Check DNS, Urls + Redirects, Certificates and Content of your Website



P

Tls-Protocol error

Checked:
25.11.2021 07:21:14


Older results

No older results found


1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
rescript.info
A
75.2.70.75
Seattle/Washington/United States (US) - Amazon.com, Inc.
Hostname: aacb0a264e514dd48.awsglobalaccelerator.com
yes
1
0

A
99.83.190.102
Seattle/Washington/United States (US) - Amazon.com, Inc.
Hostname: aacb0a264e514dd48.awsglobalaccelerator.com
yes
1
0

AAAA

yes


www.rescript.info
CNAME
proxy-ssl.webflow.com
yes
1
0

CNAME
proxy-ssl-geo.webflow.com
yes


www.rescript.info
A
3.248.8.137
Dublin/Leinster/Ireland (IE) - Amazon Technologies Inc.
No Hostname found
no



A
52.49.198.28
Dublin/Leinster/Ireland (IE) - Amazon Technologies Inc.
No Hostname found
no



A
52.212.43.230
Dublin/Leinster/Ireland (IE) - Amazon.com, Inc.
No Hostname found
no


*.rescript.info
A

yes



AAAA

yes



CNAME
cname.vercel-dns.com
yes



2. DNSSEC

Zone (*)DNSSEC - Informations

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 14748, Flags 256



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.12.2021, 00:00:00 +, Signature-Inception: 20.11.2021, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: info
info
1 DS RR in the parent zone found



DS with Algorithm 8, KeyTag 5104, DigestType 2 and Digest GvdUio0+KVDCAwN1ffk5DCbPo54myLao9six5y3Y90Q=



1 RRSIG RR to validate DS RR found



RRSIG-Owner info., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 08.12.2021, 05:00:00 +, Signature-Inception: 25.11.2021, 04:00:00 +, KeyTag 14748, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14748 used to validate the DS RRSet in the parent zone



3 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 5104, Flags 257 (SEP = Secure Entry Point)



Public Key with Algorithm 8, KeyTag 39453, Flags 256



Public Key with Algorithm 8, KeyTag 57003, Flags 256



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner info., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 08.12.2021, 15:31:57 +, Signature-Inception: 17.11.2021, 14:31:57 +, KeyTag 5104, Signer-Name: info



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 5104 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 5104, DigestType 2 and Digest "GvdUio0+KVDCAwN1ffk5DCbPo54myLao9six5y3Y90Q=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: rescript.info
rescript.info
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "08psnscorlse9bj7h6h11nqufv574bo5" between the hashed NSEC3-owner "08pp6trkp2sln9vc67g6v08p8c4aijt2" and the hashed NextOwner "08qf0mmi0voku7fb9c5cecnanhjjdri7". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 08pp6trkp2sln9vc67g6v08p8c4aijt2.info., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 08.12.2021, 15:31:57 +, Signature-Inception: 17.11.2021, 14:31:57 +, KeyTag 39453, Signer-Name: info



DS-Query in the parent zone sends valid NSEC3 RR with the Hash "dr3kecftk5dlgg1gdcs9q10f5vjs86ll" as Owner. That's the Hash of "info" with the NextHashedOwnerName "dr44461aksg9j407b3aj3j2pfm3r455d". So that domain name is the Closest Encloser of "rescript.info". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner dr3kecftk5dlgg1gdcs9q10f5vjs86ll.info., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.12.2021, 06:19:59 +, Signature-Inception: 25.11.2021, 05:19:59 +, KeyTag 39453, Signer-Name: info



0 DNSKEY RR found




Zone: www.rescript.info
www.rescript.info
0 DS RR in the parent zone found

Zone: (root)
(root)
1 DS RR published



DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=



Status: Valid because published



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 14748, Flags 256



Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.12.2021, 00:00:00 +, Signature-Inception: 20.11.2021, 00:00:00 +, KeyTag 20326, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: com
com
1 DS RR in the parent zone found



DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest 4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=



1 RRSIG RR to validate DS RR found



RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 08.12.2021, 05:00:00 +, Signature-Inception: 25.11.2021, 04:00:00 +, KeyTag 14748, Signer-Name: (root)



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14748 used to validate the DS RRSet in the parent zone



2 DNSKEY RR found



Public Key with Algorithm 8, KeyTag 15549, Flags 256



Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)



1 RRSIG RR to validate DNSKEY RR found



RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 01.12.2021, 19:24:21 +, Signature-Inception: 16.11.2021, 19:19:21 +, KeyTag 30909, Signer-Name: com



Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet



Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone

Zone: webflow.com
webflow.com
0 DS RR in the parent zone found



DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "g86reu5kvj14u1gu7mgpipleesv7q1kt" between the hashed NSEC3-owner "g86r6cguqk0maneckl4masulfu9oo428" and the hashed NextOwner "g86rkvk861d9d2m2k6u83n9kc6iq4e8s". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner g86r6cguqk0maneckl4masulfu9oo428.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 02.12.2021, 06:06:50 +, Signature-Inception: 25.11.2021, 04:56:50 +, KeyTag 15549, Signer-Name: com



DS-Query in the parent zone sends valid NSEC3 RR with the Hash "ck0pojmg874ljref7efn8430qvit8bsm" as Owner. That's the Hash of "com" with the NextHashedOwnerName "ck0q1gin43n1arrc9osm6qpqr81h5m9a". So that domain name is the Closest Encloser of "webflow.com". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner ck0pojmg874ljref7efn8430qvit8bsm.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 02.12.2021, 05:23:33 +, Signature-Inception: 25.11.2021, 04:13:33 +, KeyTag 15549, Signer-Name: com



0 DNSKEY RR found




Zone: proxy-ssl.webflow.com
proxy-ssl.webflow.com
0 DS RR in the parent zone found


3. Name Servers

DomainNameserverNS-IP
rescript.info
  ns1.vercel-dns.com
96.45.80.1
Newark/New Jersey/United States (US) - Tiggee LLC


 
2600:180a:1001::1
Reston/Virginia/United States (US) - Tiggee LLC


  ns11.constellix.com
96.45.80.1
Newark/New Jersey/United States (US) - Tiggee LLC


 
2600:180a:1001::1
Reston/Virginia/United States (US) - Tiggee LLC


  ns2.vercel-dns.com
46.31.236.1
Reston/Virginia/United States (US) - Tiggee LLC


 
2600:180b:2001::1
Reston/Virginia/United States (US) - Tiggee LLC

info
  a0.info.afilias-nst.info


  a2.info.afilias-nst.info


  b0.info.afilias-nst.org


  b2.info.afilias-nst.org


  c0.info.afilias-nst.info


  d0.info.afilias-nst.org


webflow.com
  ns-1078.awsdns-06.org / d23e598e3a96b5ffe1b039cdfda72041 -
205.251.196.54
London/England/United Kingdom (GB) - Amazon.com, Inc.


 
2600:9000:5304:3600::1
Seattle/Washington/United States (US) - Amazon.com


  ns-1722.awsdns-23.co.uk / 0462fe62d50c93815baa3ff3975d8bfc -
205.251.198.186
London/England/United Kingdom (GB) - Amazon.com, Inc.


 
2600:9000:5306:ba00::1
Seattle/Washington/United States (US) - Amazon.com


  ns-344.awsdns-43.com / 33bc7256edbe2f6e97a71182c17d2f67 -
205.251.193.88
Paris/Île-de-France/France (FR) - Amazon.com, Inc.


 
2600:9000:5301:5800::1
Seattle/Washington/United States (US) - Amazon.com


  ns-958.awsdns-55.net / bec0844a130101795d62a001484e9558 -
205.251.195.190
Seattle/Washington/United States (US) - Amazon.com, Inc.


 
2600:9000:5303:be00::1
Seattle/Washington/United States (US) - Amazon.com

com
  a.gtld-servers.net


  b.gtld-servers.net


  c.gtld-servers.net


  d.gtld-servers.net


  e.gtld-servers.net


  f.gtld-servers.net


  g.gtld-servers.net


  h.gtld-servers.net


  i.gtld-servers.net


  j.gtld-servers.net


  k.gtld-servers.net


  l.gtld-servers.net


  m.gtld-servers.net


4. SOA-Entries


Domain:info
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:6


Domain:rescript.info
Zone-Name:rescript.info
Primary:ns11.constellix.com
Mail:dns.constellix.com
Serial:2015010166
Refresh:43200
Retry:3600
Expire:1209600
TTL:180
num Entries:6



Domain:com
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:13


Domain:webflow.com
Zone-Name:webflow.com
Primary:ns-1078.awsdns-06.org
Mail:awsdns-hostmaster.amazon.com
Serial:1
Refresh:7200
Retry:900
Expire:1209600
TTL:86400
num Entries:8


5. Screenshots

Startaddress: https://rescript.info, address used: https://rescript.info/, Screenshot created 2021-11-25 07:23:26 +00:0

Mobil (412px x 732px)

198 milliseconds

Screenshot mobile - https://rescript.info/
Mobil + Landscape (732px x 412px)

461 milliseconds

Screenshot mobile landscape - https://rescript.info/
Screen (1280px x 1680px)

401 milliseconds

Screenshot Desktop - https://rescript.info/

Mobile- and other Chrome-Checks

widthheight
visual Viewport412732
content Size412732

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

Chrome-Connection: secure. secure connection settings. The connection to this site is encrypted and authenticated using TLS 1.2, ECDHE_RSA with X25519, and AES_256_GCM.

Chrome-Resources : secure. all served securely. All resources on this page are served securely.

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://rescript.info/
75.2.70.75
301
https://rescript.info/
Html is minified: 109.21 %
0.070
A
Server: openresty
Date: Thu, 25 Nov 2021 06:22:02 GMT
Content-Type: text/html
Content-Length: 166
Connection: close
Location: https://rescript.info/

• http://rescript.info/
99.83.190.102
301
https://rescript.info/
Html is minified: 109.21 %
0.060
A
Server: openresty
Date: Thu, 25 Nov 2021 06:22:02 GMT
Content-Type: text/html
Content-Length: 166
Connection: close
Location: https://rescript.info/

• http://www.rescript.info/
3.248.8.137
301
https://www.rescript.info/
Html is minified: 109.21 %
0.083
A
Server: openresty
Date: Thu, 25 Nov 2021 06:22:02 GMT
Content-Type: text/html
Content-Length: 166
Connection: close
Location: https://www.rescript.info/

• http://www.rescript.info/
52.49.198.28
301
https://www.rescript.info/
Html is minified: 109.21 %
0.063
A
Server: openresty
Date: Thu, 25 Nov 2021 06:22:03 GMT
Content-Type: text/html
Content-Length: 166
Connection: close
Location: https://www.rescript.info/

• http://www.rescript.info/
52.212.43.230
301
https://www.rescript.info/
Html is minified: 109.21 %
0.063
A
Server: openresty
Date: Thu, 25 Nov 2021 06:22:03 GMT
Content-Type: text/html
Content-Length: 166
Connection: close
Location: https://www.rescript.info/

• https://rescript.info/
75.2.70.75 GZip used - 111 / 150 - 26.00 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
403

Html is minified: 110.29 %
2.757
M
Forbidden
small visible content (num chars: 23)
403 Forbidden openresty
Server: openresty
Date: Thu, 25 Nov 2021 06:22:03 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• https://rescript.info/
99.83.190.102 GZip used - 111 / 150 - 26.00 %
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
403

Html is minified: 110.29 %
2.490
M
Forbidden
small visible content (num chars: 23)
403 Forbidden openresty
Server: openresty
Date: Thu, 25 Nov 2021 06:22:07 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip

• https://www.rescript.info/
3.248.8.137
-14

10.046
T
Timeout - The operation has timed out

• https://www.rescript.info/
52.49.198.28
-10

0.437
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://www.rescript.info/
52.212.43.230
-10

0.534
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• http://rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
75.2.70.75
200

0.133

Visible Content:
Server: openresty
Date: Thu, 25 Nov 2021 06:22:25 GMT
Transfer-Encoding: chunked
Connection: close

• http://rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
99.83.190.102
200

0.133

Visible Content:
Server: openresty
Date: Thu, 25 Nov 2021 06:22:25 GMT
Transfer-Encoding: chunked
Connection: close

• http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
3.248.8.137
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
200

Html is minified: 100.00 %
0.214

Visible Content: giAaOHnVobcKE2jnIXnyV9qnXUCrl9Sx8O1WYZY7Iso.0XcTu8AVzULjKPNkL50v9EsIgNLwbODM7U-WNpE6RHE
Server: openresty
Date: Thu, 25 Nov 2021 06:22:26 GMT
Transfer-Encoding: chunked
Connection: close

• http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
52.49.198.28
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
200

Html is minified: 100.00 %
0.154

Visible Content: giAaOHnVobcKE2jnIXnyV9qnXUCrl9Sx8O1WYZY7Iso.0XcTu8AVzULjKPNkL50v9EsIgNLwbODM7U-WNpE6RHE
Server: openresty
Date: Thu, 25 Nov 2021 06:22:26 GMT
Transfer-Encoding: chunked
Connection: close

• http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
52.212.43.230
Inline-JavaScript (∑/total): 0/0 Inline-CSS (∑/total): 0/0
200

Html is minified: 100.00 %
0.154

Visible Content: giAaOHnVobcKE2jnIXnyV9qnXUCrl9Sx8O1WYZY7Iso.0XcTu8AVzULjKPNkL50v9EsIgNLwbODM7U-WNpE6RHE
Server: openresty
Date: Thu, 25 Nov 2021 06:22:26 GMT
Transfer-Encoding: chunked
Connection: close

• https://75.2.70.75/
75.2.70.75
-10

0.080
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://3.248.8.137/
3.248.8.137
-10

0.087
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://52.49.198.28/
52.49.198.28
-10

0.087
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://52.212.43.230/
52.212.43.230
-10

0.080
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

• https://99.83.190.102/
99.83.190.102
-10

0.076
P
SecureChannelFailure - The request was aborted: Could not create SSL/TLS secure channel.

7. Comments


1. General Results, most used to calculate the result

Aname "rescript.info" is domain, public suffix is ".info", top-level-domain is ".info", top-level-domain-type is "generic", tld-manager is "Afilias Limited", num .info-domains preloaded: 1062 (complete: 168171)
Agood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: rescript.info has 2 different ip addresses (authoritative).
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: rescript.info has no ipv6 address.
Agood: No asked Authoritative Name Server had a timeout
AGood: No cookie sent via http.
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
https://rescript.info/ 75.2.70.75


Url with incomplete Content-Type - header - missing charset
https://rescript.info/ 99.83.190.102


Url with incomplete Content-Type - header - missing charset
Ahttp://rescript.info/ 75.2.70.75
301
https://rescript.info/
correct redirect http - https with the same domain name
Ahttp://rescript.info/ 99.83.190.102
301
https://rescript.info/
correct redirect http - https with the same domain name
Bhttps://rescript.info/ 75.2.70.75
403

Missing HSTS-Header
Bhttps://rescript.info/ 99.83.190.102
403

Missing HSTS-Header
Hfatal error: No https - result with http-status 200, no encryption
Khttps://www.rescript.info/ 3.248.8.137, Status -14

https://www.rescript.info/ 52.212.43.230, Status -10
configuration problem - different ip addresses with different status
Khttps://www.rescript.info/ 3.248.8.137, Status -14

https://www.rescript.info/ 52.49.198.28, Status -10
configuration problem - different ip addresses with different status
Mhttps://rescript.info/ 75.2.70.75
403

Misconfiguration - main pages should never send http status 400 - 499
Mhttps://rescript.info/ 99.83.190.102
403

Misconfiguration - main pages should never send http status 400 - 499
Phttps://www.rescript.info/ 52.49.198.28
-10

Error creating a TLS-Connection: IANA TLS Alert No. 80, internal_error. An internal error unrelated to the peer or the correctness of the protocol (such as a memory allocation failure) makes it impossible to continue. SSL_ERROR_INTERNAL_ERROR_ALERT (Mozilla) / ERR_SSL_PROTOCOL_ERROR (Chrome)
Phttps://www.rescript.info/ 52.212.43.230
-10

Error creating a TLS-Connection: IANA TLS Alert No. 80, internal_error. An internal error unrelated to the peer or the correctness of the protocol (such as a memory allocation failure) makes it impossible to continue. SSL_ERROR_INTERNAL_ERROR_ALERT (Mozilla) / ERR_SSL_PROTOCOL_ERROR (Chrome)
Phttps://75.2.70.75/ 75.2.70.75
-10

Error creating a TLS-Connection: No more details available.
Phttps://99.83.190.102/ 99.83.190.102
-10

Error creating a TLS-Connection: No more details available.
Phttps://3.248.8.137/ 3.248.8.137
-10

Error creating a TLS-Connection: No more details available.
Phttps://52.49.198.28/ 52.49.198.28
-10

Error creating a TLS-Connection: No more details available.
Phttps://52.212.43.230/ 52.212.43.230
-10

Error creating a TLS-Connection: No more details available.
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain rescript.info, 2 ip addresses.
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain rescript.info, 2 ip addresses.

2. DNS- and NameServer - Checks

AInfo:: 5 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 3 Name Servers.
AInfo:: 5 Queries complete, 5 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AGood: Some ip addresses of name servers found with the minimum of two DNS Queries. One to find the TLD-Zone, one to ask the TLD-Zone.ns1.vercel-dns.com (2600:180a:1001::1, 96.45.80.1), ns11.constellix.com (2600:180a:1001::1, 96.45.80.1), ns2.vercel-dns.com (2600:180b:2001::1, 46.31.236.1)
AGood (1 - 3.0):: An average of 1.7 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 3 different Name Servers found: ns1.vercel-dns.com, ns11.constellix.com, ns2.vercel-dns.com, 2 Name Servers included in Delegation: ns1.vercel-dns.com, ns2.vercel-dns.com, 2 Name Servers included in 1 Zone definitions: ns1.vercel-dns.com, ns2.vercel-dns.com, 1 Name Servers listed in SOA.Primary: ns11.constellix.com.
AGood: Only one SOA.Primary Name Server found.: ns11.constellix.com.
Error: SOA.Primary Name Server not included in the delegation set.: ns11.constellix.com.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns1.vercel-dns.com, ns2.vercel-dns.com
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 3 different Name Servers found
AGood: All name servers have ipv4- and ipv6-addresses.: 3 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 3 Name Servers, 1 Top Level Domain: com
AGood: Name Servers with different domain names found.: 2 different Domains found
Warning: All Name Servers from the same Country / IP location.: 3 Name Servers, 1 Countries: US
AInfo: Ipv4-Subnet-list: 3 Name Servers, 2 different subnets (first Byte): 46., 96., 2 different subnets (first two Bytes): 46.31., 96.45., 2 different subnets (first three Bytes): 46.31.236., 96.45.80.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 3 Name Servers with IPv6, 1 different subnets (first block): 2600:, 2 different subnets (first two blocks): 2600:180a:, 2600:180b:, 2 different subnets (first three blocks): 2600:180a:1001:, 2600:180b:2001:, 2 different subnets (first four blocks): 2600:180a:1001:0000:, 2600:180b:2001:0000:
AGood: Name Server IPv6 addresses from different subnets found.
AGood: Nameserver supports TCP connections: 6 good Nameserver
AInfo: Nameserver mit different domain names found. May be a problem with DNS-Updates
AGood: Nameserver supports Echo Capitalization: 6 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 6 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 6 good Nameserver
Nameserver doesn't pass all EDNS-Checks: a.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: a0.info.afilias-nst.info: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: a2.info.afilias-nst.info: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: b.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: b0.info.afilias-nst.org: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: b2.info.afilias-nst.org: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: c.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: c0.info.afilias-nst.info: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: d.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: d0.info.afilias-nst.org: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: e.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: f.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: g.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: h.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: i.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: j.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: k.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: l.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: m.gtld-servers.net: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
AGood: All SOA have the same Serial Number
Agood: CAA entries found, creating certificate is limited: letsencrypt.org is allowed to create certificates

3. Content- and Performance-critical Checks

http://rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 75.2.70.75
200

Warning: Not existing ACME-file, but Server sends 200, not 404 or redirect. May be a problem creating a Letsencrypt certificate. Checking /.well-known/acme-challenge/random-filename - a http status 404 - Not Found - is expected. If your server sends content and a http status 200, the validation file (87 bytes, token, dot and the hash of the public part of the account key) may be invisible, so Letsencrypt can't validate your domain. If it is an application that sends this content, perhaps create an exception, so /.well-known/acme-challenge sends raw files. Or create a redirect to another domain and / or port 443, but your Letsencrypt client must support such a solution. Certbot: Use webroot as authenticator - https://certbot.eff.org/docs/using.html Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 99.83.190.102
200

Warning: Not existing ACME-file, but Server sends 200, not 404 or redirect. May be a problem creating a Letsencrypt certificate. Checking /.well-known/acme-challenge/random-filename - a http status 404 - Not Found - is expected. If your server sends content and a http status 200, the validation file (87 bytes, token, dot and the hash of the public part of the account key) may be invisible, so Letsencrypt can't validate your domain. If it is an application that sends this content, perhaps create an exception, so /.well-known/acme-challenge sends raw files. Or create a redirect to another domain and / or port 443, but your Letsencrypt client must support such a solution. Certbot: Use webroot as authenticator - https://certbot.eff.org/docs/using.html Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 3.248.8.137
200

Warning: Not existing ACME-file, but Server sends 200, not 404 or redirect. May be a problem creating a Letsencrypt certificate. Checking /.well-known/acme-challenge/random-filename - a http status 404 - Not Found - is expected. If your server sends content and a http status 200, the validation file (87 bytes, token, dot and the hash of the public part of the account key) may be invisible, so Letsencrypt can't validate your domain. If it is an application that sends this content, perhaps create an exception, so /.well-known/acme-challenge sends raw files. Or create a redirect to another domain and / or port 443, but your Letsencrypt client must support such a solution. Certbot: Use webroot as authenticator - https://certbot.eff.org/docs/using.html Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.49.198.28
200

Warning: Not existing ACME-file, but Server sends 200, not 404 or redirect. May be a problem creating a Letsencrypt certificate. Checking /.well-known/acme-challenge/random-filename - a http status 404 - Not Found - is expected. If your server sends content and a http status 200, the validation file (87 bytes, token, dot and the hash of the public part of the account key) may be invisible, so Letsencrypt can't validate your domain. If it is an application that sends this content, perhaps create an exception, so /.well-known/acme-challenge sends raw files. Or create a redirect to another domain and / or port 443, but your Letsencrypt client must support such a solution. Certbot: Use webroot as authenticator - https://certbot.eff.org/docs/using.html Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.rescript.info/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 52.212.43.230
200

Warning: Not existing ACME-file, but Server sends 200, not 404 or redirect. May be a problem creating a Letsencrypt certificate. Checking /.well-known/acme-challenge/random-filename - a http status 404 - Not Found - is expected. If your server sends content and a http status 200, the validation file (87 bytes, token, dot and the hash of the public part of the account key) may be invisible, so Letsencrypt can't validate your domain. If it is an application that sends this content, perhaps create an exception, so /.well-known/acme-challenge sends raw files. Or create a redirect to another domain and / or port 443, but your Letsencrypt client must support such a solution. Certbot: Use webroot as authenticator - https://certbot.eff.org/docs/using.html Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 140137 milliseconds, 140.137 seconds


8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
rescript.info
75.2.70.75
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
error checking OCSP stapling
ok
rescript.info
75.2.70.75
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
error checking OCSP stapling
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0


rescript.info
99.83.190.102
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
error checking OCSP stapling
ok

rescript.info
99.83.190.102
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
error checking OCSP stapling
ok
no http/2 via ALPN 
Tls.1.2
no Tls.1.1
no Tls.1.0
no http/2 via ALPN
Tls.1.2
no Tls.1.1
no Tls.1.0


9. Certificates

1.
1.
CN=rescript.info
25.11.2021
23.02.2022
expires in 79 days
rescript.info - 1 entry
1.
1.
CN=rescript.info
25.11.2021

23.02.2022
expires in 79 days
rescript.info - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0476598FFA2B6BE044C6E78A5F7EC1B13D4E
Thumbprint:9A2083966CBC655D90DCD5F67444798DB52172E3
SHA256 / Certificate:1JH+Nc9flAojb4QS/X5DgqXca1VH5tVOZnOJ3Umalyg=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):55c6104c2f4cb584c70b6423357e8e9561b9d12d3adbd1f189d2c2d3fd73099b
SHA256 hex / Subject Public Key Information (SPKI):55c6104c2f4cb584c70b6423357e8e9561b9d12d3adbd1f189d2c2d3fd73099b (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://r3.o.lencr.org
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)


2.
CN=R3, O=Let's Encrypt, C=US
04.09.2020
15.09.2025
expires in 1379 days


2.
CN=R3, O=Let's Encrypt, C=US
04.09.2020

15.09.2025
expires in 1379 days


KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:00912B084ACF0C18A753F6D62E25A75F5A
Thumbprint:A053375BFE84E8B748782C7CEE15827A6AF5A405
SHA256 / Certificate:Z63RFmsCCuYbj1/JaBPATCqliZYHloZVcqPH5zdhPf0=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8d02536c887482bc34ff54e41d2ba659bf85b341a0a20afadb5813dcfbcf286d
SHA256 hex / Subject Public Key Information (SPKI):8d02536c887482bc34ff54e41d2ba659bf85b341a0a20afadb5813dcfbcf286d
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)


3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015
04.06.2035
expires in 4928 days


3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015

04.06.2035
expires in 4928 days


KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:008210CFB0D240E3594463E0BB63828B00
Thumbprint:CABD2A79A1076A31F21D253635CB039D4329A5E8
SHA256 / Certificate:lrzsBiZJdvN0YHeazyjFp8/oo8Cq4RqP/O4FwL3fCMY=
SHA256 hex / Cert (DANE * 0 1):96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
SHA256 hex / PublicKey (DANE * 1 1):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SHA256 hex / Subject Public Key Information (SPKI):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:



10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=R3, O=Let's Encrypt, C=US
0
2
2

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
3155048461
leaf cert
CN=R3, O=Let's Encrypt, C=US
2021-11-25 05:18:02
2022-02-23 05:18:01
rescript.info - 1 entries


2974714495
leaf cert
CN=R3, O=Let's Encrypt, C=US
2021-10-02 23:05:47
2021-12-31 23:05:46
*.rescript.info, rescript.info - 2 entries



2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > 2019 are listed

Issuerlast 7 daysactivenum Certs
CN=R3, O=Let's Encrypt, C=US
0 /0 new
1
4

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
5355922588
leaf cert
CN=R3, O=Let's Encrypt, C=US
2021-10-02 21:05:47
2021-12-31 22:05:46
*.rescript.info, rescript.info
2 entries


4949955680
leaf cert
CN=R3, O=Let's Encrypt, C=US
2021-07-28 17:07:32
2021-10-26 17:07:30
*.rescript.info, rescript.info
2 entries


4554572192
leaf cert
CN=R3, O=Let's Encrypt, C=US
2021-05-19 11:12:47
2021-08-17 11:12:47
*.rescript.info, rescript.info
2 entries


4223124916
precert
CN=R3, O=Let's Encrypt, C=US
2021-03-16 10:56:49
2021-06-14 09:56:49
*.rescript.info, rescript.info
2 entries



11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404


12. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.vercel-dns.com, ns11.constellix.com, ns2.vercel-dns.com

QNr.DomainTypeNS used
1
com
NS
a.root-servers.net (2001:503:ba3e::2:30)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
ns1.vercel-dns.com: 2600:180a:1001::1, 96.45.80.1
NS
b.gtld-servers.net (2001:503:231d::2:30)

Answer: ns2.vercel-dns.com
2600:180b:2001::1, 46.31.236.1
3
ns11.constellix.com: 2600:180a:1001::1, 96.45.80.1
NS
b.gtld-servers.net (2001:503:231d::2:30)

Answer: ns21.constellix.com
2600:180b:2001::1, 46.31.236.1

Answer: ns31.constellix.com
2600:180c:3001::1, 43.247.170.1
4
net
NS
b.root-servers.net (2001:500:200::b)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
5
ns41.constellix.net: 2600:180a:4001::1, 96.45.81.1
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns51.constellix.net
2600:180b:5001::1, 46.31.237.1

Answer: ns61.constellix.net
2600:180c:6001::1, 43.247.171.1


13. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
proxy-ssl.webflow.com



1
0
www.rescript.info



1
0
rescript.info
5
issue
letsencrypt.org
1
0
webflow.com
0

no CAA entry found
1
0
info
0

no CAA entry found
1
0
com
0

no CAA entry found
1
0


14. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
rescript.info

ok
1
0
www.rescript.info


1
0
proxy-ssl.webflow.com


1
0
_acme-challenge.rescript.info


1
0
_acme-challenge.www.rescript.info

Name Error - The domain name does not exist
1
0
_acme-challenge.proxy-ssl.webflow.com

missing entry or wrong length
1
0
_acme-challenge.rescript.info.rescript.info


1
0
_acme-challenge.www.rescript.info.rescript.info


1
0
_acme-challenge.www.rescript.info.www.rescript.info

Name Error - The domain name does not exist
1
0
_acme-challenge.proxy-ssl.webflow.com.proxy-ssl.webflow.com

perhaps wrong
1
0


15. Portchecks

No Port checks



Permalink: https://check-your-website.server-daten.de/?i=6a564652-71df-4291-904c-5813be0c4e7e


Last Result: https://check-your-website.server-daten.de/?q=rescript.info - 2021-11-25 07:21:14


Do you like this page? Support this tool, add a link on your page:

<a href="https://check-your-website.server-daten.de/?q=rescript.info" target="_blank">Check this Site: rescript.info</a>