaky744Ac2/YLho=
sha384-YHoX2g/hbU7JG4iM5VOtWnFnkHst6Lqub+piTUpM6SGbp+z7jf13muAZnhztJXtf
sha512-Odxwt9EUvU+Q45iET6joG0p576jhOXGl0zOchG/bmPV0tlaZTxFQ+2pOtw50c3j/lKCmHBlM6Wmr7QCzWOUGnw==

 

<script src="/_js/iana.js" crossorigin="anonymous" integrity="sha256-QyglbUDNqgR9mUYLQ/bXc2aYKXXokaky744Ac2/YLho=" />



script
src
/_js/jquery.js
200

1
ok
Missing defer / async attribute. text/javascript
missing X-Content-Type-Options nosniff





Cache-Control: public, max-age=604814, s-maxage=86402 - with long duration found.
Compression (br): 28442/89501 Bytes






local SRI possible, possible hash-values:

 

sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=
sha384-vtXRMe3mGCbOeY7l30aIg8H9p3GdeSe4IFlP6G8JMa7o7lXvnz3GFKzPxzJdPfGK
sha512-894YE6QWD5I59HgZOGReFYm4dnWc1Qt5NtvYSaNcOP+u1T9qYdvdihz0PPSiiqn/+/3e7Jo4EaG7TubfWGUrMQ==

 

<script src="/_js/jquery.js" crossorigin="anonymous" integrity="sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=" />


 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://www.iana.org/

Summary

Good: No non-document-errors
3 errors
4 warnings

TypeMessagenum found
1.errorA document must not include both a meta element with an http-equiv attribute whose value is content-type, and a meta element with a charset attribute.1
2.errorElement gcse:search not allowed as child of element div in this context. (Suppressing further errors from this subtree.)1
3.errorNo p element in scope but a p end tag seen.1
4.warningThe type attribute is unnecessary for JavaScript resources.2
5.warningConsider adding a lang attribute to the html start tag to declare the language of this document.1
6.warningElement name gcse:search cannot be represented as XML 1.0.1

Details


TypeMessage + Sample
1errorA document must not include both a meta element with an http-equiv attribute whose value is content-type, and a meta element with a charset attribute.

From line 7, column 2 to line 7, column 70

tf-8" /> <meta http-equiv="Content-type" content="text/html; charset=utf-8" /> <met
2errorElement gcse:search not allowed as child of element div in this context. (Suppressing further errors from this subtree.)

From line 80, column 13 to line 80, column 25

<gcse:search></gcse
3errorNo p element in scope but a p end tag seen.

From line 145, column 17 to line 145, column 20

</p>
4warningConsider adding a lang attribute to the html start tag to declare the language of this document.

From line 1, column 16 to line 2, column 6

type html> <html> <head
5warningThe type attribute is unnecessary for JavaScript resources.

From line 13, column 2 to line 13, column 53

.ico"/> <script type="text/javascript" src="/_js/jquery.js"></scri
6warningThe type attribute is unnecessary for JavaScript resources.

From line 14, column 2 to line 14, column 51

/script> <script type="text/javascript" src="/_js/iana.js"></scri
7warningElement name gcse:search cannot be represented as XML 1.0.

From line 80, column 13 to line 80, column 25

<gcse:search></gcse

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: a.iana-servers.net, b.iana-servers.net, c.iana-servers.net, ns.icann.org, sns.dns.icann.org

 

QNr.DomainTypeNS used
1
net
NS
d.root-servers.net (2001:500:2d::d)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
a.iana-servers.net: 199.43.135.53, 2001:500:8f::53
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: b.iana-servers.net
199.43.133.53, 2001:500:8d::53

Answer: c.iana-servers.net
199.43.134.53, 2001:500:8e::53
3
org
NS
f.root-servers.net (2001:500:2f::f)

Answer: a0.org.afilias-nst.info, a2.org.afilias-nst.info, b0.org.afilias-nst.org, b2.org.afilias-nst.org, c0.org.afilias-nst.info, d0.org.afilias-nst.org
4
ns.icann.org: 199.4.138.53, 2001:500:89::53
NS
a0.org.afilias-nst.info (2001:500:e::1)
5
sns.dns.icann.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: a.icann-servers.net, b.icann-servers.net, c.icann-servers.net, ns.icann.org

Answer: ns.icann.org
199.4.138.53, 2001:500:89::53
6
a.icann-servers.net: 199.43.135.53, 2001:500:8f::53
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: b.icann-servers.net
199.43.133.53, 2001:500:8d::53

Answer: c.icann-servers.net
199.43.134.53, 2001:500:8e::53
7
sns.dns.icann.org: 192.0.32.162
A
a.icann-servers.net (2001:500:8f::53)
8
sns.dns.icann.org: No AAAA record found
AAAA
a.icann-servers.net (2001:500:8f::53)

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
ianawww.vip.icann.org
0

no CAA entry found
1
0
vip.icann.org
0

no CAA entry found
1
0
www.iana.org



1
0
icann.org
0

no CAA entry found
1
0
iana.org
0

no CAA entry found
1
0
org
0

no CAA entry found
1
0

0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
iana.org
c9e864a6c53444038d34fe3a22513b74
ok
1
0
iana.org
docusign=b2d7c7b0-4627-494b-a7aa-682ee87c265d
ok
1
0
iana.org
google-site-verification=iIqTTcUxND4wZOeVe5Ho728rH3JOSDnssYsYJ7pUtQQ
ok
1
0
iana.org
MS=ms22660639
ok
1
0
iana.org
smartsheet-site-validation=CcnvONgQ2ibuzf2zHZxgPaWUqTwt-Sjr
ok
1
0
iana.org
v=spf1 redirect=icann.org
ok
1
0
www.iana.org


1
0
ianawww.vip.icann.org

ok
1
0
_acme-challenge.iana.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.iana.org

Name Error - The domain name does not exist
1
0
_acme-challenge.iana.org.iana.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.iana.org.iana.org

Name Error - The domain name does not exist
1
0
_acme-challenge.ianawww.vip.icann.org

Name Error - The domain name does not exist
1
0
_acme-challenge.www.iana.org.www.iana.org

Name Error - The domain name does not exist
1
0
_acme-challenge.ianawww.vip.icann.org.ianawww.vip.icann.org

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

iana.org
10
pechora1.icann.org
04ok

A


192.0.33.71
01ok

AAAA


2620:0:2d0:201::1:71
01ok

CNAME


00ok
MX

iana.org
10
pechora6.icann.org
04ok

A


192.0.46.72
01ok

AAAA


2620:0:2830:201::1:72
01ok

CNAME


00ok
MX

iana.org
10
pechora7.icann.org
04ok

A


192.0.33.73
01ok

AAAA


2620:0:2d0:201::1:73
01ok

CNAME


00ok
MX

iana.org
10
pechora8.icann.org
04ok

A


192.0.46.74
01ok

AAAA


2620:0:2830:201::1:74
01ok

CNAME


00ok
SPF
TXT
iana.org

v=spf1 redirect=icann.org
ok

TXT
icann.org

v=spf1 ip4:192.0.32.0/20 ip4:199.91.192.0/21 ip4:64.78.40.0/27 ip4:162.216.194.0/27 ip4:64.78.33.5/32 ip4:64.78.33.6/31 ip4:64.78.48.205/32 ip4:64.78.48.206/31 ip6:2620:0:2d0::0/48 ip6:2620:0:2830::0/48 ip6:2620:0:2ed0::0/48 include:salesforce.icann.org -all
ok

TXT
salesforce.icann.org

v=spf1 include:_spf.salesforce.com -all
ok

TXT
_spf.salesforce.com

v=spf1 exists:%{i}._spf.mta.salesforce.com -all
ok
_dmarc
TXT
_dmarc.iana.org

v=DMARC1;p=none;fo=1;rua=mailto:dmarc-rua@iana.org;ruf=mailto:dmarc-ruf@iana.org
ok

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
iana.org
192.0.43.8
443
7 Ciphers77.41 sec
0 without, 7 FS
100.00 %
iana.org
2001:500:88:200::8
443
7 Ciphers69.96 sec
0 without, 7 FS
100.00 %
www.iana.org
192.0.46.8
443
7 Ciphers77.94 sec
0 without, 7 FS
100.00 %
www.iana.org
2620:0:2830:200::b:8
443
7 Ciphers70.03 sec
0 without, 7 FS
100.00 %
Complete

4
28 Ciphers
7.00 Ciphers/Check
295.34 sec73.83 sec/Check
0 without, 28 FS
100.00 %

Details
DomainIPPortCipher (OpenSsl / IANA)
iana.org
192.0.43.8
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
7 Ciphers, 77.41 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1


2001:500:88:200::8
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
7 Ciphers, 69.96 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1

www.iana.org
192.0.46.8
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
7 Ciphers, 77.94 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1


2620:0:2830:200::b:8
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
7 Ciphers, 70.03 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1

 

18. Portchecks

DomainIPPortDescriptionResultAnswer
iana.org
192.0.43.8
21
FTP
open
421 Please use ftp.iana.org instead.

iana.org
192.0.43.8
21
FTP
open
421 Please use ftp.iana.org instead.

iana.org
192.0.43.8
22
SSH



iana.org
192.0.43.8
22
SSH



iana.org
192.0.43.8
25
SMTP



iana.org
192.0.43.8
25
SMTP



iana.org
192.0.43.8
53
DNS



iana.org
192.0.43.8
53
DNS



iana.org
192.0.43.8
110
POP3



iana.org
192.0.43.8
110
POP3



iana.org
192.0.43.8
143
IMAP



iana.org
192.0.43.8
143
IMAP



iana.org
192.0.43.8
465
SMTP (encrypted)



iana.org
192.0.43.8
465
SMTP (encrypted)



iana.org
192.0.43.8
587
SMTP (encrypted, submission)



iana.org
192.0.43.8
587
SMTP (encrypted, submission)



iana.org
192.0.43.8
993
IMAP (encrypted)



iana.org
192.0.43.8
993
IMAP (encrypted)



iana.org
192.0.43.8
995
POP3 (encrypted)



iana.org
192.0.43.8
995
POP3 (encrypted)



iana.org
192.0.43.8
1433
MS SQL



iana.org
192.0.43.8
1433
MS SQL



iana.org
192.0.43.8
2082
cPanel (http)



iana.org
192.0.43.8
2082
cPanel (http)



iana.org
192.0.43.8
2083
cPanel (https)



iana.org
192.0.43.8
2083
cPanel (https)



iana.org
192.0.43.8
2086
WHM (http)



iana.org
192.0.43.8
2086
WHM (http)



iana.org
192.0.43.8
2087
WHM (https)



iana.org
192.0.43.8
2087
WHM (https)



iana.org
192.0.43.8
2089
cPanel Licensing



iana.org
192.0.43.8
2089
cPanel Licensing



iana.org
192.0.43.8
2095
cPanel Webmail (http)



iana.org
192.0.43.8
2095
cPanel Webmail (http)



iana.org
192.0.43.8
2096
cPanel Webmail (https)



iana.org
192.0.43.8
2096
cPanel Webmail (https)



iana.org
192.0.43.8
2222
DirectAdmin (http)



iana.org
192.0.43.8
2222
DirectAdmin (http)



iana.org
192.0.43.8
2222
DirectAdmin (https)



iana.org
192.0.43.8
2222
DirectAdmin (https)



iana.org
192.0.43.8
3306
mySql



iana.org
192.0.43.8
3306
mySql



iana.org
192.0.43.8
5224
Plesk Licensing



iana.org
192.0.43.8
5224
Plesk Licensing



iana.org
192.0.43.8
5432
PostgreSQL



iana.org
192.0.43.8
5432
PostgreSQL



iana.org
192.0.43.8
8080
Ookla Speedtest (http)



iana.org
192.0.43.8
8080
Ookla Speedtest (http)



iana.org
192.0.43.8
8080
Ookla Speedtest (https)



iana.org
192.0.43.8
8080
Ookla Speedtest (https)



iana.org
192.0.43.8
8083
VestaCP http



iana.org
192.0.43.8
8083
VestaCP http



iana.org
192.0.43.8
8083
VestaCP https



iana.org
192.0.43.8
8083
VestaCP https



iana.org
192.0.43.8
8443
Plesk Administration (https)



iana.org
192.0.43.8
8443
Plesk Administration (https)



iana.org
192.0.43.8
8447
Plesk Installer + Updates



iana.org
192.0.43.8
8447
Plesk Installer + Updates



iana.org
192.0.43.8
8880
Plesk Administration (http)



iana.org
192.0.43.8
8880
Plesk Administration (http)



iana.org
192.0.43.8
10000
Webmin (http)



iana.org
192.0.43.8
10000
Webmin (http)



iana.org
192.0.43.8
10000
Webmin (https)



iana.org
192.0.43.8
10000
Webmin (https)



iana.org
2001:500:88:200::8
21
FTP
open
421 Please use ftp.iana.org instead.

iana.org
2001:500:88:200::8
21
FTP
open
421 Please use ftp.iana.org instead.

iana.org
2001:500:88:200::8
22
SSH



iana.org
2001:500:88:200::8
22
SSH



iana.org
2001:500:88:200::8
25
SMTP



iana.org
2001:500:88:200::8
25
SMTP



iana.org
2001:500:88:200::8
53
DNS



iana.org
2001:500:88:200::8
53
DNS



iana.org
2001:500:88:200::8
110
POP3



iana.org
2001:500:88:200::8
110
POP3



iana.org
2001:500:88:200::8
143
IMAP



iana.org
2001:500:88:200::8
143
IMAP



iana.org
2001:500:88:200::8
465
SMTP (encrypted)



iana.org
2001:500:88:200::8
465
SMTP (encrypted)



iana.org
2001:500:88:200::8
587
SMTP (encrypted, submission)



iana.org
2001:500:88:200::8
587
SMTP (encrypted, submission)



iana.org
2001:500:88:200::8
993
IMAP (encrypted)



iana.org
2001:500:88:200::8
993
IMAP (encrypted)



iana.org
2001:500:88:200::8
995
POP3 (encrypted)



iana.org
2001:500:88:200::8
995
POP3 (encrypted)



iana.org
2001:500:88:200::8
1433
MS SQL



iana.org
2001:500:88:200::8
1433
MS SQL



iana.org
2001:500:88:200::8
2082
cPanel (http)



iana.org
2001:500:88:200::8
2082
cPanel (http)



iana.org
2001:500:88:200::8
2083
cPanel (https)



iana.org
2001:500:88:200::8
2083
cPanel (https)



iana.org
2001:500:88:200::8
2086
WHM (http)



iana.org
2001:500:88:200::8
2086
WHM (http)



iana.org
2001:500:88:200::8
2087
WHM (https)



iana.org
2001:500:88:200::8
2087
WHM (https)



iana.org
2001:500:88:200::8
2089
cPanel Licensing



iana.org
2001:500:88:200::8
2089
cPanel Licensing



iana.org
2001:500:88:200::8
2095
cPanel Webmail (http)



iana.org
2001:500:88:200::8
2095
cPanel Webmail (http)



iana.org
2001:500:88:200::8
2096
cPanel Webmail (https)



iana.org
2001:500:88:200::8
2096
cPanel Webmail (https)



iana.org
2001:500:88:200::8
2222
DirectAdmin (http)



iana.org
2001:500:88:200::8
2222
DirectAdmin (http)



iana.org
2001:500:88:200::8
2222
DirectAdmin (https)



iana.org
2001:500:88:200::8
2222
DirectAdmin (https)



iana.org
2001:500:88:200::8
3306
mySql



iana.org
2001:500:88:200::8
3306
mySql



iana.org
2001:500:88:200::8
5224
Plesk Licensing



iana.org
2001:500:88:200::8
5224
Plesk Licensing



iana.org
2001:500:88:200::8
5432
PostgreSQL



iana.org
2001:500:88:200::8
5432
PostgreSQL



iana.org
2001:500:88:200::8
8080
Ookla Speedtest (http)



iana.org
2001:500:88:200::8
8080
Ookla Speedtest (http)



iana.org
2001:500:88:200::8
8080
Ookla Speedtest (https)



iana.org
2001:500:88:200::8
8080
Ookla Speedtest (https)



iana.org
2001:500:88:200::8
8083
VestaCP http



iana.org
2001:500:88:200::8
8083
VestaCP http



iana.org
2001:500:88:200::8
8083
VestaCP https



iana.org
2001:500:88:200::8
8083
VestaCP https



iana.org
2001:500:88:200::8
8443
Plesk Administration (https)



iana.org
2001:500:88:200::8
8443
Plesk Administration (https)



iana.org
2001:500:88:200::8
8447
Plesk Installer + Updates



iana.org
2001:500:88:200::8
8447
Plesk Installer + Updates



iana.org
2001:500:88:200::8
8880
Plesk Administration (http)



iana.org
2001:500:88:200::8
8880
Plesk Administration (http)



iana.org
2001:500:88:200::8
10000
Webmin (http)



iana.org
2001:500:88:200::8
10000
Webmin (http)



iana.org
2001:500:88:200::8
10000
Webmin (https)



iana.org
2001:500:88:200::8
10000
Webmin (https)



www.iana.org
192.0.46.8
21
FTP



www.iana.org
192.0.46.8
21
FTP



www.iana.org
192.0.46.8
22
SSH



www.iana.org
192.0.46.8
22
SSH



www.iana.org
192.0.46.8
25
SMTP



www.iana.org
192.0.46.8
25
SMTP



www.iana.org
192.0.46.8
53
DNS



www.iana.org
192.0.46.8
53
DNS



www.iana.org
192.0.46.8
110
POP3



www.iana.org
192.0.46.8
110
POP3



www.iana.org
192.0.46.8
143
IMAP



www.iana.org
192.0.46.8
143
IMAP



www.iana.org
192.0.46.8
465
SMTP (encrypted)



www.iana.org
192.0.46.8
465
SMTP (encrypted)



www.iana.org
192.0.46.8
587
SMTP (encrypted, submission)



www.iana.org
192.0.46.8
587
SMTP (encrypted, submission)



www.iana.org
192.0.46.8
993
IMAP (encrypted)



www.iana.org
192.0.46.8
993
IMAP (encrypted)



www.iana.org
192.0.46.8
995
POP3 (encrypted)



www.iana.org
192.0.46.8
995
POP3 (encrypted)



www.iana.org
192.0.46.8
1433
MS SQL



www.iana.org
192.0.46.8
1433
MS SQL



www.iana.org
192.0.46.8
2082
cPanel (http)



www.iana.org
192.0.46.8
2082
cPanel (http)



www.iana.org
192.0.46.8
2083
cPanel (https)



www.iana.org
192.0.46.8
2083
cPanel (https)



www.iana.org
192.0.46.8
2086
WHM (http)



www.iana.org
192.0.46.8
2086
WHM (http)



www.iana.org
192.0.46.8
2087
WHM (https)



www.iana.org
192.0.46.8
2087
WHM (https)



www.iana.org
192.0.46.8
2089
cPanel Licensing



www.iana.org
192.0.46.8
2089
cPanel Licensing



www.iana.org
192.0.46.8
2095
cPanel Webmail (http)



www.iana.org
192.0.46.8
2095
cPanel Webmail (http)



www.iana.org
192.0.46.8
2096
cPanel Webmail (https)



www.iana.org
192.0.46.8
2096
cPanel Webmail (https)



www.iana.org
192.0.46.8
2222
DirectAdmin (http)



www.iana.org
192.0.46.8
2222
DirectAdmin (http)



www.iana.org
192.0.46.8
2222
DirectAdmin (https)



www.iana.org
192.0.46.8
2222
DirectAdmin (https)



www.iana.org
192.0.46.8
3306
mySql



www.iana.org
192.0.46.8
3306
mySql



www.iana.org
192.0.46.8
5224
Plesk Licensing



www.iana.org
192.0.46.8
5224
Plesk Licensing



www.iana.org
192.0.46.8
5432
PostgreSQL



www.iana.org
192.0.46.8
5432
PostgreSQL



www.iana.org
192.0.46.8
8080
Ookla Speedtest (http)



www.iana.org
192.0.46.8
8080
Ookla Speedtest (http)



www.iana.org
192.0.46.8
8080
Ookla Speedtest (https)



www.iana.org
192.0.46.8
8080
Ookla Speedtest (https)



www.iana.org
192.0.46.8
8083
VestaCP http



www.iana.org
192.0.46.8
8083
VestaCP http



www.iana.org
192.0.46.8
8083
VestaCP https



www.iana.org
192.0.46.8
8083
VestaCP https



www.iana.org
192.0.46.8
8443
Plesk Administration (https)



www.iana.org
192.0.46.8
8443
Plesk Administration (https)



www.iana.org
192.0.46.8
8447
Plesk Installer + Updates



www.iana.org
192.0.46.8
8447
Plesk Installer + Updates



www.iana.org
192.0.46.8
8880
Plesk Administration (http)



www.iana.org
192.0.46.8
8880
Plesk Administration (http)



www.iana.org
192.0.46.8
10000
Webmin (http)



www.iana.org
192.0.46.8
10000
Webmin (http)



www.iana.org
192.0.46.8
10000
Webmin (https)



www.iana.org
192.0.46.8
10000
Webmin (https)



www.iana.org
2620:0:2830:200::b:8
21
FTP



www.iana.org
2620:0:2830:200::b:8
21
FTP



www.iana.org
2620:0:2830:200::b:8
22
SSH



www.iana.org
2620:0:2830:200::b:8
22
SSH



www.iana.org
2620:0:2830:200::b:8
25
SMTP



www.iana.org
2620:0:2830:200::b:8
25
SMTP



www.iana.org
2620:0:2830:200::b:8
53
DNS



www.iana.org
2620:0:2830:200::b:8
53
DNS



www.iana.org
2620:0:2830:200::b:8
110
POP3



www.iana.org
2620:0:2830:200::b:8
110
POP3



www.iana.org
2620:0:2830:200::b:8
143
IMAP



www.iana.org
2620:0:2830:200::b:8
143
IMAP



www.iana.org
2620:0:2830:200::b:8
465
SMTP (encrypted)



www.iana.org
2620:0:2830:200::b:8
465
SMTP (encrypted)



www.iana.org
2620:0:2830:200::b:8
587
SMTP (encrypted, submission)



www.iana.org
2620:0:2830:200::b:8
587
SMTP (encrypted, submission)



www.iana.org
2620:0:2830:200::b:8
993
IMAP (encrypted)



www.iana.org
2620:0:2830:200::b:8
993
IMAP (encrypted)



www.iana.org
2620:0:2830:200::b:8
995
POP3 (encrypted)



www.iana.org
2620:0:2830:200::b:8
995
POP3 (encrypted)



www.iana.org
2620:0:2830:200::b:8
1433
MS SQL



www.iana.org
2620:0:2830:200::b:8
1433
MS SQL



www.iana.org
2620:0:2830:200::b:8
2082
cPanel (http)



www.iana.org
2620:0:2830:200::b:8
2082
cPanel (http)



www.iana.org
2620:0:2830:200::b:8
2083
cPanel (https)



www.iana.org
2620:0:2830:200::b:8
2083
cPanel (https)



www.iana.org
2620:0:2830:200::b:8
2086
WHM (http)



www.iana.org
2620:0:2830:200::b:8
2086
WHM (http)



www.iana.org
2620:0:2830:200::b:8
2087
WHM (https)



www.iana.org
2620:0:2830:200::b:8
2087
WHM (https)



www.iana.org
2620:0:2830:200::b:8
2089
cPanel Licensing



www.iana.org
2620:0:2830:200::b:8
2089
cPanel Licensing



www.iana.org
2620:0:2830:200::b:8
2095
cPanel Webmail (http)



www.iana.org
2620:0:2830:200::b:8
2095
cPanel Webmail (http)



www.iana.org
2620:0:2830:200::b:8
2096
cPanel Webmail (https)



www.iana.org
2620:0:2830:200::b:8
2096
cPanel Webmail (https)



www.iana.org
2620:0:2830:200::b:8
2222
DirectAdmin (http)



www.iana.org
2620:0:2830:200::b:8
2222
DirectAdmin (http)



www.iana.org
2620:0:2830:200::b:8
2222
DirectAdmin (https)



www.iana.org
2620:0:2830:200::b:8
2222
DirectAdmin (https)



www.iana.org
2620:0:2830:200::b:8
3306
mySql



www.iana.org
2620:0:2830:200::b:8
3306
mySql



www.iana.org
2620:0:2830:200::b:8
5224
Plesk Licensing



www.iana.org
2620:0:2830:200::b:8
5224
Plesk Licensing



www.iana.org
2620:0:2830:200::b:8
5432
PostgreSQL



www.iana.org
2620:0:2830:200::b:8
5432
PostgreSQL



www.iana.org
2620:0:2830:200::b:8
8080
Ookla Speedtest (http)



www.iana.org
2620:0:2830:200::b:8
8080
Ookla Speedtest (http)



www.iana.org
2620:0:2830:200::b:8
8080
Ookla Speedtest (https)



www.iana.org
2620:0:2830:200::b:8
8080
Ookla Speedtest (https)



www.iana.org
2620:0:2830:200::b:8
8083
VestaCP http



www.iana.org
2620:0:2830:200::b:8
8083
VestaCP http



www.iana.org
2620:0:2830:200::b:8
8083
VestaCP https



www.iana.org
2620:0:2830:200::b:8
8083
VestaCP https



www.iana.org
2620:0:2830:200::b:8
8443
Plesk Administration (https)



www.iana.org
2620:0:2830:200::b:8
8443
Plesk Administration (https)



www.iana.org
2620:0:2830:200::b:8
8447
Plesk Installer + Updates



www.iana.org
2620:0:2830:200::b:8
8447
Plesk Installer + Updates



www.iana.org
2620:0:2830:200::b:8
8880
Plesk Administration (http)



www.iana.org
2620:0:2830:200::b:8
8880
Plesk Administration (http)



www.iana.org
2620:0:2830:200::b:8
10000
Webmin (http)



www.iana.org
2620:0:2830:200::b:8
10000
Webmin (http)



www.iana.org
2620:0:2830:200::b:8
10000
Webmin (https)



www.iana.org
2620:0:2830:200::b:8
10000
Webmin (https)



 

 

Permalink: https://check-your-website.server-daten.de/?i=22a84b54-11c5-4a96-b717-bb2d7b0e3b90

 

Last Result: https://check-your-website.server-daten.de/?q=iana.org - 2025-01-14 05:30:20

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=iana.org" target="_blank">Check this Site: iana.org</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=iana.org