Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

K

 

different ip addresses with diff. status

 

Checked:
22.07.2026 11:56:18

 

Older results

 

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
ic3.gov
A
20.141.170.64
Boydton/Virginia/United States (US) - Microsoft Corporation
No Hostname found
yes
1
0

A
52.126.48.246
Phoenix/Arizona/United States (US) - Microsoft Corporation
No Hostname found
yes
1
0

AAAA
2001:489a:3102:6::62
Boydton/Virginia/United States (US) - Microsoft Corporation

yes



AAAA
2001:489a:3600::13
Phoenix/Arizona/United States (US) - Microsoft Corporation

yes


www.ic3.gov
CNAME
www-dbfzbhdmagffhxd7.z01.azurefd.us
yes
1
0

CNAME
t-0001.msedge.azure.us
yes


www.ic3.gov
A
20.140.151.75
San Antonio/Texas/United States (US) - Microsoft Corporation
No Hostname found
no


*.ic3.gov
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 57780, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.08.2026, 00:00:00 +, Signature-Inception: 21.07.2026, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: gov

gov
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 2536, DigestType 2 and Digest C68mt7vzE6hZBG/Tse5J3fujOTTPs+cXwh4qKTXC8lk=






1 RRSIG RR to validate DS RR found






RRSIG-Owner gov., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 04.08.2026, 05:00:00 +, Signature-Inception: 22.07.2026, 04:00:00 +, KeyTag 57780, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 57780 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 2536, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 35496, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner gov., Algorithm: 13, 1 Labels, original TTL: 3600 sec, Signature-expiration: 09.09.2026, 11:06:35 +, Signature-Inception: 10.07.2026, 11:06:35 +, KeyTag 2536, Signer-Name: gov






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 2536 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 2536, DigestType 2 and Digest "C68mt7vzE6hZBG/Tse5J3fujOTTPs+cXwh4qKTXC8lk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: ic3.gov

ic3.gov
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 45370, DigestType 2 and Digest He4knqzDqgVuH0uIR1TW5PjU2Zvr8bp5sMHtg2jRW2E=






1 RRSIG RR to validate DS RR found






RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 23.07.2026, 10:56:24 +, Signature-Inception: 21.07.2026, 08:56:24 +, KeyTag 35496, Signer-Name: gov






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 35496 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 5916, Flags 256






Public Key with Algorithm 13, KeyTag 45370, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 12.09.2026, 07:00:01 +, Signature-Inception: 14.07.2026, 07:00:01 +, KeyTag 45370, Signer-Name: ic3.gov






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 45370 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 45370, DigestType 2 and Digest "He4knqzDqgVuH0uIR1TW5PjU2Zvr8bp5sMHtg2jRW2E=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone






RRSIG Type 1 validates the A - Result: 20.141.170.64 52.126.48.246
Validated: RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 300 sec, Signature-expiration: 23.07.2026, 10:56:36 +, Signature-Inception: 21.07.2026, 08:56:36 +, KeyTag 5916, Signer-Name: ic3.gov






RRSIG Type 16 validates the TXT - Result: _khghqassscz3aae29b9b22xb3pxffyb v=spf1 a:smtp.ic3.gov mx exp=spf-exp.ic3.gov -all
Validated: RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 23.07.2026, 10:56:31 +, Signature-Inception: 21.07.2026, 08:56:31 +, KeyTag 5916, Signer-Name: ic3.gov






RRSIG Type 28 validates the AAAA - Result: 2001:489A:3102:0006:0000:0000:0000:0062 2001:489A:3600:0000:0000:0000:0000:0013
Validated: RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 300 sec, Signature-expiration: 23.07.2026, 10:56:22 +, Signature-Inception: 21.07.2026, 08:56:22 +, KeyTag 5916, Signer-Name: ic3.gov






RRSIG Type 257 validates the CAA - Result: 5|issuedigicert.com
Validated: RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 23.07.2026, 10:56:13 +, Signature-Inception: 21.07.2026, 08:56:13 +, KeyTag 5916, Signer-Name: ic3.gov






CNAME-Query sends a valid NSEC RR as result with the query name "ic3.gov" equal the NSEC-owner "ic3.gov" and the NextOwner "\000.ic3.gov". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, NSEC, DNSKEY, CAA Validated: RRSIG-Owner ic3.gov., Algorithm: 13, 2 Labels, original TTL: 300 sec, Signature-expiration: 23.07.2026, 10:56:39 +, Signature-Inception: 21.07.2026, 08:56:39 +, KeyTag 5916, Signer-Name: ic3.gov






Status: Good. NoData-Proof required and found.






TLSA-Query (_443._tcp.ic3.gov) sends a valid NSEC RR as result with the query name "_443._tcp.ic3.gov" equal the NSEC-owner "_443._tcp.ic3.gov" and the NextOwner "\000._443._tcp.ic3.gov". So the zone confirmes the not-existence of that TLSA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: RRSIG, NSEC Validated: RRSIG-Owner _443._tcp.ic3.gov., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.07.2026, 10:56:39 +, Signature-Inception: 21.07.2026, 08:56:39 +, KeyTag 5916, Signer-Name: ic3.gov






Status: Good. NoData-Proof required and found.



Zone: www.ic3.gov

www.ic3.gov
0 DS RR in the parent zone found






RRSIG Type 5 validates the CNAME - Result: www-dbfzbhdmagffhxd7.z01.azurefd.us
Validated: RRSIG-Owner www.ic3.gov., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 23.07.2026, 10:56:36 +, Signature-Inception: 21.07.2026, 08:56:36 +, KeyTag 5916, Signer-Name: ic3.gov



Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






3 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 57780, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.08.2026, 00:00:00 +, Signature-Inception: 21.07.2026, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: us

us
1 DS RR in the parent zone found






DS with Algorithm 8, KeyTag 59017, DigestType 2 and Digest fa9GnUK12OVTf9TdS2BXcQ6aYfcsMut/tlJvUid+wrA=






1 RRSIG RR to validate DS RR found






RRSIG-Owner us., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 04.08.2026, 05:00:00 +, Signature-Inception: 22.07.2026, 04:00:00 +, KeyTag 57780, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 57780 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 54159, Flags 256






Public Key with Algorithm 8, KeyTag 59017, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner us., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 01.08.2026, 15:48:45 +, Signature-Inception: 18.07.2026, 15:46:35 +, KeyTag 59017, Signer-Name: us






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59017 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 59017, DigestType 2 and Digest "fa9GnUK12OVTf9TdS2BXcQ6aYfcsMut/tlJvUid+wrA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: azurefd.us

azurefd.us
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "a3vp1e4pr4v0ckmn1ne8k8ne9u8j3ul4" between the hashed NSEC3-owner "a3v9gmilcgcr6blfr0uh12tbd14rbj1g" and the hashed NextOwner "a3vuuve0344ia6t50rh9m39riks5455i". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner a3v9gmilcgcr6blfr0uh12tbd14rbj1g.us., Algorithm: 8, 2 Labels, original TTL: 900 sec, Signature-expiration: 31.07.2026, 02:41:24 +, Signature-Inception: 17.07.2026, 02:02:23 +, KeyTag 54159, Signer-Name: us






DS-Query in the parent zone sends valid NSEC3 RR with the Hash "r0lo40lj4j76eriqpo80i3insgcmv5ns" as Owner. That's the Hash of "us" with the NextHashedOwnerName "r0men30o2a9cjn3tjp2meeou3fvpig9u". So that domain name is the Closest Encloser of "azurefd.us". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM, CDS, CDNSKEY Validated: RRSIG-Owner r0lo40lj4j76eriqpo80i3insgcmv5ns.us., Algorithm: 8, 2 Labels, original TTL: 900 sec, Signature-expiration: 03.08.2026, 20:05:53 +, Signature-Inception: 20.07.2026, 19:13:24 +, KeyTag 54159, Signer-Name: us






0 DNSKEY RR found









Zone: z01.azurefd.us

z01.azurefd.us
0 DS RR in the parent zone found






0 DNSKEY RR found









Zone: www-dbfzbhdmagffhxd7.z01.azurefd.us

www-dbfzbhdmagffhxd7.z01.azurefd.us
0 DS RR in the parent zone found

 

3. Name Servers

DomainNameserverNS-IP
ic3.gov
  ns1-35.azuregov-dns.us
195.134.236.35
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4000:10::23
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns2-35.azuregov-dns.us
195.134.238.35
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4002:10::23
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns3-35.azuregov-dns.us
195.134.248.35
Lawrenceville/Virginia/United States (US) - Microsoft Federal


 
2001:489a:4004:10::23
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns4-35.azuregov-dns.us
195.134.250.35
Lawrenceville/Virginia/United States (US) - Microsoft Federal


 
2001:489a:4006:10::23
Washington/District of Columbia/United States (US) - Microsoft Corporation

gov
  a.ns.gov / 67m140


  b.ns.gov / 67m96


  c.ns.gov / 67m171


  d.ns.gov / 67m159


z01.azurefd.us
  ns1-03.azuregov-dns.us
195.134.224.3
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4000::3
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns2-03.azuregov-dns.us
195.134.226.3
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4002::3
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns3-03.azuregov-dns.us
204.13.120.3
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4004::3
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns4-03.azuregov-dns.us
204.13.122.3
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4006::3
Washington/District of Columbia/United States (US) - Microsoft Corporation

azurefd.us
  ns1-05.azuregov-dns.us
195.134.224.5
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4000::5
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns2-05.azuregov-dns.us
195.134.226.5
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4002::5
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns3-05.azuregov-dns.us
204.13.120.5
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4004::5
Washington/District of Columbia/United States (US) - Microsoft Corporation


  ns4-05.azuregov-dns.us
204.13.122.5
Madison/Wisconsin/United States (US) - Microsoft Corporation


 
2001:489a:4006::5
Washington/District of Columbia/United States (US) - Microsoft Corporation

us
  a.cctld.us


  b.cctld.us / u-ci-xtld2.defra1.ultradns


  f.cctld.us / u-ci-xtld2.defra1.ultradns


  k.cctld.us / u-ci-xtld1.defra1.ultradns


  m.cctld.us / xtldgd1.defra201.ultradns


  n.cctld.us / xtldgd1.nlams201.ultradns


  w.cctld.us / dns2.defra1


  x.cctld.us / dns4.defra1


  y.cctld.us / dns4.defra1

 

4. SOA-Entries


Domain:gov
Zone-Name:gov
Primary:a.ns.gov
Mail:dns.cloudflare.com
Serial:1784713682
Refresh:3600
Retry:900
Expire:604800
TTL:300
num Entries:4


Domain:ic3.gov
Zone-Name:ic3.gov
Primary:ns1-35.azuregov-dns.us
Mail:hostmaster.ic3.gov
Serial:1000
Refresh:3600
Retry:300
Expire:2419200
TTL:300
num Entries:8



Domain:us
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1


Domain:us
Zone-Name:us
Primary:a.cctld.us
Mail:admin.tldns.godaddy
Serial:1784713567
Refresh:1800
Retry:300
Expire:604800
TTL:1800
num Entries:8


Domain:azurefd.us
Zone-Name:azurefd.us
Primary:ns1-05.azuregov-dns.us
Mail:azuredns-hostmaster.microsoft.com
Serial:1
Refresh:3600
Retry:300
Expire:2419200
TTL:300
num Entries:8


Domain:z01.azurefd.us
Zone-Name:z01.azurefd.us
Primary:ns1-03.azuregov-dns.us
Mail:azuredns-hostmaster.microsoft.com
Serial:1
Refresh:3600
Retry:300
Expire:2419200
TTL:300
num Entries:8


5. Screenshots

Startaddress: https://www.ic3.gov/, address used: https://www.ic3.gov/, Screenshot created 2026-07-22 12:07:39 +00:0

 

Mobil (412px x 732px)

 

728 milliseconds

 

Screenshot mobile - https://www.ic3.gov/
Mobil + Landscape (732px x 412px)

 

729 milliseconds

 

Screenshot mobile landscape - https://www.ic3.gov/
Screen (1280px x 1680px)

 

1423 milliseconds

 

Screenshot Desktop - https://www.ic3.gov/

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport397732
content Size3975537

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://ic3.gov/
20.141.170.64
301
https://ic3.gov/
Html is minified: 100.72 %
0.280
A
Location: https://ic3.gov/
Date: Wed, 22 Jul 2026 09:58:59 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 139

• http://ic3.gov/
52.126.48.246
308
https://www.ic3.gov/
Html is minified: 100.70 %
0.320
E
Location: https://www.ic3.gov/
Date: Wed, 22 Jul 2026 09:58:59 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• http://ic3.gov/
2001:489a:3102:6::62
301
https://ic3.gov/
Html is minified: 100.72 %
0.210
A
Location: https://ic3.gov/
Date: Wed, 22 Jul 2026 09:58:59 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 139

• http://ic3.gov/
2001:489a:3600::13
308
https://www.ic3.gov/
Html is minified: 100.70 %
0.343
E
Location: https://www.ic3.gov/
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 09:59:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• http://www.ic3.gov/
20.140.151.75
307
https://www.ic3.gov/

0.276
A
Date: Wed, 22 Jul 2026 09:59:00 GMT
Connection: keep-alive
Location: https://www.ic3.gov/
x-azure-ref: 20260722T095900Z-186c4cbc75829hz2hS1SNR09fn0000003wvg000000002sf1
X-Cache: CONFIG_NOCACHE
Content-Type: text/html
Content-Length: 0

• https://ic3.gov/
20.141.170.64
308
https://www.ic3.gov/
Html is minified: 100.70 %
5.243
A
Location: https://www.ic3.gov/
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 09:59:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• https://ic3.gov/
52.126.48.246
308
https://www.ic3.gov/
Html is minified: 100.70 %
6.344
A
Location: https://www.ic3.gov/
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 09:59:07 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• https://ic3.gov/
2001:489a:3102:6::62
308
https://www.ic3.gov/
Html is minified: 100.70 %
4.673
A
Location: https://www.ic3.gov/
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 09:59:14 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• https://ic3.gov/
2001:489a:3600::13
308
https://www.ic3.gov/
Html is minified: 100.70 %
5.680
B
Location: https://www.ic3.gov/
Date: Wed, 22 Jul 2026 09:59:20 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 143

• https://www.ic3.gov/
20.140.151.75 br used - 14218 / 52858 - 73.10 %
Inline-JavaScript (∑/total): 1/721 Inline-CSS (∑/total): 0/0
200

Html is minified: 146.15 %
Other inline scripts (∑/total): 2/322
6.436
I
Date: Wed, 22 Jul 2026 09:59:27 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Age: 104
Cache-Control: public, max-age=120
Vary: Accept-Encoding
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'none'; upgrade-insecure-requests; frame-ancestors 'none'; font-src 'self'; img-src 'self'; script-src 'nonce-e2wq0dtgvhrklwup' https://www.google-analytics.com https://www.googletagmanager.com; connect-src https://www.google-analytics.com; style-src 'self' 'nonce-e2wq0dtgvhrklwup'; base-uri 'none'; form-action 'self'; require-trusted-types-for 'script'; trusted-types default
Permissions-Policy: camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=(), payment=(), publickey-credentials-get=(), web-share=()
x-azure-ref: 20260722T095927Z-186c4cbc758f5c4chS1SNR7cvg0000003wx0000000002cew
X-Cache: TCP_HIT
x-fd-int-roxy-purgeid: 1490086
Content-Type: text/html; charset=utf-8
Content-Encoding: br
Content-Length: 14218

• http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
20.141.170.64
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.48 %
Other inline scripts (∑/total): 0/0
0.117
A
Visible Content:
Location: https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Date: Wed, 22 Jul 2026 09:59:35 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 208

• http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
52.126.48.246
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
308
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.47 %
Other inline scripts (∑/total): 0/0
0.160
E
Visible Content:
Location: https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Date: Wed, 22 Jul 2026 09:59:36 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 212

• http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2001:489a:3102:6::62
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
301
https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.48 %
Other inline scripts (∑/total): 0/0
0.107
A
Visible Content:
Location: https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Date: Wed, 22 Jul 2026 09:59:37 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 208

• http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2001:489a:3600::13
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
308
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.47 %
Other inline scripts (∑/total): 0/0
0.180
E
Visible Content:
Location: https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 09:59:38 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 212

• http://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
20.140.151.75
307
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

0.143
A
Visible Content:
Date: Wed, 22 Jul 2026 09:59:39 GMT
Connection: keep-alive
Location: https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
x-azure-ref: 20260722T095939Z-186c4cbc75829hz2hS1SNR09fn0000003wvg000000002sxg
X-Cache: CONFIG_NOCACHE
Content-Type: text/html
Content-Length: 0

• https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
308
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Html is minified: 100.47 %
Other inline scripts (∑/total): 0/0
6.150
A
Visible Content:
Location: https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Wed, 22 Jul 2026 10:00:20 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 212

• https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
br used - 9595 / 33070 - 70.99 %
Inline-JavaScript (∑/total): 1/721 Inline-CSS (∑/total): 0/0
404

Html is minified: 152.86 %
Other inline scripts (∑/total): 2/322
7.387
A
Not Found
Visible Content:
Date: Wed, 22 Jul 2026 10:00:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: no-store, no-cache
Pragma: no-cache
Vary: Accept-Encoding
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff,nosniff
Content-Security-Policy: default-src 'none'; upgrade-insecure-requests; frame-ancestors 'none'; font-src 'self'; img-src 'self'; script-src 'nonce-wnxm2oplqevx5kbu' https://www.google-analytics.com https://www.googletagmanager.com; connect-src https://www.google-analytics.com; style-src 'self' 'nonce-wnxm2oplqevx5kbu'; base-uri 'none'; form-action 'self'; require-trusted-types-for 'script'; trusted-types default
Permissions-Policy: camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=(), payment=(), publickey-credentials-get=(), web-share=()
x-azure-ref: 20260722T100029Z-16655987dbd9pzbkhS1PHXbez00000003fa00000000012d0
X-Cache: PRIVATE_NOSTORE
x-fd-int-roxy-purgeid: 1490086
Content-Type: text/html; charset=utf-8
Content-Encoding: br
Content-Length: 9595

• https://20.140.151.75/
20.140.151.75 br used - 837 / 3601 - 76.76 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 141.77 %
Other inline scripts (∑/total): 0/0
6.144
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Date: Wed, 22 Jul 2026 10:00:12 GMT
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Cache-Control: no-store
x-azure-ref: 20260722T100012Z-186c4cbc758zjl67hS1SNR06m00000003x2000000000010q
X-Cache: CONFIG_NOCACHE
Content-Type: text/html
Content-Encoding: br
Content-Length: 837

• https://20.141.170.64/
20.141.170.64
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 103.96 %
Other inline scripts (∑/total): 0/0
5.226
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Server: Microsoft-HTTPAPI/2.0
Date: Wed, 22 Jul 2026 09:59:42 GMT
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 315

• https://52.126.48.246/
52.126.48.246
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 103.96 %
Other inline scripts (∑/total): 0/0
6.287
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Server: Microsoft-HTTPAPI/2.0
Date: Wed, 22 Jul 2026 09:59:49 GMT
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 315

• https://[2001:489a:3102:0006:0000:0000:0000:0062]/
2001:489a:3102:6::62
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 103.96 %
Other inline scripts (∑/total): 0/0
4.674
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Server: Microsoft-HTTPAPI/2.0
Date: Wed, 22 Jul 2026 09:59:58 GMT
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 315

• https://[2001:489a:3600:0000:0000:0000:0000:0013]/
2001:489a:3600::13
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
404

Html is minified: 103.96 %
Other inline scripts (∑/total): 0/0
5.760
N
Not Found
Certificate error: RemoteCertificateNameMismatch
Server: Microsoft-HTTPAPI/2.0
Date: Wed, 22 Jul 2026 10:00:04 GMT
Connection: close
Content-Type: text/html; charset=us-ascii
Content-Length: 315

 

7. Comments


1. General Results, most used to calculate the result

Aname "ic3.gov" is domain, public suffix is ".gov", top-level-domain is ".gov", top-level-domain-type is "sponsored", tld-manager is "General Services Administration Attn: QTDC, 2E08 (.gov Domain Registration)", num .gov-domains preloaded: 5119 (complete: 276475)
AGood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: ic3.gov has 4 different ip addresses (authoritative).
AGood: Ipv4 and Ipv6 addresses per domain name found: ic3.gov has 2 ipv4, 2 ipv6 addresses
AGood: No asked Authoritative Name Server had a timeout
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: www is preferred
AGood: No cookie sent via http.
AExcellent: Domain is in the Google-Preload-List
AExcellent: Domain is in the Mozilla/Firefox-Preload-List
AHSTS-Preload-Status: Preloaded. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):6 complete Content-Type - header (7 urls)
https://20.140.151.75/ 20.140.151.75


Url with incomplete Content-Type - header - missing charset
Ahttp://ic3.gov/ 20.141.170.64
301
https://ic3.gov/
Correct redirect http - https with the same domain name
Ahttp://ic3.gov/ 2001:489a:3102:6::62
301
https://ic3.gov/
Correct redirect http - https with the same domain name
Ahttp://www.ic3.gov/ 20.140.151.75
307
https://www.ic3.gov/
Correct redirect http - https with the same domain name
Bhttps://ic3.gov/ 2001:489a:3600::13
308

Missing HSTS-Header
Ehttp://ic3.gov/ 52.126.48.246
308
https://www.ic3.gov/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Ehttp://ic3.gov/ 2001:489a:3600::13
308
https://www.ic3.gov/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Ihttps://www.ic3.gov/ 20.140.151.75
200

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Ihttps://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
308

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Ihttps://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Check the Html-Content - Part.
Ihttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.126.48.246
308

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Not used to calculate the result because it's a http - check. But listed so you should fix it.
Ihttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3600::13
308

Content problems or problems with resources included - http links, files doesn't exist, different Content-Type definitions. Not used to calculate the result because it's a http - check. But listed so you should fix it.
Khttp://ic3.gov/ 20.141.170.64, Status 301

http://ic3.gov/ 52.126.48.246, Status 308
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/ 20.141.170.64, Status 301

http://ic3.gov/ 2001:489a:3600::13, Status 308
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/ 52.126.48.246, Status 308

http://ic3.gov/ 2001:489a:3102:6::62, Status 301
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 20.141.170.64, Status 301

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3600::13, Status 308
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/ 2001:489a:3102:6::62, Status 301

http://ic3.gov/ 2001:489a:3600::13, Status 308
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 20.141.170.64, Status 301

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.126.48.246, Status 308
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.126.48.246, Status 308

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3102:6::62, Status 301
Configuration problem - different ip addresses with different status
Khttp://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3102:6::62, Status 301

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3600::13, Status 308
Configuration problem - different ip addresses with different status
Mhttps://20.141.170.64/ 20.141.170.64
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://52.126.48.246/ 52.126.48.246
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://[2001:489a:3102:0006:0000:0000:0000:0062]/ 2001:489a:3102:6::62
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://[2001:489a:3600:0000:0000:0000:0000:0013]/ 2001:489a:3600::13
404

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://20.140.151.75/ 20.140.151.75
404

Misconfiguration - main pages should never send http status 400 - 499
Nhttps://20.141.170.64/ 20.141.170.64
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://52.126.48.246/ 52.126.48.246
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://[2001:489a:3102:0006:0000:0000:0000:0062]/ 2001:489a:3102:6::62
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://[2001:489a:3600:0000:0000:0000:0000:0013]/ 2001:489a:3600::13
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
Nhttps://20.140.151.75/ 20.140.151.75
404

Error - Certificate isn't trusted, RemoteCertificateNameMismatch
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain ic3.gov, 4 ip addresses.
Warning: More then one ip address per domain name found, checking all ip addresses the same http status, but different certificates found: Domain ic3.gov, 4 ip addresses, 2 certificates.
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain ic3.gov, 4 ip addresses.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.ic3.gov

2. Header-Checks

Awww.ic3.gov 20.140.151.75
Content-Security-Policy
Ok: Header without syntax errors found: default-src 'none'; upgrade-insecure-requests; frame-ancestors 'none'; font-src 'self'; img-src 'self'; script-src 'nonce-e2wq0dtgvhrklwup' https://www.google-analytics.com https://www.googletagmanager.com; connect-src https://www.google-analytics.com; style-src 'self' 'nonce-e2wq0dtgvhrklwup'; base-uri 'none'; form-action 'self'; require-trusted-types-for 'script'; trusted-types default
A

Good: default-src directive only with 'none' or 'self', additional sources are blocked.
A

Good: default-src without 'unsafe-inline' or 'unsave-eval'.
A

Good: form-action directive found. That reduces the risk sending data to unwanted domains. form-action is a navigation-directive, so default-src isn't used.
A

Good: frame-ancestors directive found. That limits pages who are allowed to use this page in a frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
A

Good: base-uri directive found. That limits the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
A

Good: No object-src found, but the default-src used as fallback is defined and restricted.
A

Good: script-src without 'unsafe-inline' and 'unsafe-eval' found. That's the recommended configuration.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A

Good: frame-src without data: defined or frame-src missing and the default-src used as fallback not allows the data: schema. That blocks hidden code injection. Insert <iframe src="data:text/html;charset=utf-8;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGJvZHk+PHA+YmVmb3JlPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPmFsZXJ0KCdYU1MnKTwvc2NyaXB0PjxwPmFmdGVyPC9ib2R5PjwvaHRtbD4="></iframe> in your page and see what happens.
A

Ok: Nonce found. (Element: font-src)
A

Ok: Nonce found. (Element: img-src)
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Permissions-Policy
Ok: Header without syntax errors found: camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=(), payment=(), publickey-credentials-get=(), web-share=()
Fwww.ic3.gov 20.140.151.75
Referrer-Policy
Critical: Missing Header:
Bwww.ic3.gov 20.140.151.75
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.ic3.gov 20.140.151.75
Cross-Origin-Opener-Policy
Info: Missing Header
Bwww.ic3.gov 20.140.151.75
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 13 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 4 Name Servers.
AInfo:: 13 Queries complete, 5 with IPv6, 8 with IPv4.
Warning: Only some DNS Queries done via ipv6. IPv6 is the future, so the name servers of your name servers should have ipv6 addresses.
Ok (4 - 8):: An average of 3.3 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 4 different Name Servers found: ns1-35.azuregov-dns.us, ns2-35.azuregov-dns.us, ns3-35.azuregov-dns.us, ns4-35.azuregov-dns.us, 4 Name Servers included in Delegation: ns1-35.azuregov-dns.us, ns2-35.azuregov-dns.us, ns3-35.azuregov-dns.us, ns4-35.azuregov-dns.us, 4 Name Servers included in 1 Zone definitions: ns1-35.azuregov-dns.us, ns2-35.azuregov-dns.us, ns3-35.azuregov-dns.us, ns4-35.azuregov-dns.us, 1 Name Servers listed in SOA.Primary: ns1-35.azuregov-dns.us.
AGood: Only one SOA.Primary Name Server found.: ns1-35.azuregov-dns.us.
AGood: SOA.Primary Name Server included in the delegation set.: ns1-35.azuregov-dns.us.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns1-35.azuregov-dns.us, ns2-35.azuregov-dns.us, ns3-35.azuregov-dns.us, ns4-35.azuregov-dns.us
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 4 different Name Servers found
AGood: All name servers have ipv4- and ipv6-addresses.: 4 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 4 Name Servers, 1 Top Level Domain: us
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: azuregov-dns.us
Warning: All Name Servers from the same Country / IP location.: 4 Name Servers, 1 Countries: US
AInfo: Ipv4-Subnet-list: 4 Name Servers, 1 different subnets (first Byte): 195., 1 different subnets (first two Bytes): 195.134., 4 different subnets (first three Bytes): 195.134.236., 195.134.238., 195.134.248., 195.134.250.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 4 Name Servers with IPv6, 1 different subnets (first block): 2001:, 1 different subnets (first two blocks): 2001:489a:, 4 different subnets (first three blocks): 2001:489a:4000:, 2001:489a:4002:, 2001:489a:4004:, 2001:489a:4006:, 4 different subnets (first four blocks): 2001:489a:4000:0010:, 2001:489a:4002:0010:, 2001:489a:4004:0010:, 2001:489a:4006:0010:
AGood: Name Server IPv6 addresses from different subnets found.
AGood: Nameserver supports TCP connections: 8 good Nameserver
AGood: Nameserver supports Echo Capitalization: 8 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 8 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 8 good Nameserver
Nameserver doesn't pass all EDNS-Checks: a.cctld.us: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
AGood: All SOA have the same Serial Number
AGood: CAA entries found, creating certificate is limited: digicert.com is allowed to create certificates

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3102:6::62, Status 301

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.126.48.246, Status 308
Fatal: Check of /.well-known/acme-challenge/random-filename has different answers checking ipv6 / ipv4. Ipv6 doesn't have the expected result http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 validation may not work. Checking the validation file in /.well-known/acme-challenge Letsencrypt prefers ipv6. Two options: Remove your ipv6 / AAAA DNS entry or (better) fix your ipv6, so your webserver handles ipv6 correct. Perhaps add "Listen [::]:80". Don't use <VirtualHost ip-address:80>, switch to <VirtualHost *:80>. If you use IIS, check your bindings. Don't select a single ip address. Use this tool to check your raw ipv6 address. Add your domain name in the "Hostname" - field. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2001:489a:3600::13, Status 308

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 20.141.170.64, Status 301
Fatal: Check of /.well-known/acme-challenge/random-filename has different answers checking ipv6 / ipv4. Ipv6 doesn't have the expected result http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 validation may not work. Checking the validation file in /.well-known/acme-challenge Letsencrypt prefers ipv6. Two options: Remove your ipv6 / AAAA DNS entry or (better) fix your ipv6, so your webserver handles ipv6 correct. Perhaps add "Listen [::]:80". Don't use <VirtualHost ip-address:80>, switch to <VirtualHost *:80>. If you use IIS, check your bindings. Don't select a single ip address. Use this tool to check your raw ipv6 address. Add your domain name in the "Hostname" - field. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://www.ic3.gov/ 20.140.151.75
200

Warning: Https + http status 200 + Inline CSS / JavaScript found. Don't use inline CSS / JavaScript. These are compiled and re-used ressources, save these with a long Cache-Control max-age - header.
https://www.ic3.gov/ 20.140.151.75
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
AGood: Every https connection via port 443 supports the http/2 protocol via ALPN.
AGood: Some script Elements (type text/javascript) with a src-Attribute have a defer / async - Attribute. So loading and executing these JavaScripts doesn't block parsing and rendering the Html-Output.
https://www.ic3.gov/ 20.140.151.75
200

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 1 script elements without defer/async.
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404

Critical: Some script Elements (type text/javascript) with a src-Attribute don't have a defer / async - Attribute. Loading and executing these JavaScripts blocks parsing and rendering the Html-Output. That's bad if your site is large or the connection is slow / mobile usage. Use "async" if the js file has only functions (so nothing is executed after parsing the file) or is independend. Use "defer" if the order of the scripts is important. All "defer" scripts are executed before the DOMContentLoaded event is fired. Check https://developer.mozilla.org/en-US/docs/Web/HTML/Element/script to see some details.: 1 script elements without defer/async.
AGood: All CSS / JavaScript files are sent compressed (gzip, deflate, br checked). That reduces the content of the files. 8 external CSS / JavaScript files found
AGood: All images with internal compression not compressed. Some Images (.png, .jpg, .jpeg, .webp, .gif) are already compressed, so an additional compression isn't helpful. 7 images (type image/png, image/jpg, image/jpeg, image/webp, image/gif) found without additional Compression. Not required because these images are already compressed
Warning: CSS / JavaScript files with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 2 external CSS / JavaScript files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 8 with Cache-Control max-age too short (minimum 7 days), 0 with Cache-Control long enough, 10 complete.
Warning: Images with a missing or too short Cache-Control header found. Browsers should cache and re-use these files. 0 image files without Cache-Control-Header, 0 with Cache-Control, but no max-age, 15 with Cache-Control max-age too short (minimum 7 days), 0 with Cache-Control long enough, 15 complete.
AGood: All checked attribute values are enclosed in quotation marks (" or ').
AGood: Some img-elements have a valid alt-attribute.: 21 img-elements found, 9 img-elements with correct alt-attributes (defined, not an empty value).
Wrong: img-elements without alt-attribute or empty alt-attribute found. The alt-attribute ("alternative") is required and should describe the img. So Screenreader and search engines are able to use these informations.: 3 img-elements without alt-attribute, 9 img-elements with empty alt-attribute found.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
http://ic3.gov/ 2001:489a:3600::13
308

Warning: HSTS header sent via http has no effect
https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
7.387 seconds
Warning: 404 needs more then one second
https://20.141.170.64/ 20.141.170.64
404
5.226 seconds
Warning: 404 needs more then one second
https://52.126.48.246/ 52.126.48.246
404
6.287 seconds
Warning: 404 needs more then one second
https://[2001:489a:3102:0006:0000:0000:0000:0062]/ 2001:489a:3102:6::62
404
4.674 seconds
Warning: 404 needs more then one second
https://[2001:489a:3600:0000:0000:0000:0000:0013]/ 2001:489a:3600::13
404
5.760 seconds
Warning: 404 needs more then one second
https://20.140.151.75/ 20.140.151.75
404
6.144 seconds
Warning: 404 needs more then one second
ADuration: 686233 milliseconds, 686.233 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
ic3.gov
20.141.170.64
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
ic3.gov
20.141.170.64
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


ic3.gov
52.126.48.246
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

ic3.gov
52.126.48.246
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


ic3.gov
2001:489a:3102:6::62
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

ic3.gov
2001:489a:3102:6::62
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


ic3.gov
2001:489a:3600::13
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

ic3.gov
2001:489a:3600::13
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
No SNI required - domain included in main certificate
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


www.ic3.gov
20.140.151.75
443
ok
Tls12
ECDH Ephermal
256
Aes256
256
Sha384
supported
ok

www.ic3.gov
20.140.151.75
443
ok
Tls12

ECDH Ephermal
256
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=www.ic3.gov


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


3CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US


ic3.gov
ic3.gov
443
ok
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

ic3.gov
ic3.gov
443
ok
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


www.ic3.gov
www.ic3.gov
443
ok
Tls12
ECDH Ephermal
256
Aes256
256
Sha384
supported
ok

www.ic3.gov
www.ic3.gov
443
ok
Tls12

ECDH Ephermal
256
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=www.ic3.gov


2CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US


3CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US


20.140.151.75
20.140.151.75
443
name does not match
Tls12
ECDH Ephermal
256
Aes256
256
Sha384
supported
ok

20.140.151.75
20.140.151.75
443
name does not match
Tls12

ECDH Ephermal
256
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.azureedge.us, O=Microsoft Corporation, L=Redmond, C=US, ST=Washington


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


3CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US


20.141.170.64
20.141.170.64
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

20.141.170.64
20.141.170.64
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


52.126.48.246
52.126.48.246
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

52.126.48.246
52.126.48.246
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


[2001:489a:3102:0006:0000:0000:0000:0062]
2001:489a:3102:6::62
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

[2001:489a:3102:0006:0000:0000:0000:0062]
2001:489a:3102:6::62
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US


[2001:489a:3600:0000:0000:0000:0000:0013]
2001:489a:3600::13
443
name does not match
Tls12
ECDH Ephermal
384
Aes256
256
Sha384
supported
ok

[2001:489a:3600:0000:0000:0000:0000:0013]
2001:489a:3600::13
443
name does not match
Tls12

ECDH Ephermal
384
Aes256
256
Sha384
supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, C=US, ST=California


2CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US

 

9. Certificates

1.
1.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025
06.01.2027
expires in 142 days
ic3.gov - 1 entry
1.
1.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025

06.01.2027
expires in 142 days


ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0783488E4ACB0F319876428859BC756C
Thumbprint:8FA63D094DA3C0934E765133C5281B590A344193
SHA256 / Certificate:eUE0q3l/ocaUTrB8xTrYUAXc1wAJrY2FbO10mEh3+I0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b
SHA256 hex / Subject Public Key Information (SPKI):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




2.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025
06.01.2027
expires in 142 days
ic3.gov - 1 entry

2.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025

06.01.2027
expires in 142 days


ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0783488E4ACB0F319876428859BC756C
Thumbprint:8FA63D094DA3C0934E765133C5281B590A344193
SHA256 / Certificate:eUE0q3l/ocaUTrB8xTrYUAXc1wAJrY2FbO10mEh3+I0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b
SHA256 hex / Subject Public Key Information (SPKI):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1686 days


3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1686 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1686 days


4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1686 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024
09.11.2031
expires in 1910 days


5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024

09.11.2031
expires in 1910 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0E7D75235CA83761577F4CCD24CD6D1D
Thumbprint:B7402517EEAAC80AB04681186E8247BD7851CD0A
SHA256 / Certificate:oNYJp+PENOh4qaHBvQZbjc8zqn7+4bEbx1zOXloEIIA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.cn
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4169 days


6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4169 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006
10.11.2031
expires in 1911 days


7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:02AC5C266A0B409B8F0B79F2AE462577
Thumbprint:5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
SHA256 / Certificate:dDHl9MPBzkaQd08LYeBUQIg7qaAe0Aumq9eAbtOxGM8=
SHA256 hex / Cert (DANE * 0 1):7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
SHA256 hex / PublicKey (DANE * 1 1):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SHA256 hex / Subject Public Key Information (SPKI):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




2.
1.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025
06.01.2027
expires in 142 days
ic3.gov - 1 entry
2.
1.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025

06.01.2027
expires in 142 days


ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0783488E4ACB0F319876428859BC756C
Thumbprint:8FA63D094DA3C0934E765133C5281B590A344193
SHA256 / Certificate:eUE0q3l/ocaUTrB8xTrYUAXc1wAJrY2FbO10mEh3+I0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b
SHA256 hex / Subject Public Key Information (SPKI):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




2.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025
06.01.2027
expires in 142 days
ic3.gov - 1 entry

2.
CN=ic3.gov, O=Internet Crime Complaint Center, L=Los Angeles, S=California, C=US
05.12.2025

06.01.2027
expires in 142 days


ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0783488E4ACB0F319876428859BC756C
Thumbprint:8FA63D094DA3C0934E765133C5281B590A344193
SHA256 / Certificate:eUE0q3l/ocaUTrB8xTrYUAXc1wAJrY2FbO10mEh3+I0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b
SHA256 hex / Subject Public Key Information (SPKI):6ccc97dcc79917408cd2ff9bd3ba82f4107f0108cdd9ae134179ef46f32efc5b (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
24.09.2020
24.09.2030
expires in 1499 days


3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
24.09.2020

24.09.2030
expires in 1499 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:085F94C02D857BE8CC14FF53EDA23E2A
Thumbprint:1D7322B41ED99FDD68511BAB786C8E26E0831B3B
SHA256 / Certificate:H4656ajgZsxbODPgazEpdktiJjnVsWP2AOHHkSC/Pu0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
24.09.2020
24.09.2030
expires in 1499 days


4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
24.09.2020

24.09.2030
expires in 1499 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:085F94C02D857BE8CC14FF53EDA23E2A
Thumbprint:1D7322B41ED99FDD68511BAB786C8E26E0831B3B
SHA256 / Certificate:H4656ajgZsxbODPgazEpdktiJjnVsWP2AOHHkSC/Pu0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4169 days


5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4169 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
18.01.2024
10.11.2031
expires in 1911 days


6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
18.01.2024

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0FE032AB844D033106C50C8E13C8B068
Thumbprint:8BF7F178A745A11BAC6AE5B586FC1838EADCB2CF
SHA256 / Certificate:edV7Fd+mXChw6v4Rtjd2WQnP6Te0nBXOfxlAMMqzla0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.cn
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




7.
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006
10.11.2031
expires in 1911 days


7.
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:083BE056904246B1A1756AC95991C74A
Thumbprint:A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
SHA256 / Certificate:Q0ig6URMeMsmXgWNXolEtNhPlmK9Jtslf4k0pEPHAWE=
SHA256 hex / Cert (DANE * 0 1):4348a0e9444c78cb265e058d5e8944b4d84f9662bd26db257f8934a443c70161
SHA256 hex / PublicKey (DANE * 1 1):aff988906dde12955d9bebbf928fdcc31cce328d5b9384f21c8941ca26e20391
SHA256 hex / Subject Public Key Information (SPKI):aff988906dde12955d9bebbf928fdcc31cce328d5b9384f21c8941ca26e20391
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




3.
1.
CN=www.ic3.gov
08.06.2026
09.12.2026
expires in 114 days
www.ic3.gov - 1 entry
3.
1.
CN=www.ic3.gov
08.06.2026

09.12.2026
expires in 114 days


www.ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:067A3933E42D38F227BEE3F96A196BAB
Thumbprint:2B17B23A7042832F660F223D81BF557A21773F04
SHA256 / Certificate:CRtm6y55pcQmx/+PdAJ7i+kv19VJSgEMvjytj4as1oY=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):983f23c884dc2b44658722e0da1bbfb979ef14f57bceb393d75bab4869bffb87
SHA256 hex / Subject Public Key Information (SPKI):983f23c884dc2b44658722e0da1bbfb979ef14f57bceb393d75bab4869bffb87 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://status.geotrust.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=www.ic3.gov
08.06.2026
09.12.2026
expires in 114 days
www.ic3.gov - 1 entry

2.
CN=www.ic3.gov
08.06.2026

09.12.2026
expires in 114 days


www.ic3.gov - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:067A3933E42D38F227BEE3F96A196BAB
Thumbprint:2B17B23A7042832F660F223D81BF557A21773F04
SHA256 / Certificate:CRtm6y55pcQmx/+PdAJ7i+kv19VJSgEMvjytj4as1oY=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):983f23c884dc2b44658722e0da1bbfb979ef14f57bceb393d75bab4869bffb87
SHA256 hex / Subject Public Key Information (SPKI):983f23c884dc2b44658722e0da1bbfb979ef14f57bceb393d75bab4869bffb87 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://status.geotrust.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




3.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017
02.11.2027
expires in 442 days


3.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017

02.11.2027
expires in 442 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0D07782A133FC6F9A57296E131FFD179
Thumbprint:8B3C5B9B867D4BE46D1CB5A01D45D67DC8E94082
SHA256 / Certificate:wG4wf3z8HTL6cqTAM8h7kAGa8hbwd11kl4ouymyKIw4=
SHA256 hex / Cert (DANE * 0 1):c06e307f7cfc1d32fa72a4c033c87b90019af216f0775d64978a2eca6c8a230e
SHA256 hex / PublicKey (DANE * 1 1):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SHA256 hex / Subject Public Key Information (SPKI):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Server Authentication (1.3.6.1.5.5.7.3.1), Client Authentication (1.3.6.1.5.5.7.3.2)




4.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017
02.11.2027
expires in 442 days


4.
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
02.11.2017

02.11.2027
expires in 442 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0D07782A133FC6F9A57296E131FFD179
Thumbprint:8B3C5B9B867D4BE46D1CB5A01D45D67DC8E94082
SHA256 / Certificate:wG4wf3z8HTL6cqTAM8h7kAGa8hbwd11kl4ouymyKIw4=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):4831b9a2b12ff225fa30d7a7200c5af2740536944e07febe965b197571d936ab
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4169 days


5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4169 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
18.01.2024
10.11.2031
expires in 1911 days


6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
18.01.2024

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0FE032AB844D033106C50C8E13C8B068
Thumbprint:8BF7F178A745A11BAC6AE5B586FC1838EADCB2CF
SHA256 / Certificate:edV7Fd+mXChw6v4Rtjd2WQnP6Te0nBXOfxlAMMqzla0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.cn
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




7.
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006
10.11.2031
expires in 1911 days


7.
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:083BE056904246B1A1756AC95991C74A
Thumbprint:A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
SHA256 / Certificate:Q0ig6URMeMsmXgWNXolEtNhPlmK9Jtslf4k0pEPHAWE=
SHA256 hex / Cert (DANE * 0 1):4348a0e9444c78cb265e058d5e8944b4d84f9662bd26db257f8934a443c70161
SHA256 hex / PublicKey (DANE * 1 1):aff988906dde12955d9bebbf928fdcc31cce328d5b9384f21c8941ca26e20391
SHA256 hex / Subject Public Key Information (SPKI):aff988906dde12955d9bebbf928fdcc31cce328d5b9384f21c8941ca26e20391
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




4.
1.
CN=*.azureedge.us, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
19.03.2026
16.09.2026
expires in 30 days
*.azureedge.us, azureedge.us - 2 entries
4.
1.
CN=*.azureedge.us, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
19.03.2026

16.09.2026
expires in 30 days


*.azureedge.us, azureedge.us - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0335F2A11F54BA6357D95131172BAE52
Thumbprint:E321B2F0A1F3E62F5ACE81CF99B5AE6EFBFF072B
SHA256 / Certificate:/Wy3RN/+xA28BZvYzB7WEl9VuHY6jELDVoSYAPQ6VcE=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):5f4964b222063f23a27d249963903b5df249e6bb3d1c8e4fd533099227eaa7e1
SHA256 hex / Subject Public Key Information (SPKI):5f4964b222063f23a27d249963903b5df249e6bb3d1c8e4fd533099227eaa7e1 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




2.
CN=*.azureedge.us, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
19.03.2026
16.09.2026
expires in 30 days
*.azureedge.us, azureedge.us - 2 entries

2.
CN=*.azureedge.us, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
19.03.2026

16.09.2026
expires in 30 days


*.azureedge.us, azureedge.us - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0335F2A11F54BA6357D95131172BAE52
Thumbprint:E321B2F0A1F3E62F5ACE81CF99B5AE6EFBFF072B
SHA256 / Certificate:/Wy3RN/+xA28BZvYzB7WEl9VuHY6jELDVoSYAPQ6VcE=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):5f4964b222063f23a27d249963903b5df249e6bb3d1c8e4fd533099227eaa7e1
SHA256 hex / Subject Public Key Information (SPKI):5f4964b222063f23a27d249963903b5df249e6bb3d1c8e4fd533099227eaa7e1 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1686 days


3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1686 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1686 days


4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1686 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024
09.11.2031
expires in 1910 days


5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024

09.11.2031
expires in 1910 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0E7D75235CA83761577F4CCD24CD6D1D
Thumbprint:B7402517EEAAC80AB04681186E8247BD7851CD0A
SHA256 / Certificate:oNYJp+PENOh4qaHBvQZbjc8zqn7+4bEbx1zOXloEIIA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.cn
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4169 days


6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4169 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006
10.11.2031
expires in 1911 days


7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006

10.11.2031
expires in 1911 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:02AC5C266A0B409B8F0B79F2AE462577
Thumbprint:5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
SHA256 / Certificate:dDHl9MPBzkaQd08LYeBUQIg7qaAe0Aumq9eAbtOxGM8=
SHA256 hex / Cert (DANE * 0 1):7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
SHA256 hex / PublicKey (DANE * 1 1):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SHA256 hex / Subject Public Key Information (SPKI):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
6
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
0
2
4
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
1
3

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
15269568423
leaf cert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2026-06-08 00:00:00
2026-12-08 23:59:59
www.ic3.gov - 1 entries


14523524679
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2026-04-15 00:00:00
2026-10-15 23:59:59
ic3.gov - 1 entries


13522325288
leaf cert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2026-01-22 00:00:00
2026-07-22 23:59:59
www.ic3.gov - 1 entries


12979373803
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2025-12-05 00:00:00
2027-01-05 23:59:59
ic3.gov - 1 entries


11470244590
precert
CN=GeoTrust TLS RSA CA G1, OU=www.digicert.com, O=DigiCert Inc, C=US
2025-08-12 00:00:00
2026-02-12 23:59:59
www.ic3.gov - 1 entries


10894756220
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2025-06-26 00:00:00
2026-04-14 23:59:59
www.ic3.gov - 1 entries


10535502324
leaf cert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2025-05-25 00:00:00
2026-04-14 23:59:59
www.ic3.gov - 1 entries


8279505287
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-09-28 00:00:00
2025-09-28 23:59:59
www.ic3.gov - 1 entries


8042138547
leaf cert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-08-27 00:00:00
2025-08-27 23:59:59
www.ic3.gov - 1 entries


7882040288
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-08-06 00:00:00
2025-01-03 23:59:59
*.ic3.gov, ic3.gov, mail1.ic3.gov, mail2.ic3.gov - 4 entries


6473915795
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-12-31 00:00:00
2024-12-31 23:59:59
www.ic3.gov - 1 entries


6278972600
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-11-29 00:00:00
2024-11-29 23:59:59
www.ic3.gov - 1 entries


6104559188
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-10-31 00:00:00
2024-11-30 23:59:59
*.ic3.gov, ic3.gov, mail1.ic3.gov, mail2.ic3.gov - 4 entries


 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Issuerlast 7 daysactivenum Certs
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
4
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
2

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
14714857513
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-09-27 22:00:00
2025-09-28 21:59:59
www.ic3.gov
1 entries


14714871401
leaf cert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-08-26 22:00:00
2025-08-27 21:59:59
www.ic3.gov
1 entries


15061274794
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-08-05 22:00:00
2025-01-03 22:59:59
*.ic3.gov, ic3.gov, mail1.ic3.gov, mail2.ic3.gov
4 entries


11475760421
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-12-30 23:00:00
2024-12-31 22:59:59
www.ic3.gov
1 entries


11263687066
precert
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-11-28 23:00:00
2024-11-29 22:59:59
www.ic3.gov
1 entries


12338479356
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-10-30 23:00:00
2024-11-30 22:59:59
*.ic3.gov, ic3.gov, mail1.ic3.gov, mail2.ic3.gov
4 entries


 

11. Html-Content - Entries

Summary


Subresource Integrity (SRI)
DomainnameHtmlElementrel/property∑ size∑ problems∑ int.∑ ext.∑ Origin poss.∑ SRI ParseErrors∑ SRI valid∑ SRI missing
https://www.ic3.gov/
20.140.151.75
a

60
10,288,809 Bytes
12
46
10
0
0
0


form

1

1
1
0
0
0
0


img

6
2,519 Bytes
0
6
0
0
0
0


link
alternate
2

0


0
0
0


link
stylesheet
2
50,656 Bytes
0
2
0
0
0
0


link
other
4
180,402 Bytes
0
4
0
0
0
0


meta
other
3

0


0
0
0


picture

3

0


0
0
0


script

3
33,204 Bytes
1
2
1
1
0
0
-1
https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
a

1

1
0
1
0
0
0

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
52.126.48.246
a

1

1
0
1
0
0
0

http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2001:489a:3600::13
a

1

1
0
1
0
0
0

https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
a

43
389,538 Bytes
9
31
8
0
0
0


form

1

1
1
0
0
0
0


img

4
1,949 Bytes
0
4
0
0
0
0


link
alternate
2

0


0
0
0


link
stylesheet
2
50,656 Bytes
0
2
0
0
0
0


link
other
4
180,402 Bytes
0
4
0
0
0
0


meta
other
3

0


0
0
0


picture

2

0


0
0
0


script

3
33,204 Bytes
1
2
1
1
0
0
-1
https://20.141.170.64/
20.141.170.64
meta
other
1

0


0
0
0

https://52.126.48.246/
52.126.48.246
meta
other
1

0


0
0
0

https://[2001:489a:3102:0006:0000:0000:0000:0062]/
2001:489a:3102:6::62
meta
other
1

0


0
0
0

https://[2001:489a:3600:0000:0000:0000:0000:0013]/
2001:489a:3600::13
meta
other
1

0


0
0
0

https://20.140.151.75/
20.140.151.75
a

3

0


0
0
0


img

6

0


0
0
0


link
stylesheet
2

0


0
0
0


link
other
2

0


0
0
0


meta
other
4

0


0
0
0

 

Details (currently limited to 500 rows - some problems with spam users)

DomainnameHtml-Elementname/equiv/ property/relhref/src/contentHttpStatusmsgStatus
https://www.ic3.gov/
20.140.151.75
a

#


1
ok















a

#fileTerms


1
ok















a

#main-content


1
ok















a

/
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





15244 Bytes








a

/AnnualReport/Reports
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11086 Bytes








a

/AnnualReport/Reports/2025_IC3Report.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





3362954 Bytes








a

/ContactFBICyber
500
Internal Server Error
1
Server Error
text/html; charset=utf-8
X-Content-Type-Options nosniff found





0 Bytes








a

/CrimeInfo/AccountTakeover
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12730 Bytes








a

/CrimeInfo/BEC
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10906 Bytes








a

/CrimeInfo/Botnet-DDoS
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12563 Bytes








a

/CrimeInfo/ChineseAuthorityImpersonation
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11578 Bytes








a

/CrimeInfo/Cryptocurrency
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12581 Bytes








a

/CrimeInfo/DataBreach
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10906 Bytes








a

/CrimeInfo/ElderFraud
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13151 Bytes








a

/CrimeInfo/Investment
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13726 Bytes








a

/CrimeInfo/Ransomware
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11404 Bytes








a

/CrimeInfo/TechSupportGovImpersonation
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13270 Bytes








a

/CSA
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10902 Bytes








a

/CSA/2026/260526.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





583714 Bytes








a

/CSA/2026/260602.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





375611 Bytes








a

/CSA/2026/260603.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





4159427 Bytes








a

/CSA/2026/260702.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





486388 Bytes








a

/CSA/2026/260713.pdf
200

1
ok
application/pdf
X-Content-Type-Options nosniff found





834171 Bytes








a

/CSA/RSS
200

1
Problems with Content-Type - Header - see details
application/rss+xml
X-Content-Type-Options nosniff found


Unknown Combination of MediaType "application" and Media Sub Type "rss+xml". Combinations must be IANA-registered, see https://www.iana.org/assignments/media-types/media-types.xhtml


1264 Bytes








a

/Egress/https/report.cybertip.org/443/B144AE1A444A360E687E858B62C3D8913EADD8B1D19AB98AEBD01849ABF34204
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





9616 Bytes








a

/Egress/https/www.facebook.com/443/FBI/F988F3D53ACC9B5D2A4CC8276AE2006662B6D72058374D3E09AA10E7861CC038
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





9622 Bytes








a

/Egress/https/www.instagram.com/443/fbi⁄/0C3BC974864F7E48BA2714D2DCB8530B96520442CBDBD28EEB2C863DF8CE214A
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





425 Bytes








a

/Egress/https/www.linkedin.com/443/company⁄fbi/9F47E4A3420E7E7AA4332809D5B5E3103308E4600403A5A0E0288229078F44FA
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





426 Bytes








a

/Egress/https/www.youtube.com/443/user⁄fbi/373A6D07BCC3254539DB94A6C9BB80B3A69E8EB0E056D081EF2ECF6A19814ADA
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





424 Bytes








a

/Egress/https/x.com/443/FBI/96FF544C349DD9D30D109CEFE46458EB3140AEEB098205B62D9026525651A5C3
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





9593 Bytes








a

/Home/About
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10678 Bytes








a

/Home/FAQ
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13176 Bytes








a

/Home/Index
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





15242 Bytes








a

/Home/Privacy
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13298 Bytes








a

/Outreach/Brochures
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10645 Bytes








a

/Outreach/PrivateSectorEngagement
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12294 Bytes








a

/Outreach/Resources
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





15257 Bytes








a

/PSA
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10484 Bytes








a

/PSA/2026/PSA260615
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





4137 Bytes








a

/PSA/2026/PSA260616
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





3155 Bytes








a

/PSA/2026/PSA260618
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





4563 Bytes








a

/PSA/2026/PSA260626
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





4689 Bytes








a

/PSA/2026/PSA260720
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





6516 Bytes








a

/PSA/RSS
200

1
Problems with Content-Type - Header - see details
application/rss+xml
X-Content-Type-Options nosniff found


Unknown Combination of MediaType "application" and Media Sub Type "rss+xml". Combinations must be IANA-registered, see https://www.iana.org/assignments/media-types/media-types.xhtml


1359 Bytes








a

https://complaint.ic3.gov
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





50559 Bytes








a

https://www.fbi.gov/
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3338 Bytes








a

https://www.fbi.gov/about
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3339 Bytes








a

https://www.fbi.gov/accessibility
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3379 Bytes








a

https://www.fbi.gov/privacy-policy
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3340 Bytes








a

https://www.fbi.gov/scams-and-safety
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3350 Bytes








a

https://www.fbi.gov/tips/
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3339 Bytes








a

https://www.ic3.gov/PSA/2025/PSA250418
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





3014 Bytes








a

https://www.justice.gov/
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





15457 Bytes








a

https://www.justice.gov/about
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





11462 Bytes








a

https://www.justice.gov/doj/privacy-policy
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





16663 Bytes








a

tel:1-202-324-3691


1
ok















form
post
/Search/Results
500
Internal Server Error
1
Server Error

missing X-Content-Type-Options nosniff





0 Bytes








img
src
/assets/img/icon-dot-gov.svg
200

1
ok
no alt-Attributeimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
633 Bytes






ETag: "1daf94352e955f9"



img
src
/assets/img/icon-https.svg
200

1
ok
no alt-Attributeimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
720 Bytes






ETag: "1daf94352e95550"



img
src
/assets/img/material-icons/rss_feed.svg
200

2
ok
alt: RSS Symbolimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
285 Bytes






ETag: "1daf943541a859d"



img
src
/assets/img/us_flag_small.png
200

1
ok
no alt-Attributeimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 244 Bytes






ETag: "1daf94352e95774"



img
src
/assets/img/usa-icons-bg/search--white.svg
200

1
ok
alt: Searchimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
352 Bytes






ETag: "1daf94354b31a60"



link
alternate
/CSA/rss


1
ok















link
alternate
/PSA/rss


1
ok















link
apple-touch-icon
/img/favicon-180.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 66969 Bytes






ETag: "1da74983727e819"



link
icon
/img/favicon-128.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 37410 Bytes






ETag: "1da749837267fa2"



link
icon
/img/favicon-192.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 73000 Bytes






ETag: "1da74983727f0a8"



link
icon
/img/favicon-32.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 3023 Bytes






ETag: "1da74983726e64f"



link
stylesheet
/assets/css/uswds.min.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 48289/524764 Bytes






ETag: W/"1daf94352e1565c"

local SRI possible, possible hash-values:

 

sha256-cxVNpVscfyJnUoXUAHITdMyWkjTu2VRXu+w0H750WyM=
sha384-hFaRJ5P30gjeVzIQN4fJsncTGcp9ewnylL1/+2L+QzbeGS7oqWhV9Ceqcwa/rNe+
sha512-c54cBXlMCHyctBarSG5INC3euZr4UvbldzM8bm0d3K0mKW7Whi4SN+tf7RuRhTQXdztpfyeIgcdVPSEc1PdaTQ==

 

<link rel="stylesheet" href="/assets/css/uswds.min.css" crossorigin="anonymous" integrity="sha256-cxVNpVscfyJnUoXUAHITdMyWkjTu2VRXu+w0H750WyM=" />



link
stylesheet
/css/site.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 2367/9826 Bytes






ETag: W/"1db3b52c40b4062"

local SRI possible, possible hash-values:

 

sha256-U6OicTc60rwDTA8YRWbwZTBtJ3zByAIZCTdxzDsAywc=
sha384-YRw6+O6Dx4bcolNbKWT0pLrLMpzMQJv5jnEzq1M5yzwlCmMymp9qmU39R6V4Fv7m
sha512-KTRr8yweWCBKj9tgT6JbMHDWF6Af0KL7a71J6ZJpB0/59kcAVFWwqoc5iHlN851ggYew7HsMUZU4axATvn4gdQ==

 

<link rel="stylesheet" href="/css/site.css" crossorigin="anonymous" integrity="sha256-U6OicTc60rwDTA8YRWbwZTBtJ3zByAIZCTdxzDsAywc=" />



meta
charset
utf-8


1
ok















meta
format-detection
telephone=no


1
ok















meta
viewport
width=device-width, initial-scale=1.0


1
ok















picture


• source

type: image/webp



1
ok














srcset
/img/ic3_logo.webp


1
ok







/img/ic3_logo.webp
200

1
ok
image/webp
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 37368 Bytes






ETag: "1da749837267c78"

• img




/img/ic3_logo.png
200

1
ok
alt: IC3 Logoimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 148462 Bytes






ETag: "1da74983724ae6e"



picture


• source

type: image/webp



1
ok














srcset
/img/losses.webp


1
ok







/img/losses.webp
200

1
ok
image/webp
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 24802 Bytes






ETag: "1dbb4497c621062"

• img




/img/losses.jpg
200

1
ok
alt: Column chart showing complaint-reported losses over a five-year period: $4.2 billion in 2020, $6.9 billion in 2021, $10.3 billion in 2022, $12.5 billion in 2023, and $16.6 billion in 2024image/jpeg
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 68983 Bytes






ETag: "1dbb4495c33bcf7"



picture


• source

type: image/webp



1
ok














srcset
/img/fbi_seal_new.webp


1
ok







/img/fbi_seal_new.webp
200

1
ok
image/webp
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 118188 Bytes






ETag: "1da74983727202c"

• img




/img/fbi_seal_new.png
200

1
ok
alt: FBI Sealimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 176805 Bytes






ETag: "1da749837245f25"



script
src
/assets/js/uswds.min.js
200

1
ok
defer attribute found text/javascript
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 23668/84549 Bytes






ETag: W/"1daf943554afbc5"

local SRI possible, possible hash-values:

 

sha256-ogA7/HWvxfTHtd1g4F9iRO9GZFM6zHJ/1iie/COo6TA=
sha384-2EhiNiNkhkRLH9w00iNV7UfnvQKbuWKZjm9Sy7mhPBFVj0sVT1lXGGIV5/4Z4/Om
sha512-iEkS/2oGQisJgioadYOkqiscJz4DULhifYSSBuV5Yu3W9BQc4N9B2vUfpqFwiivapuAx9w13Ke4sN/ghmx7UeQ==

 

<script src="/assets/js/uswds.min.js" crossorigin="anonymous" integrity="sha256-ogA7/HWvxfTHtd1g4F9iRO9GZFM6zHJ/1iie/COo6TA=" />



script
src
/assets/js/uswds-init.min.js
200

1
ok
Missing defer / async attribute. text/javascript
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
336 Bytes






ETag: "1daf94354b31a50"

local SRI possible, possible hash-values:

 

sha256-ySbd7kjvcvkMnxstD/j1nWN9MqcPM1S5yGPcntZf4CI=
sha384-fdTnpNXKc4lLWbGwyEpYUtmOBdUJxMdJZT4k28WCXQmp801MD0WrYApu4Lbu/GQ8
sha512-JfvuOYD20WEe+MHjxs94+e381uz0xByQuxAL5eeImmu7ApiFc7nQllnBh+wSznY+bDOZ0GFhIdBzMVl3FosWiw==

 

<script src="/assets/js/uswds-init.min.js" crossorigin="anonymous" integrity="sha256-ySbd7kjvcvkMnxstD/j1nWN9MqcPM1S5yGPcntZf4CI=" />



script
src
https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DOJ
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (gzip): 9200/30230 Bytes






ETag: W/"24fd7299d0e6aa876e32726b0dbe4ea4"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-UJAswHTCORQUyY18QaP3NSUB6b3nXSA5tOkTnAO40sE=
sha384-RqFQH29b3Lh0VpOpU/v9mq2mrq5yQOHadICur9xkSBY1G54cE06vgJ/XjgldY2c6
sha512-EZIagjp/WwnXfIIA7KOzewlv2NT58ZLowJMit+rXaOR2AZTIuBthDEQzl2M9lpbOGN43S1ZkTJYHD0cLUMIBoQ==

 

<script src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DOJ" crossorigin="anonymous" integrity="sha256-UJAswHTCORQUyY18QaP3NSUB6b3nXSA5tOkTnAO40sE=" />


https://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

a

https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
Not Found
1
missing file
text/html; charset=utf-8
missing X-Content-Type-Options nosniff





0 Bytes







http://ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
52.126.48.246
a

https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
Not Found
1
missing file
text/html; charset=utf-8
missing X-Content-Type-Options nosniff





0 Bytes







2001:489a:3600::13
a

https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
Not Found
1
missing file
text/html; charset=utf-8
missing X-Content-Type-Options nosniff





0 Bytes







https://www.ic3.gov/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

a

#


1
ok















a

#fileTerms


1
ok















a

#main-content


1
ok















a

/
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





15248 Bytes








a

/AnnualReport/Reports
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10411 Bytes








a

/ContactFBICyber
500
Internal Server Error
1
Server Error
text/html; charset=utf-8
X-Content-Type-Options nosniff found





0 Bytes








a

/CrimeInfo/AccountTakeover
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12445 Bytes








a

/CrimeInfo/BEC
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10499 Bytes








a

/CrimeInfo/Botnet-DDoS
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12154 Bytes








a

/CrimeInfo/ChineseAuthorityImpersonation
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11131 Bytes








a

/CrimeInfo/Cryptocurrency
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12579 Bytes








a

/CrimeInfo/DataBreach
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10427 Bytes








a

/CrimeInfo/ElderFraud
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12661 Bytes








a

/CrimeInfo/Investment
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





13336 Bytes








a

/CrimeInfo/Ransomware
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11689 Bytes








a

/CrimeInfo/TechSupportGovImpersonation
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12692 Bytes








a

/CSA
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10602 Bytes








a

/Egress/https/www.facebook.com/443/FBI/F988F3D53ACC9B5D2A4CC8276AE2006662B6D72058374D3E09AA10E7861CC038
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





9625 Bytes








a

/Egress/https/www.instagram.com/443/fbi⁄/0C3BC974864F7E48BA2714D2DCB8530B96520442CBDBD28EEB2C863DF8CE214A
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





425 Bytes








a

/Egress/https/www.linkedin.com/443/company⁄fbi/9F47E4A3420E7E7AA4332809D5B5E3103308E4600403A5A0E0288229078F44FA
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





422 Bytes








a

/Egress/https/www.youtube.com/443/user⁄fbi/373A6D07BCC3254539DB94A6C9BB80B3A69E8EB0E056D081EF2ECF6A19814ADA
403
Forbidden
1
Forbidden
text/html
missing X-Content-Type-Options nosniff





425 Bytes








a

/Egress/https/x.com/443/FBI/96FF544C349DD9D30D109CEFE46458EB3140AEEB098205B62D9026525651A5C3
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





9592 Bytes








a

/Home/About
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10277 Bytes








a

/Home/FAQ
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12586 Bytes








a

/Home/Index
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





14219 Bytes








a

/Home/Privacy
200

2
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





12873 Bytes








a

/Outreach/Brochures
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10647 Bytes








a

/Outreach/PrivateSectorEngagement
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





11960 Bytes








a

/Outreach/Resources
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





14617 Bytes








a

/PSA
200

1
ok
text/html; charset=utf-8
X-Content-Type-Options nosniff found





10778 Bytes








a

https://www.fbi.gov/
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3318 Bytes








a

https://www.fbi.gov/about
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3343 Bytes








a

https://www.fbi.gov/accessibility
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3336 Bytes








a

https://www.fbi.gov/privacy-policy
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3337 Bytes








a

https://www.fbi.gov/scams-and-safety
403
Forbidden
1
Forbidden
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





3376 Bytes








a

https://www.justice.gov/
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





15457 Bytes








a

https://www.justice.gov/about
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





11462 Bytes








a

https://www.justice.gov/doj/privacy-policy
200

1
ok
text/html; charset=UTF-8
X-Content-Type-Options nosniff found





16663 Bytes








a

tel:1-202-324-3691


1
ok















form
post
/Search/Results
500
Internal Server Error
1
Server Error

missing X-Content-Type-Options nosniff





0 Bytes








img
src
/assets/img/icon-dot-gov.svg
200

1
ok
no alt-Attributeimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
633 Bytes






ETag: "1daf94352e955f9"



img
src
/assets/img/icon-https.svg
200

1
ok
no alt-Attributeimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
720 Bytes






ETag: "1daf94352e95550"



img
src
/assets/img/us_flag_small.png
200

1
ok
no alt-Attributeimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 244 Bytes






ETag: "1daf94352e95774"



img
src
/assets/img/usa-icons-bg/search--white.svg
200

1
ok
alt: Searchimage/svg+xml
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
352 Bytes






ETag: "1daf94354b31a60"



link
alternate
/CSA/rss


1
ok















link
alternate
/PSA/rss


1
ok















link
apple-touch-icon
/img/favicon-180.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 66969 Bytes






ETag: "1da74983727e819"



link
icon
/img/favicon-128.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 37410 Bytes






ETag: "1da749837267fa2"



link
icon
/img/favicon-192.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 73000 Bytes






ETag: "1da74983727f0a8"



link
icon
/img/favicon-32.png
200

1
ok
image/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 3023 Bytes






ETag: "1da74983726e64f"



link
stylesheet
/assets/css/uswds.min.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 48289/524764 Bytes






ETag: W/"1daf94352e1565c"

local SRI possible, possible hash-values:

 

sha256-cxVNpVscfyJnUoXUAHITdMyWkjTu2VRXu+w0H750WyM=
sha384-hFaRJ5P30gjeVzIQN4fJsncTGcp9ewnylL1/+2L+QzbeGS7oqWhV9Ceqcwa/rNe+
sha512-c54cBXlMCHyctBarSG5INC3euZr4UvbldzM8bm0d3K0mKW7Whi4SN+tf7RuRhTQXdztpfyeIgcdVPSEc1PdaTQ==

 

<link rel="stylesheet" href="/assets/css/uswds.min.css" crossorigin="anonymous" integrity="sha256-cxVNpVscfyJnUoXUAHITdMyWkjTu2VRXu+w0H750WyM=" />



link
stylesheet
/css/site.css
200

1
ok
text/css
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 2367/9826 Bytes






ETag: W/"1db3b52c40b4062"

local SRI possible, possible hash-values:

 

sha256-U6OicTc60rwDTA8YRWbwZTBtJ3zByAIZCTdxzDsAywc=
sha384-YRw6+O6Dx4bcolNbKWT0pLrLMpzMQJv5jnEzq1M5yzwlCmMymp9qmU39R6V4Fv7m
sha512-KTRr8yweWCBKj9tgT6JbMHDWF6Af0KL7a71J6ZJpB0/59kcAVFWwqoc5iHlN851ggYew7HsMUZU4axATvn4gdQ==

 

<link rel="stylesheet" href="/css/site.css" crossorigin="anonymous" integrity="sha256-U6OicTc60rwDTA8YRWbwZTBtJ3zByAIZCTdxzDsAywc=" />



meta
charset
utf-8


1
ok















meta
format-detection
telephone=no


1
ok















meta
viewport
width=device-width, initial-scale=1.0


1
ok















picture


• source

type: image/webp



1
ok














srcset
/img/ic3_logo.webp


1
ok







/img/ic3_logo.webp
200

1
ok
image/webp
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 37368 Bytes






ETag: "1da749837267c78"

• img




/img/ic3_logo.png
200

1
ok
alt: IC3 Logoimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 148462 Bytes






ETag: "1da74983724ae6e"



picture


• source

type: image/webp



1
ok














srcset
/img/fbi_seal_new.webp


1
ok







/img/fbi_seal_new.webp
200

1
ok
image/webp
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 118188 Bytes






ETag: "1da74983727202c"

• img




/img/fbi_seal_new.png
200

1
ok
alt: FBI Sealimage/png
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
No Compression - 176805 Bytes






ETag: "1da749837245f25"



script
src
/assets/js/uswds.min.js
200

1
ok
defer attribute found text/javascript
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
Compression (br): 23668/84549 Bytes






ETag: W/"1daf943554afbc5"

local SRI possible, possible hash-values:

 

sha256-ogA7/HWvxfTHtd1g4F9iRO9GZFM6zHJ/1iie/COo6TA=
sha384-2EhiNiNkhkRLH9w00iNV7UfnvQKbuWKZjm9Sy7mhPBFVj0sVT1lXGGIV5/4Z4/Om
sha512-iEkS/2oGQisJgioadYOkqiscJz4DULhifYSSBuV5Yu3W9BQc4N9B2vUfpqFwiivapuAx9w13Ke4sN/ghmx7UeQ==

 

<script src="/assets/js/uswds.min.js" crossorigin="anonymous" integrity="sha256-ogA7/HWvxfTHtd1g4F9iRO9GZFM6zHJ/1iie/COo6TA=" />



script
src
/assets/js/uswds-init.min.js
200

1
ok
Missing defer / async attribute. text/javascript
X-Content-Type-Options nosniff found





Cache-Control: public, max-age=120 - max-age too short.
336 Bytes






ETag: "1daf94354b31a50"

local SRI possible, possible hash-values:

 

sha256-ySbd7kjvcvkMnxstD/j1nWN9MqcPM1S5yGPcntZf4CI=
sha384-fdTnpNXKc4lLWbGwyEpYUtmOBdUJxMdJZT4k28WCXQmp801MD0WrYApu4Lbu/GQ8
sha512-JfvuOYD20WEe+MHjxs94+e381uz0xByQuxAL5eeImmu7ApiFc7nQllnBh+wSznY+bDOZ0GFhIdBzMVl3FosWiw==

 

<script src="/assets/js/uswds-init.min.js" crossorigin="anonymous" integrity="sha256-ySbd7kjvcvkMnxstD/j1nWN9MqcPM1S5yGPcntZf4CI=" />



script
src
https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DOJ
200

1
Problems with Content-Type - Header - see details
async attribute found application/javascript
missing X-Content-Type-Options nosniff


This Combination of MediaType "application" and MediaSubType "javascript" is obsolete. Don't use it. See https://www.iana.org/assignments/media-types/media-types.xhtml to find a correct Combination. Use "text/javascript" instead.


No Cache-Control - header
Compression (gzip): 9200/30230 Bytes






ETag: W/"24fd7299d0e6aa876e32726b0dbe4ea4"

Server-Header Access-Control-Allow-Origin: *
Cross-Origin Resource Sharing (CORS) supported

missing crossorigin=anonymous|use-credentials and integrity - attribute, possible hash-values:

 

sha256-UJAswHTCORQUyY18QaP3NSUB6b3nXSA5tOkTnAO40sE=
sha384-RqFQH29b3Lh0VpOpU/v9mq2mrq5yQOHadICur9xkSBY1G54cE06vgJ/XjgldY2c6
sha512-EZIagjp/WwnXfIIA7KOzewlv2NT58ZLowJMit+rXaOR2AZTIuBthDEQzl2M9lpbOGN43S1ZkTJYHD0cLUMIBoQ==

 

<script src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DOJ" crossorigin="anonymous" integrity="sha256-UJAswHTCORQUyY18QaP3NSUB6b3nXSA5tOkTnAO40sE=" />


https://20.141.170.64/
20.141.170.64
meta
Content-Type
text/html; charset=us-ascii


1
ok














https://52.126.48.246/
52.126.48.246
meta
Content-Type
text/html; charset=us-ascii


1
ok














https://[2001:489a:3102:0006:0000:0000:0000:0062]/
2001:489a:3102:6::62
meta
Content-Type
text/html; charset=us-ascii


1
ok














https://[2001:489a:3600:0000:0000:0000:0000:0013]/
2001:489a:3600::13
meta
Content-Type
text/html; charset=us-ascii


1
ok














https://20.140.151.75/
20.140.151.75
a

https://azure.microsoft.com/en-us/documentation/services/frontdoor/


1
ok















a

https://azure.microsoft.com/en-us/support/options/


1
ok















a

https://portal.azure.com/#create/Microsoft.AFDX


1
ok















img
src
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/chevron.svg


3
ok
no alt-Attribute














img
src
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/cloud_drop.svg


3
ok
no alt-Attribute














link
icon
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/favicon.ico


1
ok















link
shortcut icon
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/favicon.ico


1
ok















link
stylesheet
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/UxFxErrorCss_8097D4DBB3B4874308CB3816C1762BED98637360.css


1
ok















link
stylesheet
https://azurefrontdoorpages.azureedge.net/pages/PageNotFound_files/UxFxStableCssWesternEuropean_6724ABFCA058F28804A76FD40AD14C9D7A6031D9.css


1
ok















meta
Content-Type
text/html; charset=UTF-8


1
ok















meta
X-UA-Compatible
IE=edge


1
ok















meta
msapplication-config
none


1
ok















meta
robots
noindex, nofollow


1
ok














 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://www.ic3.gov/

Summary

Good: No non-document-errors
16 errors
1 warnings

TypeMessagenum found
1.errorAttribute input not allowed on element feOffset at this point.4
2.errorElement feComposite is missing required attribute in2.4
3.errorAn img element with a role attribute must not have an alt attribute whose value is the empty string.2
4.errorAttribute href not allowed on element button at this point.1
5.errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)1
6.errorThe element button must not appear as a descendant of the a element.1
7.errorThe aria-labelledby attribute must not be specified on any div element unless the element has a role value other than caption, code, deletion, emphasis, generic, insertion, paragraph, presentation, strong, subscript, or superscript.1
8.errorNo p element in scope but a p end tag seen.1
9.errorThe heading h3 (with computed level 3) follows the heading h1 (with computed level 1), skipping 1 heading level.1
10.warningConsider using the h1 element as a top-level heading only — or else use the headingoffset attribute (otherwise, all h1 elements are treated as top-level headings by many screen readers and other tools).1

Details


TypeMessage + Sample
1errorAn img element with a role attribute must not have an alt attribute whose value is the empty string.

From line 54, column 25 to line 54, column 147

<img class="usa-banner__icon usa-media-block__img" src="/assets/img/icon-dot-gov.svg" role="img" alt="" aria-hidden="true">
2errorAn img element with a role attribute must not have an alt attribute whose value is the empty string.

From line 63, column 25 to line 63, column 145

<img class="usa-banner__icon usa-media-block__img" src="/assets/img/icon-https.svg" role="img" alt="" aria-hidden="true">
3errorAttribute href not allowed on element button at this point.

From line 253, column 5 to line 253, column 140

.</p> <button id="fileComplaint" class="usa-button usa-button--big" type="button" data-open-modal href="#fileTerms" aria-controls="fileTerms"> <
4errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 258, column 5 to line 258, column 9

/svg> <div>File A
5errorAttribute input not allowed on element feOffset at this point.

From line 271, column 29 to line 271, column 60

<feOffset input="SourceAlpha" />
6errorElement feComposite is missing required attribute in2.

From line 275, column 29 to line 275, column 62

<feComposite in="SourceGraphic" />
7errorAttribute input not allowed on element feOffset at this point.

From line 291, column 29 to line 291, column 60

<feOffset input="SourceAlpha" />
8errorElement feComposite is missing required attribute in2.

From line 295, column 29 to line 295, column 62

<feComposite in="SourceGraphic" />
9errorAttribute input not allowed on element feOffset at this point.

From line 311, column 29 to line 311, column 60

<feOffset input="SourceAlpha" />
10errorElement feComposite is missing required attribute in2.

From line 315, column 29 to line 315, column 62

<feComposite in="SourceGraphic" />
11errorAttribute input not allowed on element feOffset at this point.

From line 318, column 29 to line 318, column 60

<feOffset input="SourceAlpha" />
12errorElement feComposite is missing required attribute in2.

From line 322, column 29 to line 322, column 62

<feComposite in="SourceGraphic" />
13errorThe element button must not appear as a descendant of the a element.

From line 365, column 29 to line 365, column 102

<button class="usa-button margin-left-2px margin-right-2px" type="button">Annual
14errorThe aria-labelledby attribute must not be specified on any div element unless the element has a role value other than caption, code, deletion, emphasis, generic, insertion, paragraph, presentation, strong, subscript, or superscript.

From line 536, column 5 to line 536, column 124

main> <div class="usa-modal usa-modal--lg" id="fileTerms" aria-labelledby="fileTermsHeading" aria-describedby="fileTermsDesc">
15errorNo p element in scope but a p end tag seen.

From line 555, column 21 to line 555, column 24

</p>
16errorThe heading h3 (with computed level 3) follows the heading h1 (with computed level 1), skipping 1 heading level.

From line 676, column 25 to line 676, column 28

<h3>Federa
17warningConsider using the h1 element as a top-level heading only — or else use the headingoffset attribute (otherwise, all h1 elements are treated as top-level headings by many screen readers and other tools).

From line 218, column 5 to line 218, column 8

p-1"> <h1>Welcom

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1-35.azuregov-dns.us, ns2-35.azuregov-dns.us, ns3-35.azuregov-dns.us, ns4-35.azuregov-dns.us

 

QNr.DomainTypeNS used
1
us
NS
d.root-servers.net (2001:500:2d::d)

Answer: b.cctld.us, f.cctld.us, k.cctld.us, m.cctld.us, n.cctld.us, w.cctld.us, x.cctld.us, y.cctld.us
2
ns1-35.azuregov-dns.us
NS
b.cctld.us (2001:502:ad09::29)

Answer: ns1-01.azuregov-dns.us, ns2-02.azuregov-dns.us, ns3-01.azuregov-dns.us, ns4-02.azuregov-dns.us

Answer: ns1-01.azuregov-dns.us
195.134.224.1

Answer: ns2-02.azuregov-dns.us
195.134.226.2

Answer: ns3-01.azuregov-dns.us
204.13.120.1

Answer: ns4-02.azuregov-dns.us
204.13.122.2
3
ns2-35.azuregov-dns.us
NS
b.cctld.us (2001:502:ad09::29)

Answer: ns1-01.azuregov-dns.us, ns2-02.azuregov-dns.us, ns3-01.azuregov-dns.us, ns4-02.azuregov-dns.us

Answer: ns1-01.azuregov-dns.us
195.134.224.1

Answer: ns2-02.azuregov-dns.us
195.134.226.2

Answer: ns3-01.azuregov-dns.us
204.13.120.1

Answer: ns4-02.azuregov-dns.us
204.13.122.2
4
ns3-35.azuregov-dns.us
NS
b.cctld.us (2001:502:ad09::29)

Answer: ns1-01.azuregov-dns.us, ns2-02.azuregov-dns.us, ns3-01.azuregov-dns.us, ns4-02.azuregov-dns.us

Answer: ns1-01.azuregov-dns.us
195.134.224.1

Answer: ns2-02.azuregov-dns.us
195.134.226.2

Answer: ns3-01.azuregov-dns.us
204.13.120.1

Answer: ns4-02.azuregov-dns.us
204.13.122.2
5
ns4-35.azuregov-dns.us
NS
b.cctld.us (2001:502:ad09::29)

Answer: ns1-01.azuregov-dns.us, ns2-02.azuregov-dns.us, ns3-01.azuregov-dns.us, ns4-02.azuregov-dns.us

Answer: ns1-01.azuregov-dns.us
195.134.224.1

Answer: ns2-02.azuregov-dns.us
195.134.226.2

Answer: ns3-01.azuregov-dns.us
204.13.120.1

Answer: ns4-02.azuregov-dns.us
204.13.122.2
6
ns1-35.azuregov-dns.us: 195.134.236.35
A
ns1-01.azuregov-dns.us (195.134.224.1)
7
ns1-35.azuregov-dns.us: 2001:489a:4000:10::23
AAAA
ns1-01.azuregov-dns.us (195.134.224.1)
8
ns2-35.azuregov-dns.us: 195.134.238.35
A
ns1-01.azuregov-dns.us (195.134.224.1)
9
ns2-35.azuregov-dns.us: 2001:489a:4002:10::23
AAAA
ns1-01.azuregov-dns.us (195.134.224.1)
10
ns3-35.azuregov-dns.us: 195.134.248.35
A
ns1-01.azuregov-dns.us (195.134.224.1)
11
ns3-35.azuregov-dns.us: 2001:489a:4004:10::23
AAAA
ns1-01.azuregov-dns.us (195.134.224.1)
12
ns4-35.azuregov-dns.us: 195.134.250.35
A
ns1-01.azuregov-dns.us (195.134.224.1)
13
ns4-35.azuregov-dns.us: 2001:489a:4006:10::23
AAAA
ns1-01.azuregov-dns.us (195.134.224.1)

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www-dbfzbhdmagffhxd7.z01.azurefd.us



1
0
z01.azurefd.us
12
unknown
contactemailcaarecordaware@microsoft.com
1
0
www.ic3.gov



1
0
azurefd.us
12
unknown
contactemailcaarecordaware@microsoft.com
1
0
ic3.gov
5
issue
digicert.com
1
0
gov
0

no CAA entry found
1
0
us
0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
ic3.gov
_khghqassscz3aae29b9b22xb3pxffyb
ok
1
0
ic3.gov
v=spf1 a:smtp.ic3.gov mx exp=spf-exp.ic3.gov -all
ok
1
0
www.ic3.gov


1
0
_acme-challenge.ic3.gov

Name Error - The domain name does not exist
1
0
_acme-challenge.www.ic3.gov

Name Error - The domain name does not exist
1
0
_acme-challenge.ic3.gov.ic3.gov

Name Error - The domain name does not exist
1
0
_acme-challenge.www.ic3.gov.ic3.gov

Name Error - The domain name does not exist
1
0
www-dbfzbhdmagffhxd7.z01.azurefd.us


1
0
_acme-challenge.www.ic3.gov.www.ic3.gov

Name Error - The domain name does not exist
1
0
_acme-challenge.www-dbfzbhdmagffhxd7.z01.azurefd.us


1
0
_acme-challenge.www-dbfzbhdmagffhxd7.z01.azurefd.us.www-dbfzbhdmagffhxd7.z01.azurefd.us


1
0

 

16. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

ic3.gov
10
mail1.ic3.gov
02ok

A


65.210.47.37
01ok

AAAA


2600:803:9a0:7::37
01ok

CNAME


00ok
MX

ic3.gov
25
mail2.ic3.gov
02ok

A


65.210.47.38
01ok

AAAA


2600:803:9a0:7::38
01ok

CNAME


00ok
SPF
TXT
ic3.gov

v=spf1 a:smtp.ic3.gov mx exp=spf-exp.ic3.gov -all
ok

A
smtp.ic3.gov

65.210.47.36
ok

AAAA
smtp.ic3.gov

2600:803:9a0:7::36
ok

MX
ic3.gov

mail1.ic3.gov
ok

MX-A
mail1.ic3.gov

65.210.47.37
ok

MX-AAAA
mail1.ic3.gov

2600:803:9a0:7::37
ok

MX
ic3.gov

mail2.ic3.gov
ok

MX-A
mail2.ic3.gov

65.210.47.38
ok

MX-AAAA
mail2.ic3.gov

2600:803:9a0:7::38
ok

TXT
spf-exp.ic3.gov

Mail from %{s} at %{i} rejected: SPF failure.
ok
_dmarc
TXT
_dmarc.ic3.gov

v=DMARC1; p=reject; rua=mailto:postmaster@ic3.gov,mailto:reports@dmarc.cyber.dhs.gov,mailto:dmarcreports@usdoj.gov; ruf=mailto:postmaster@ic3.gov; fo=1; pct=100
ok

TXT
ic3.gov._report._dmarc.dmarc.cyber.dhs.gov

mailto:reports@dmarc.cyber.dhs.gov
okMail domain unequal current domain. Check required, if there is a confirming _report._dmarc-Record. See RFC 7489, 7.1.

TXT
ic3.gov._report._dmarc.usdoj.gov

mailto:dmarcreports@usdoj.gov
okMail domain unequal current domain. Check required, if there is a confirming _report._dmarc-Record. See RFC 7489, 7.1.

TXT
ic3.gov._report._dmarc.dmarc.cyber.dhs.gov

v=DMARC1
okConfirmed. Sending reports to external domain is allowed.

TXT
ic3.gov._report._dmarc.usdoj.gov

v=DMARC1
okConfirmed. Sending reports to external domain is allowed.

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
ic3.gov
20.141.170.64
443
4 Ciphers70.03 sec
0 without, 4 FS
100.00 %
ic3.gov
52.126.48.246
443
4 Ciphers89.52 sec
0 without, 4 FS
100.00 %
ic3.gov
2001:489a:3102:6::62
443
4 Ciphers62.70 sec
0 without, 4 FS
100.00 %
ic3.gov
2001:489a:3600::13
443
4 Ciphers79.52 sec
0 without, 4 FS
100.00 %
Complete

4
16 Ciphers
4.00 Ciphers/Check
301.77 sec75.44 sec/Check
0 without, 16 FS
100.00 %

Details
DomainIPPortCipher (OpenSsl / IANA)
ic3.gov
20.141.170.64
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
4 Ciphers, 70.03 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256


52.126.48.246
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
4 Ciphers, 89.52 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256


2001:489a:3102:6::62
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
4 Ciphers, 62.70 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256


2001:489a:3600::13
443
ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS
4 Ciphers, 79.52 sec
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=dcf27f6a-3247-410d-b34f-5ec11f2e2da6

 

Last Result: https://check-your-website.server-daten.de/?q=ic3.gov - 2026-07-22 11:56:18

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=ic3.gov" target="_blank">Check this Site: ic3.gov</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=ic3.gov