Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
safaricom.et
A
102.218.49.49
Addis Ababa/Ethiopia (ET) - STEP
No Hostname found
yes
1
0

A
102.218.49.116
Addis Ababa/Ethiopia (ET) - STEP
No Hostname found
yes
1
0

AAAA

yes


www.safaricom.et
A
102.218.49.49
Addis Ababa/Ethiopia (ET) - STEP
No Hostname found
yes
1
0

AAAA

yes


*.safaricom.et
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






4 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 46441, Flags 256






Public Key with Algorithm 8, KeyTag 53148, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 20.09.2025, 00:00:00 +, Signature-Inception: 30.08.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: et

et
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "et" and the NextOwner "eu". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: NS, RRSIG, NSEC






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 30356, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 41733, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner et., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 12.09.2025, 02:48:01 +, Signature-Inception: 29.08.2025, 13:28:07 +, KeyTag 30356, Signer-Name: et






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30356 used to validate the DNSKEY RRSet






Error: DNSKEY 30356 signs DNSKEY RRset, but no confirming DS RR in the parent zone found. No chain of trust created.



Zone: safaricom.et

safaricom.et
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "f2hb1p73qq607bdvt66mh62bl4a8qfjn" between the hashed NSEC3-owner "f2hb1p73qq607bdvt66mh62bl4a8qfjn" and the hashed NextOwner "f36r52jim2i2ivkk6944rr7iaghsv7nm". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner f2hb1p73qq607bdvt66mh62bl4a8qfjn.et., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 14.09.2025, 20:51:37 +, Signature-Inception: 31.08.2025, 11:06:14 +, KeyTag 41733, Signer-Name: et






0 DNSKEY RR found









Zone: www.safaricom.et

www.safaricom.et
0 DS RR in the parent zone found

 

3. Name Servers

DomainNameserverNS-IP
www.safaricom.et
  adns1.safaricom.et


  adns2.safaricom.et

safaricom.et
  ns1.safaricombusiness.co.ke / ns1.safaricombusiness.co.ke
41.203.208.129
Nairobi/Nairobi County/Kenya (KE) - Safaricom Limited


  ns2.safaricombusiness.co.ke / ns2.safaricombusiness.co.ke
197.248.128.1
Nairobi/Nairobi County/Kenya (KE) - Safaricom Limited


  ns3.safaricombusiness.co.ke / ns3.safaricombusiness.co.ke
197.248.128.2
Nairobi/Nairobi County/Kenya (KE) - Safaricom Limited


  ns4.safaricombusiness.co.ke / ns4.safaricombusiness.co.ke
41.203.208.130
Nairobi/Nairobi County/Kenya (KE) - Safaricom Limited

et
  a.nic.et


  b.nic.et


  c.nic.et


  d.nic.et

 

4. SOA-Entries


Domain:et
Zone-Name:et
Primary:a.nic.et
Mail:postmaster.ethionet.et
Serial:1756887576
Refresh:600
Retry:1800
Expire:1209600
TTL:3600
num Entries:4


Domain:safaricom.et
Zone-Name:safaricom.et
Primary:ns1.safaricombusiness.co.ke
Mail:root.host29.safaricombusiness.co.ke
Serial:2025071200
Refresh:3600
Retry:1800
Expire:1209600
TTL:86400
num Entries:4


Domain:www.safaricom.et
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:2


5. Screenshots

Startaddress: https://safaricom.et/en, address used: https://safaricom.et/en, Screenshot created 2025-09-03 11:48:44 +00:0

 

Mobil (412px x 732px)

 

262043 milliseconds

 

Mobil + Landscape (732px x 412px)

 

239847 milliseconds

 

Screen (1280px x 1680px)

 

1196 milliseconds

 

Screenshot Desktop - https://safaricom.et/en

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport412732
content Size412732

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://safaricom.et/
102.218.49.49
-14


10.023
T
Timeout - The operation has timed out.

• http://safaricom.et/
102.218.49.116
-14


10.030
T
Timeout - The operation has timed out.

• http://www.safaricom.et/
102.218.49.49
-14


10.020
T
Timeout - The operation has timed out.

• https://safaricom.et/
102.218.49.49 gzip used - 29 / 3 - -866.67 %
307
https://safaricom.et/en
Html is minified: 100.00 %
11.653
B
Server: envoy
Date: Wed, 03 Sep 2025 09:27:00 GMT
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Content-Type-Options: nosniff
permissions-policy: camera=(), geolocation=(), microphone=()
Referrer-Policy: same-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains
x-dns-prefetch-control: on
X-XSS-Protection: 1
X-Frame-Options: SAMEORIGIN
Location: /en
Set-Cookie: NEXT_LOCALE=en; Path=/; Secure; SameSite=lax,cookiesession1=678B76984B2347AC5B57BE5DAEC54749;Expires=Thu, 03 Sep 2026 09:26:29 GMT;Path=/;HttpOnly
x-envoy-upstream-service-time: 3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 29

• https://safaricom.et/
102.218.49.116 gzip used - 29 / 3 - -866.67 %
307
https://safaricom.et/en
Html is minified: 100.00 %
12.074
B
Server: envoy
Date: Wed, 03 Sep 2025 09:26:46 GMT
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Content-Type-Options: nosniff
permissions-policy: camera=(), geolocation=(), microphone=()
Referrer-Policy: same-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains
x-dns-prefetch-control: on
X-XSS-Protection: 1
X-Frame-Options: SAMEORIGIN
Location: /en
Set-Cookie: NEXT_LOCALE=en; Path=/; Secure; SameSite=lax,cookiesession1=678B7699993B13394366026D4CF2FC28;Expires=Thu, 03 Sep 2026 09:26:46 GMT;Path=/;HttpOnly
x-envoy-upstream-service-time: 4
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 29

• https://www.safaricom.et/
102.218.49.49 gzip used - 29 / 3 - -866.67 %
307
https://www.safaricom.et/en
Html is minified: 100.00 %
11.657
B
Server: envoy
Date: Wed, 03 Sep 2025 09:27:13 GMT
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Content-Type-Options: nosniff
permissions-policy: camera=(), geolocation=(), microphone=()
Referrer-Policy: same-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains
x-dns-prefetch-control: on
X-XSS-Protection: 1
X-Frame-Options: SAMEORIGIN
Location: /en
x-envoy-upstream-service-time: 3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 29

• https://safaricom.et/en
gzip used - 33649 / 200347 - 83.20 %
200

Html is minified: 112.97 %
11.970
B
Server: envoy
Date: Wed, 03 Sep 2025 09:27:57 GMT
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Content-Type-Options: nosniff
permissions-policy: camera=(), geolocation=(), microphone=()
Referrer-Policy: same-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains
x-dns-prefetch-control: on
X-XSS-Protection: 1
X-Frame-Options: SAMEORIGIN
Set-Cookie: NEXT_LOCALE=en; Path=/; Secure; SameSite=lax,cookiesession1=678B769837E928142764EDB0C615CA7B;Expires=Thu, 03 Sep 2026 09:27:26 GMT;Path=/;HttpOnly
x-middleware-rewrite: /en
Vary: RSC,Next-Router-State-Tree,Next-Router-Prefetch,Next-Router-Segment-Prefetch,Accept-Encoding
x-nextjs-cache: HIT
x-nextjs-prerender: 1
x-nextjs-stale-time: 4294967294
Cache-Control: s-maxage=120, stale-while-revalidate=31535880
ETag: "100f9esu8ua4afn"
x-envoy-upstream-service-time: 8
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Content-Length: 33649

• https://www.safaricom.et/en
gzip used - 33649 / 200347 - 83.20 %
200

Html is minified: 112.97 %
12.637
B
Server: envoy
Date: Wed, 03 Sep 2025 09:28:11 GMT
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Content-Type-Options: nosniff
permissions-policy: camera=(), geolocation=(), microphone=()
Referrer-Policy: same-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains
x-dns-prefetch-control: on
X-XSS-Protection: 1
X-Frame-Options: SAMEORIGIN
Set-Cookie: NEXT_LOCALE=en; Path=/; Secure; SameSite=lax,cookiesession1=678B769885F1049E7A1DB3B23F9CD227;Expires=Thu, 03 Sep 2026 09:27:40 GMT;Path=/;HttpOnly
x-middleware-rewrite: /en
Vary: RSC,Next-Router-State-Tree,Next-Router-Prefetch,Next-Router-Segment-Prefetch,Accept-Encoding
x-nextjs-cache: HIT
x-nextjs-prerender: 1
x-nextjs-stale-time: 4294967294
Cache-Control: s-maxage=120, stale-while-revalidate=31535880
ETag: "100f9esu8ua4afn"
x-envoy-upstream-service-time: 8
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Content-Length: 33649

• http://safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
102.218.49.49
-14


10.027
T
Timeout - The operation has timed out.
Visible Content:

• http://safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
102.218.49.116
-14


10.023
T
Timeout - The operation has timed out.
Visible Content:

• http://www.safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
102.218.49.49
-14


10.017
T
Timeout - The operation has timed out.
Visible Content:

• https://102.218.49.49/
102.218.49.49
-103


0.470
P
SecureConnectionError (3, 0x80131620). The SSL connection could not be established, see inner exception. Received an unexpected EOF or 0 bytes from the transport stream (FF: PR_END_OF_FILE_ERROR)

• https://102.218.49.116/
102.218.49.116
-103


0.454
P
SecureConnectionError (3, 0x80131620). The SSL connection could not be established, see inner exception. Received an unexpected EOF or 0 bytes from the transport stream (FF: PR_END_OF_FILE_ERROR)

 

7. Comments


1. General Results, most used to calculate the result

Aname "safaricom.et" is domain, public suffix is ".et", top-level-domain is ".et", top-level-domain-type is "country-code", Country is Ethiopia, tld-manager is "Ethio telecom", num .et-domains preloaded: 14 (complete: 276475)
AGood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: safaricom.et has 2 different ip addresses (authoritative).
Warning: Only one ip address found: www.safaricom.et has only one ip address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: safaricom.et has no ipv6 address.
Warning: No ipv6 address found. Ipv6 is the future with a lot of new features. So every domain name should have an ipv6 address. See https://en.wikipedia.org/wiki/IPv6: www.safaricom.et has no ipv6 address.
AGood: No asked Authoritative Name Server had a timeout
Ahttps://safaricom.et/ 102.218.49.49
307
https://safaricom.et/en
Correct redirect https to https
Ahttps://safaricom.et/ 102.218.49.116
307
https://safaricom.et/en
Correct redirect https to https
Ahttps://www.safaricom.et/ 102.218.49.49
307
https://www.safaricom.et/en
Correct redirect https to https
AGood: destination is https
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: All urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset)
BWarning: HSTS max-age is too short - minimum 31536000 = 365 days required, 15552000 seconds = 180 days found
Bhttps://safaricom.et/ 102.218.49.49
307
cookiesession1=678B76984B2347AC5B57BE5DAEC54749;Expires=Thu, 03 Sep 2026 09:26:29 GMT;Path=/;HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://safaricom.et/ 102.218.49.116
307
cookiesession1=678B7699993B13394366026D4CF2FC28;Expires=Thu, 03 Sep 2026 09:26:46 GMT;Path=/;HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://safaricom.et/en
200
cookiesession1=678B769837E928142764EDB0C615CA7B;Expires=Thu, 03 Sep 2026 09:27:26 GMT;Path=/;HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://www.safaricom.et/en
200
cookiesession1=678B769885F1049E7A1DB3B23F9CD227;Expires=Thu, 03 Sep 2026 09:27:40 GMT;Path=/;HttpOnly
Cookie sent via https, but not marked as secure
Bhttps://safaricom.et/ 102.218.49.49
307
cookiesession1=678B76984B2347AC5B57BE5DAEC54749;Expires=Thu, 03 Sep 2026 09:26:29 GMT;Path=/;HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://safaricom.et/ 102.218.49.116
307
cookiesession1=678B7699993B13394366026D4CF2FC28;Expires=Thu, 03 Sep 2026 09:26:46 GMT;Path=/;HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://safaricom.et/en
200
cookiesession1=678B769837E928142764EDB0C615CA7B;Expires=Thu, 03 Sep 2026 09:27:26 GMT;Path=/;HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
Bhttps://www.safaricom.et/en
200
cookiesession1=678B769885F1049E7A1DB3B23F9CD227;Expires=Thu, 03 Sep 2026 09:27:40 GMT;Path=/;HttpOnly
Cookie without a SameSite-Attribute. Possible values are: Strict/Lax/None. Cookie may not work as expected, if "None" is wanted, but browsers use "Lax" as default value.
CError - no preferred version www or non-www. Select one version as preferred version, then add a redirect https + not-preferred version to https + preferred version. Perhaps in your port 443 vHost something like "RewriteEngine on" + "RewriteCond %{SERVER_NAME} = example.com" + "ReWriteRule ^ https://www.example.com%{REQUEST_URI} [END,QSA,R=permanent]" (three rows, without the "). That should create a redirect https + example.com ⇒ https + www.example.com. Or switch both values to use the non-www version as your preferred version.
CError - more then one version with Http-Status 200. After all redirects, all users (and search engines) should see the same https url: Non-www or www, but not both with http status 200.
Osafaricom.et / 102.218.49.49 / 443


Old connection: Cipher Suites without Forward Secrecy (FS) found. Remove all of these Cipher Suites, use only Cipher Suites with Forward Secrecy: Starting with ECDHE- or DHE - the last "E" says: "ephemeral". Or use Tls.1.3, then all Cipher Suites use FS. 17 Cipher Suites without Forward Secrecy found
Osafaricom.et / 102.218.49.116 / 443


Old connection: Cipher Suites without Forward Secrecy (FS) found. Remove all of these Cipher Suites, use only Cipher Suites with Forward Secrecy: Starting with ECDHE- or DHE - the last "E" says: "ephemeral". Or use Tls.1.3, then all Cipher Suites use FS. 17 Cipher Suites without Forward Secrecy found
Owww.safaricom.et / 102.218.49.49 / 443


Old connection: Cipher Suites without Forward Secrecy (FS) found. Remove all of these Cipher Suites, use only Cipher Suites with Forward Secrecy: Starting with ECDHE- or DHE - the last "E" says: "ephemeral". Or use Tls.1.3, then all Cipher Suites use FS. 17 Cipher Suites without Forward Secrecy found
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain safaricom.et, 2 ip addresses.
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain safaricom.et, 2 ip addresses.
Info: Checking the ip addresses of that domain name not exact one certificate found. So it's impossible to check if that domain requires Server Name Indication (SNI).: Domain www.safaricom.et, 1 ip addresses.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.safaricom.et

2. Header-Checks

Asafaricom.et
Content-Security-Policy
Ok: Header without syntax errors found: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
A

Good: default-src directive only with 'none' or 'self', additional sources are blocked.
A

Good: default-src without 'unsafe-inline' or 'unsave-eval'.
A

Good: form-action directive found. That reduces the risk sending data to unwanted domains. form-action is a navigation-directive, so default-src isn't used.
A

Good: frame-ancestors directive found. That limits pages who are allowed to use this page in a frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
A

Good: base-uri directive found. That limits the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
A

Good: object-src only with 'none' or 'self' found, no scheme, no other urls. That blocks object / embed / applet - elements.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A

Good: frame-src without data: defined or frame-src missing and the default-src used as fallback not allows the data: schema. That blocks hidden code injection. Insert <iframe src="data:text/html;charset=utf-8;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGJvZHk+PHA+YmVmb3JlPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPmFsZXJ0KCdYU1MnKTwvc2NyaXB0PjxwPmFmdGVyPC9ib2R5PjwvaHRtbD4="></iframe> in your page and see what happens.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
Permissions-Policy
Ok: Header without syntax errors found: camera=(), geolocation=(), microphone=()
A
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
X-Xss-Protection
Ok: Header without syntax errors found: 1
B

Info: Header is deprecated. May not longer work in modern browsers. 1
Awww.safaricom.et
Content-Security-Policy
Ok: Header without syntax errors found: default-src 'self'; script-src 'self' 'unsafe-inline' www.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' www.google-analytics.com www.googletagmanager.com https://safaricom.bamboohr.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' blob: data: resources.bamboohr.com flagsapi.com i.ytimg.com img.youtube.com ; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; frame-src 'self' https://www.youtube.com/; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;
A

Good: default-src directive only with 'none' or 'self', additional sources are blocked.
A

Good: default-src without 'unsafe-inline' or 'unsave-eval'.
A

Good: form-action directive found. That reduces the risk sending data to unwanted domains. form-action is a navigation-directive, so default-src isn't used.
A

Good: frame-ancestors directive found. That limits pages who are allowed to use this page in a frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
A

Good: base-uri directive found. That limits the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
A

Good: object-src only with 'none' or 'self' found, no scheme, no other urls. That blocks object / embed / applet - elements.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A

Good: frame-src without data: defined or frame-src missing and the default-src used as fallback not allows the data: schema. That blocks hidden code injection. Insert <iframe src="data:text/html;charset=utf-8;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGJvZHk+PHA+YmVmb3JlPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPmFsZXJ0KCdYU1MnKTwvc2NyaXB0PjxwPmFmdGVyPC9ib2R5PjwvaHRtbD4="></iframe> in your page and see what happens.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
Permissions-Policy
Ok: Header without syntax errors found: camera=(), geolocation=(), microphone=()
A
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
X-Xss-Protection
Ok: Header without syntax errors found: 1
B

Info: Header is deprecated. May not longer work in modern browsers. 1
Bsafaricom.et
Cross-Origin-Embedder-Policy
Info: Missing Header
Bsafaricom.et
Cross-Origin-Opener-Policy
Info: Missing Header
Bsafaricom.et
Cross-Origin-Resource-Policy
Info: Missing Header
Bwww.safaricom.et
Cross-Origin-Embedder-Policy
Info: Missing Header
Bwww.safaricom.et
Cross-Origin-Opener-Policy
Info: Missing Header
Bwww.safaricom.et
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 13 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 4 Name Servers.
AInfo:: 13 Queries complete, 5 with IPv6, 8 with IPv4.
Warning: Only some DNS Queries done via ipv6. IPv6 is the future, so the name servers of your name servers should have ipv6 addresses.
Ok (4 - 8):: An average of 3.3 queries per domain name server required to find all ip addresses of all name servers.
AInfo:: 4 different Name Servers found: ns1.safaricombusiness.co.ke, ns2.safaricombusiness.co.ke, ns3.safaricombusiness.co.ke, ns4.safaricombusiness.co.ke, 4 Name Servers included in Delegation: ns1.safaricombusiness.co.ke, ns2.safaricombusiness.co.ke, ns3.safaricombusiness.co.ke, ns4.safaricombusiness.co.ke, 4 Name Servers included in 1 Zone definitions: ns1.safaricombusiness.co.ke, ns2.safaricombusiness.co.ke, ns3.safaricombusiness.co.ke, ns4.safaricombusiness.co.ke, 1 Name Servers listed in SOA.Primary: ns1.safaricombusiness.co.ke.
AGood: Only one SOA.Primary Name Server found.: ns1.safaricombusiness.co.ke.
AGood: SOA.Primary Name Server included in the delegation set.: ns1.safaricombusiness.co.ke.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: ns1.safaricombusiness.co.ke, ns2.safaricombusiness.co.ke, ns3.safaricombusiness.co.ke, ns4.safaricombusiness.co.ke
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 4 different Name Servers found
Warning: No Name Server IPv6 address found. IPv6 is the future, so your name servers should be visible via IPv6.: 4 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 4 Name Servers, 1 Top Level Domain: co.ke
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: safaricombusiness.co.ke
Warning: All Name Servers from the same Country / IP location.: 4 Name Servers, 1 Countries: KE
AInfo: Ipv4-Subnet-list: 4 Name Servers, 2 different subnets (first Byte): 197., 41., 2 different subnets (first two Bytes): 197.248., 41.203., 2 different subnets (first three Bytes): 197.248.128., 41.203.208.
AGood: Name Server IPv4-addresses from different subnet found:
AGood: Nameserver supports TCP connections: 4 good Nameserver
AGood: Nameserver supports Echo Capitalization: 4 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 4 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 4 good Nameserver
Nameserver doesn't pass all EDNS-Checks: adns1.safaricom.et: OP100: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. FLAGS: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. COOKIE: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: adns2.safaricom.et: OP100: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found, no OPT100 expected, no OPT100 found. FLAGS: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. COOKIE: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found. CLIENTSUBNET: ok.
AGood: All SOA have the same Serial Number
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: digicert.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: entrust.net is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: gandi.net is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: globalsign is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: globalsign.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: intcaa.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: letsencrypt.org is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: pki.goog is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: Playbet.et is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: digicert.com is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: entrust.net is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: globalsign is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: globalsign.com is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: letsencrypt.org is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: pki.goog is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: Playbet.et is allowed to create wildcard-certificates
AGood: CAA entries found, creating certificate is limited: sectigo.com is allowed to create wildcard-certificates
Warning: Unknown CAA found: sectigo.com isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: gandi.net isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: globalsign isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: intcaa.com isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: Playbet.et isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: sectigo.com isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: globalsign isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.
Warning: Unknown CAA found: Playbet.et isn't defined. Unknown entry. May be wrong written, may be not longer valid. May be a missing entry in this tool.

4. Content- and Performance-critical Checks

http://safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 102.218.49.49
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 102.218.49.116
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
http://www.safaricom.et/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 102.218.49.49
-14

Fatal: Check of /.well-known/acme-challenge/random-filename has a timeout. Creating a Letsencrypt certificate via http-01 challenge can't work. You need a running webserver (http) and an open port 80. If it's a home server + ipv4, perhaps a correct port forwarding port 80 extern ⇒ working port intern is required. Port 80 / http can redirect to another domain port 80 or port 443, but not other ports. If it's a home server, perhaps your ISP blocks port 80. Then you may use the dns-01 challenge. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://safaricom.et/en
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://www.safaricom.et/en
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
AGood: Every https connection via port 443 supports the http/2 protocol via ALPN.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 1436600 milliseconds, 1436.600 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
safaricom.et
safaricom.et
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
safaricom.et
safaricom.et
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE


safaricom.et
102.218.49.49
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

safaricom.et
102.218.49.49
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE


safaricom.et
102.218.49.116
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

safaricom.et
102.218.49.116
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE


www.safaricom.et
www.safaricom.et
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

www.safaricom.et
www.safaricom.et
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE


www.safaricom.et
102.218.49.49
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

www.safaricom.et
102.218.49.49
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain - incomplete

1CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE

 

9. Certificates

1.
1.
CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE
10.06.2025
10.06.2026 01:59:59
3 hours expired
safaricom.et, www.safaricom.et - 2 entries
1.
1.
CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE
10.06.2025

10.06.2026
0 days expired


safaricom.et, www.safaricom.et - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:055F35B7DDA0200E394657B1EFEB8FAE
Thumbprint:8181F8EF9529B6A3136E483B6BCE70A7F991D4EC
SHA256 / Certificate:XBvvfCKzl4d7Qveg1EAJdVWrrkgtigIVTnglmjHXU/I=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):985a437a31495aa338b21f3cb2331d51070473ba5e28b23a1e38e78caea196e9
SHA256 hex / Subject Public Key Information (SPKI):985a437a31495aa338b21f3cb2331d51070473ba5e28b23a1e38e78caea196e9 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE
10.06.2025
10.06.2026 01:59:59
3 hours expired
safaricom.et, www.safaricom.et - 2 entries

2.
CN=safaricom.et, O=Safaricom PLC, L=Nairobi, C=KE
10.06.2025

10.06.2026
0 days expired


safaricom.et, www.safaricom.et - 2 entries

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:055F35B7DDA0200E394657B1EFEB8FAE
Thumbprint:8181F8EF9529B6A3136E483B6BCE70A7F991D4EC
SHA256 / Certificate:XBvvfCKzl4d7Qveg1EAJdVWrrkgtigIVTnglmjHXU/I=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):985a437a31495aa338b21f3cb2331d51070473ba5e28b23a1e38e78caea196e9
SHA256 hex / Subject Public Key Information (SPKI):985a437a31495aa338b21f3cb2331d51070473ba5e28b23a1e38e78caea196e9 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1754 days


3.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1754 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021
30.03.2031
expires in 1754 days


4.
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
30.03.2021

30.03.2031
expires in 1754 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0CF5BD062B5602F47AB8502C23CCF066
Thumbprint:1B511ABEAD59C6CE207077C0BF0E0043B1382612
SHA256 / Certificate:yAJfn8Zf38lbPKjMeGe5pYe1J3lzlXkXRj/IE9C2Jak=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):59e738e674221702af1edb87c5200c1a4b75f64fae3d2c3d265124c61bd83c79
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024
09.11.2031
expires in 1978 days


5.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
29.10.2024

09.11.2031
expires in 1978 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:0E7D75235CA83761577F4CCD24CD6D1D
Thumbprint:B7402517EEAAC80AB04681186E8247BD7851CD0A
SHA256 / Certificate:oNYJp+PENOh4qaHBvQZbjc8zqn7+4bEbx1zOXloEIIA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:http://ocsp.digicert.cn
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013
15.01.2038
expires in 4237 days


6.
CN=DigiCert Global Root G2, OU=www.digicert.com, O=DigiCert Inc, C=US
01.08.2013

15.01.2038
expires in 4237 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:033AF1E6A711A9A0BB2864B11D09FAE5
Thumbprint:DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
SHA256 / Certificate:yzzLt2Ax5eATj43TmiP53kf/w15DwRRM6ifUalqxy18=
SHA256 hex / Cert (DANE * 0 1):cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
SHA256 hex / PublicKey (DANE * 1 1):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SHA256 hex / Subject Public Key Information (SPKI):8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:





7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006
10.11.2031
expires in 1979 days


7.
CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US
10.11.2006

10.11.2031
expires in 1979 days




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA-1 with RSA Encryption
Serial Number:02AC5C266A0B409B8F0B79F2AE462577
Thumbprint:5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
SHA256 / Certificate:dDHl9MPBzkaQd08LYeBUQIg7qaAe0Aumq9eAbtOxGM8=
SHA256 hex / Cert (DANE * 0 1):7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
SHA256 hex / PublicKey (DANE * 1 1):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SHA256 hex / Subject Public Key Information (SPKI):5a889647220e54d6bd8a16817224520bb5c78e58984bd570506388b9de0f075f
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
5
CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1, O=GlobalSign nv-sa, C=BE
0
0
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
10711929770
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2025-06-10 00:00:00
2026-06-09 23:59:59
safaricom.et, www.safaricom.et - 2 entries


10711898664
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2025-06-10 00:00:00
2026-06-09 23:59:59
www.safaricom.et - 1 entries


8090044254
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2024-09-02 00:00:00
2025-09-01 23:59:59
safaricom.et, www.safaricom.et - 2 entries


5833055510
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-09-11 00:00:00
2024-09-10 23:59:59
safaricom.et, www.safaricom.et - 2 entries


5720659058
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-08-21 00:00:00
2024-08-20 23:59:59
safaricom.et, www.safaricom.et - 2 entries


5060028151
precert
CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1, O=GlobalSign nv-sa, C=BE
2023-04-08 13:22:59
2023-10-05 13:22:59
*.coaching.safaricom.co.ke, *.safaricom.et, imperva.com, melkamtimket.com, npm.safaricombusiness.co.ke, safaricom.et, safbox.safaricombusiness.co.ke, www.melkamtimket.com - 8 entries


 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Issuerlast 7 daysactivenum Certs
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
0
0
2
CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1, O=GlobalSign nv-sa, C=BE
0
0
1

CRT-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
10564116001
leaf cert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-09-10 22:00:00
2024-09-10 21:59:59
safaricom.et, www.safaricom.et
2 entries


10189628479
precert
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US
2023-08-20 22:00:00
2024-08-20 21:59:59
safaricom.et, www.safaricom.et
2 entries


9093992319
precert
CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1, O=GlobalSign nv-sa, C=BE
2023-04-08 11:22:59
2023-10-05 11:22:59
*.coaching.safaricom.co.ke, *.safaricom.et, imperva.com, melkamtimket.com, npm.safaricombusiness.co.ke, safaricom.et, safbox.safaricombusiness.co.ke, www.melkamtimket.com
8 entries


 

11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404

 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://safaricom.et/en

Summary

Good: No non-document-errors
24 errors
19 warnings

TypeMessagenum found
1.errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)14
2.errorThe aria-controls attribute must point to an element in the same document.8
3.errorBad value besh prizes for attribute id on element section: An ID must not contain whitespace.1
4.errorBad value besh t&c for attribute id on element section: An ID must not contain whitespace.1
5.warningEmpty heading.15
6.warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.2
7.warningConsider using the h1 element as a top-level heading only (all h1 elements are treated as top-level headings by many screen readers and other tools).2

Details


TypeMessage + Sample
1errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 11045 to line 1, column 11219

reground"><button class="inline-flex items-center justify-center py-2 " type="button" aria-haspopup="dialog" aria-expanded="false" aria-controls="radix-«R197ndbnb»" data-state="closed"><svg x
2errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 11903 to line 1, column 12446

"ltr"><li><button id="radix-«R1p7ndbnb»-trigger-radix-«Rnp7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«Rnp7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">PERSON
3errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 12844 to line 1, column 13389

></li><li><button id="radix-«R1p7ndbnb»-trigger-radix-«R17p7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«R17p7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">BUSINE
4errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 14634 to line 1, column 15179

></li><li><button id="radix-«R1p7ndbnb»-trigger-radix-«R27p7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«R27p7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">WHAT&#
5errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 15584 to line 1, column 16129

></li><li><button id="radix-«R1p7ndbnb»-trigger-radix-«R2np7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«R2np7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">WORK W
6errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 16531 to line 1, column 17076

></li><li><button id="radix-«R1p7ndbnb»-trigger-radix-«R37p7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«R37p7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">ABOUT
7errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 17474 to line 1, column 18019

></li><li><button id="radix-«R1p7ndbnb»-trigger-radix-«R3np7ndbnb»" data-state="closed" aria-expanded="false" aria-controls="radix-«R1p7ndbnb»-content-radix-«R3np7ndbnb»" class="group inline-flex h-10 w-max items-center justify-center rounded-md bg-background px-2 font-medium transition-colors hover:bg-accent hover:text-accent-foreground focus:bg-accent focus:text-accent-foreground focus:outline-none disabled:pointer-events-none disabled:opacity-50 data-[active]:bg-accent/50 data-[state=open]:bg-accent/50 group text-xs" data-radix-collection-item="">HELP A
8errorBad value besh prizes for attribute id on element section: An ID must not contain whitespace.

From line 1, column 24888 to line 1, column 24935

ontainer"><section class="py-4 md:py-12" id="besh prizes"><div c
9errorThe aria-controls attribute must point to an element in the same document.

From line 1, column 31304 to line 1, column 31831

d w-full"><button class="inline-flex items-center whitespace-nowrap rounded-md text-sm ring-offset-background transition-colors focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-offset-2 disabled:pointer-events-none disabled:opacity-50 border border-input bg-background hover:bg-accent hover:text-accent-foreground h-10 px-4 py-2 w-[280px] justify-start text-left font-normal my-4" type="button" aria-haspopup="dialog" aria-expanded="false" aria-controls="radix-«R5d0m7ndbnb»" data-state="closed"><svg x
10errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 34147 to line 1, column 34241

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
11errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 36915 to line 1, column 37009

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
12errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 39290 to line 1, column 39384

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
13errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 41664 to line 1, column 41758

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
14errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 44055 to line 1, column 44149

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
15errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 46470 to line 1, column 46564

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
16errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 48847 to line 1, column 48941

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
17errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 51235 to line 1, column 51329

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
18errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 53633 to line 1, column 53727

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
19errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 56031 to line 1, column 56125

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
20errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 58428 to line 1, column 58522

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
21errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 60826 to line 1, column 60920

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
22errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 63227 to line 1, column 63321

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
23errorElement div not allowed as child of element button in this context. (Suppressing further errors from this subtree.)

From line 1, column 65611 to line 1, column 65705

n-item=""><div class="flex flex-1 items-center justify-between md:py-4 font-medium transition-all group"><h3 cl
24errorBad value besh t&c for attribute id on element section: An ID must not contain whitespace.

From line 1, column 67626 to line 1, column 67666

ontainer"><section class="py-12" id="besh t&amp;c"><div c
25warningEmpty heading.

From line 1, column 10970 to line 1, column 11044

g:hidden"><h2 id="radix-«R197ndbnbH1»" class="text-lg font-semibold text-foreground"><butto
26warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.

From line 1, column 20264 to line 1, column 20462

ontainer"><section class="relative w-full overflow-hidden flex items-center justify-center max-h-[600px] md:max-h-[900px] lg:max-h-svh h-[60svh] md:h-[80svh] rounded-3xl mt-8" style="background-color:#31B24B"><img a
27warningSection lacks heading. Consider using h2-h6 elements to add identifying headings to all sections, or else use a div element instead for any cases where no heading is needed.

From line 1, column 23063 to line 1, column 23276

ll-width"><section class="relative w-full overflow-hidden flex items-center justify-center max-h-[600px] md:max-h-[900px] lg:max-h-svh h-auto aspect-video md:aspect-[2.5/1]" style="background-color:#31B24B;aspect-ratio:4.4"><img a
28warningConsider using the h1 element as a top-level heading only (all h1 elements are treated as top-level headings by many screen readers and other tools).

From line 1, column 28913 to line 1, column 28972

min-h-64"><h1 class="text-5xl font-bold tracking-tighter text-center">List o
29warningConsider using the h1 element as a top-level heading only (all h1 elements are treated as top-level headings by many screen readers and other tools).

From line 1, column 33476 to line 1, column 33506

(-100px)"><h1 class="text-5xl font-bold">FAQ</h
30warningEmpty heading.

From line 1, column 33809 to line 1, column 33871

-4 gap-4"><h3 data-orientation="vertical" data-state="open" class="flex"><butto
31warningEmpty heading.

From line 1, column 36572 to line 1, column 36636

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
32warningEmpty heading.

From line 1, column 38947 to line 1, column 39011

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
33warningEmpty heading.

From line 1, column 41321 to line 1, column 41385

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
34warningEmpty heading.

From line 1, column 43712 to line 1, column 43776

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
35warningEmpty heading.

From line 1, column 46127 to line 1, column 46191

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
36warningEmpty heading.

From line 1, column 48504 to line 1, column 48568

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
37warningEmpty heading.

From line 1, column 50892 to line 1, column 50956

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
38warningEmpty heading.

From line 1, column 53290 to line 1, column 53354

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
39warningEmpty heading.

From line 1, column 55688 to line 1, column 55752

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
40warningEmpty heading.

From line 1, column 58085 to line 1, column 58149

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
41warningEmpty heading.

From line 1, column 60483 to line 1, column 60547

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
42warningEmpty heading.

From line 1, column 62884 to line 1, column 62948

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto
43warningEmpty heading.

From line 1, column 65268 to line 1, column 65332

-4 gap-4"><h3 data-orientation="vertical" data-state="closed" class="flex"><butto

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: ns1.safaricombusiness.co.ke, ns2.safaricombusiness.co.ke, ns3.safaricombusiness.co.ke, ns4.safaricombusiness.co.ke

 

QNr.DomainTypeNS used
1
ke
NS
d.root-servers.net (2001:500:2d::d)

Answer: kenic.anycastdns.cz, mzizi.kenic.or.ke, ns-ke.afrinic.net, ns.anycast.kenic.or.ke
2
ns1.safaricombusiness.co.ke
NS
mzizi.kenic.or.ke (2001:43f8:10:0:50c0:a8ff:feee:30)

Answer: dns1.safaricombusiness.co.ke, dns2.safaricombusiness.co.ke

Answer: dns1.safaricombusiness.co.ke
41.203.208.19

Answer: dns2.safaricombusiness.co.ke
41.203.208.18
3
ns2.safaricombusiness.co.ke
NS
mzizi.kenic.or.ke (2001:43f8:10:0:50c0:a8ff:feee:30)

Answer: dns1.safaricombusiness.co.ke, dns2.safaricombusiness.co.ke

Answer: dns1.safaricombusiness.co.ke
41.203.208.19

Answer: dns2.safaricombusiness.co.ke
41.203.208.18
4
ns3.safaricombusiness.co.ke
NS
mzizi.kenic.or.ke (2001:43f8:10:0:50c0:a8ff:feee:30)

Answer: dns1.safaricombusiness.co.ke, dns2.safaricombusiness.co.ke

Answer: dns1.safaricombusiness.co.ke
41.203.208.19

Answer: dns2.safaricombusiness.co.ke
41.203.208.18
5
ns4.safaricombusiness.co.ke
NS
mzizi.kenic.or.ke (2001:43f8:10:0:50c0:a8ff:feee:30)

Answer: dns1.safaricombusiness.co.ke, dns2.safaricombusiness.co.ke

Answer: dns1.safaricombusiness.co.ke
41.203.208.19

Answer: dns2.safaricombusiness.co.ke
41.203.208.18
6
ns1.safaricombusiness.co.ke: 41.203.208.129
A
dns1.safaricombusiness.co.ke (41.203.208.19)
7
ns1.safaricombusiness.co.ke: No AAAA record found
AAAA
dns1.safaricombusiness.co.ke (41.203.208.19)
8
ns2.safaricombusiness.co.ke: 197.248.128.1
A
dns1.safaricombusiness.co.ke (41.203.208.19)
9
ns2.safaricombusiness.co.ke: No AAAA record found
AAAA
dns1.safaricombusiness.co.ke (41.203.208.19)
10
ns3.safaricombusiness.co.ke: 197.248.128.2
A
dns1.safaricombusiness.co.ke (41.203.208.19)
11
ns3.safaricombusiness.co.ke: No AAAA record found
AAAA
dns1.safaricombusiness.co.ke (41.203.208.19)
12
ns4.safaricombusiness.co.ke: 41.203.208.130
A
dns1.safaricombusiness.co.ke (41.203.208.19)
13
ns4.safaricombusiness.co.ke: No AAAA record found
AAAA
dns1.safaricombusiness.co.ke (41.203.208.19)

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.safaricom.et
0

no CAA entry found
1
0
safaricom.et
0

no CAA entry found
1
0
et
5
issue
sectigo.com
2
0

9
issuewild
sectigo.com
2
0

5
issue
digicert.com
2
0

9
issuewild
digicert.com
2
0

5
issue
entrust.net
2
0

9
issuewild
entrust.net
2
0

5
issue
gandi.net
2
0

5
issue
globalsign
2
0

9
issuewild
globalsign
2
0

5
issue
globalsign.com
2
0

9
issuewild
globalsign.com
2
0

5
issue
intcaa.com
2
0

5
issue
letsencrypt.org
2
0

9
issuewild
letsencrypt.org
2
0

5
iodef
mailto:report-abuse@globalsign.com
2
0

5
issue
pki.goog
2
0

9
issuewild
pki.goog
2
0

5
issue
Playbet.et
2
0

9
issuewild
Playbet.et
2
0

5
issue
sectigo.com
2
0

9
issuewild
sectigo.com
2
0

8
unknown
wildcardsectigo.com
2
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
safaricom.et
_d76hr15awlz2q555oiqzh1ro0b68v9h
ok
1
0
safaricom.et
35h3lfln64q94sqfc0tq6jv0p9nrqgyg
ok
1
0
safaricom.et
docusign=bad1b219-feb6-48c9-a715-7a08e1e68dfd
ok
1
0
safaricom.et
g8stnl5z6cb6ytcdhqb2jtmv3dmx04qz
ok
1
0
safaricom.et
globalsign-domain-verification=2E7CE0FB47857865371F1944EB0854E6
ok
1
0
safaricom.et
globalsign-domain-verification=98A033C9A91288360F8E842FD90BE95D
ok
1
0
safaricom.et
globalsign-domain-verification=C1F1BD000A0019355F4ADB6372AF0111
ok
1
0
safaricom.et
google-gws-recovery-domain-verification=54142888
ok
1
0
safaricom.et
google-gws-recovery-domain-verification=54582610
ok
1
0
safaricom.et
google-site-verification=WfcWLop1QeDB4jBo3cusb1OVlb99wXbQW2-C6PkTtfI
ok
1
0
safaricom.et
hynp83k4k8mh2q2rfj9b0t5ydkmw7gmf
ok
1
0
safaricom.et
MS=ms19053540
ok
1
0
safaricom.et
MS=ms27726798
ok
1
0
safaricom.et
MS=ms37053801
ok
1
0
safaricom.et
MS=ms49423963
ok
1
0
safaricom.et
r8ttjnm4p7ylmq83vptwhy78vbyf9pn5
ok
1
0
safaricom.et
v=spf1 include:spf.protection.outlook.com ~all
ok
1
0
www.safaricom.et

ok
1
0
_acme-challenge.safaricom.et

Name Error - The domain name does not exist
1
0
_acme-challenge.www.safaricom.et

missing entry or wrong length
1
0
_acme-challenge.safaricom.et.safaricom.et

Name Error - The domain name does not exist
1
0
_acme-challenge.www.safaricom.et.safaricom.et

perhaps wrong
1
0
_acme-challenge.www.safaricom.et.www.safaricom.et

perhaps wrong
1
0

 

16. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

safaricom.et
0
safaricom-et.mail.protection.outlook.com
01ok

A


52.101.68.0
04ok

A


52.101.73.2
04ok

A


52.101.73.12
04ok

A


52.101.73.24
04ok

CNAME


-40ok
SPF
TXT
safaricom.et

v=spf1 include:spf.protection.outlook.com ~all
ok

TXT
spf.protection.outlook.com

v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all
ok
_dmarc
TXT
_dmarc.safaricom.et

v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400;rua=mailto:safaricom-plc@rua.dmp.cisco.com,mailto:csocalerts@safaricom.et;ruf=mailto:safaricom-plc@ruf.dmp.cisco.com,mailto:csocalerts@safaricom.et
ok

TXT
safaricom.et._report._dmarc.rua.dmp.cisco.com

mailto:safaricom-plc@rua.dmp.cisco.com
okMail domain unequal current domain. Check required, if there is a confirming _report._dmarc-Record. See RFC 7489, 7.1.

TXT
safaricom.et._report._dmarc.rua.dmp.cisco.com

v=DMARC1;
okConfirmed. Sending reports to external domain is allowed.

TXT
safaricom.et._report._dmarc.ruf.dmp.cisco.com

mailto:safaricom-plc@ruf.dmp.cisco.com
okMail domain unequal current domain. Check required, if there is a confirming _report._dmarc-Record. See RFC 7489, 7.1.

TXT
safaricom.et._report._dmarc.ruf.dmp.cisco.com

v=DMARC1;
okConfirmed. Sending reports to external domain is allowed.

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
safaricom.et
102.218.49.49
443
46 Ciphers221.37 sec
17 without, 29 FS
63.04 %
safaricom.et
102.218.49.116
443
46 Ciphers222.02 sec
17 without, 29 FS
63.04 %
www.safaricom.et
102.218.49.49
443
46 Ciphers221.79 sec
17 without, 29 FS
63.04 %
Complete

3
138 Ciphers
46.00 Ciphers/Check
665.18 sec221.73 sec/Check
51 without, 87 FS
63.04 %

Details
DomainIPPortCipher (OpenSsl / IANA)
safaricom.et
102.218.49.49
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
46 Ciphers, 221.37 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




DHE-RSA-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x53
FS

TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384

DH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xAA
FS

TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256

DH
RSA
CHACHA20/POLY1305(256)
AEAD




DHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0x00,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

DH
RSA
AESGCM(256)
AEAD




ECDHE-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x61
FS

TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384

ECDH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-AES256-CCM8
(Secure)
TLSv1.2
0xC0,0xA3
FS

TLS_DHE_RSA_WITH_AES_256_CCM_8

DH
RSA
AESCCM8(256)
AEAD




DHE-RSA-AES256-CCM
(Secure)
TLSv1.2
0xC0,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_CCM

DH
RSA
AESCCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




DHE-RSA-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x52
FS

TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256

DH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0x00,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

DH
RSA
AESGCM(128)
AEAD




ECDHE-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x60
FS

TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256

ECDH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-CCM8
(Secure)
TLSv1.2
0xC0,0xA2
FS

TLS_DHE_RSA_WITH_AES_128_CCM_8

DH
RSA
AESCCM8(128)
AEAD




DHE-RSA-AES128-CCM
(Secure)
TLSv1.2
0xC0,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_CCM

DH
RSA
AESCCM(128)
AEAD




ECDHE-RSA-CAMELLIA256-SHA384
(Weak)
TLSv1.2
0xC0,0x77
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384

ECDH
RSA
Camellia(256)
SHA384




DHE-RSA-CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC4
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256

DH
RSA
Camellia(256)
SHA256




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




DHE-RSA-AES256-SHA256
(Weak)
TLSv1.2
0x00,0x6B
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

DH
RSA
AES(256)
SHA256




CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC0
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256

RSA
RSA
Camellia(256)
SHA256




ARIA256-GCM-SHA384
(Weak)
TLSv1.2
0xC0,0x51
No FS

TLS_RSA_WITH_ARIA_256_GCM_SHA384

RSA
RSA
ARIAGCM(256)
AEAD




AES256-GCM-SHA384
(Weak)
TLSv1.2
0x00,0x9D
No FS

TLS_RSA_WITH_AES_256_GCM_SHA384

RSA
RSA
AESGCM(256)
AEAD




AES256-SHA256
(Weak)
TLSv1.2
0x00,0x3D
No FS

TLS_RSA_WITH_AES_256_CBC_SHA256

RSA
RSA
AES(256)
SHA256




AES256-CCM8
(Weak)
TLSv1.2
0xC0,0xA1
No FS

TLS_RSA_WITH_AES_256_CCM_8

RSA
RSA
AESCCM8(256)
AEAD




AES256-CCM
(Weak)
TLSv1.2
0xC0,0x9D
No FS

TLS_RSA_WITH_AES_256_CCM

RSA
RSA
AESCCM(256)
AEAD




ECDHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0xC0,0x76
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

ECDH
RSA
Camellia(128)
SHA256




DHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBE
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

DH
RSA
Camellia(128)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




DHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0x00,0x67
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

DH
RSA
AES(128)
SHA256




CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBA
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256

RSA
RSA
Camellia(128)
SHA256




ARIA128-GCM-SHA256
(Weak)
TLSv1.2
0xC0,0x50
No FS

TLS_RSA_WITH_ARIA_128_GCM_SHA256

RSA
RSA
ARIAGCM(128)
AEAD




AES128-GCM-SHA256
(Weak)
TLSv1.2
0x00,0x9C
No FS

TLS_RSA_WITH_AES_128_GCM_SHA256

RSA
RSA
AESGCM(128)
AEAD




AES128-SHA256
(Weak)
TLSv1.2
0x00,0x3C
No FS

TLS_RSA_WITH_AES_128_CBC_SHA256

RSA
RSA
AES(128)
SHA256




AES128-CCM8
(Weak)
TLSv1.2
0xC0,0xA0
No FS

TLS_RSA_WITH_AES_128_CCM_8

RSA
RSA
AESCCM8(128)
AEAD




AES128-CCM
(Weak)
TLSv1.2
0xC0,0x9C
No FS

TLS_RSA_WITH_AES_128_CCM

RSA
RSA
AESCCM(128)
AEAD




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




DHE-RSA-CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x88
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

DH
RSA
Camellia(256)
SHA1




DHE-RSA-AES256-SHA
(Weak)
SSLv3
0x00,0x39
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

DH
RSA
AES(256)
SHA1




CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x84
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA

RSA
RSA
Camellia(256)
SHA1




AES256-SHA
(Weak)
SSLv3
0x00,0x35
No FS

TLS_RSA_WITH_AES_256_CBC_SHA

RSA
RSA
AES(256)
SHA1




DHE-RSA-CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x45
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

DH
RSA
Camellia(128)
SHA1




DHE-RSA-AES128-SHA
(Weak)
SSLv3
0x00,0x33
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

DH
RSA
AES(128)
SHA1




DHE-RSA-SEED-SHA
(Weak)
SSLv3
0x00,0x9A
FS

TLS_DHE_RSA_WITH_SEED_CBC_SHA

DH
RSA
SEED(128)
SHA1




CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x41
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA

RSA
RSA
Camellia(128)
SHA1




AES128-SHA
(Weak)
SSLv3
0x00,0x2F
No FS

TLS_RSA_WITH_AES_128_CBC_SHA

RSA
RSA
AES(128)
SHA1




SEED-SHA
(Weak)
SSLv3
0x00,0x96
No FS

TLS_RSA_WITH_SEED_CBC_SHA

RSA
RSA
SEED(128)
SHA1


102.218.49.116
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
46 Ciphers, 222.02 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




DHE-RSA-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x53
FS

TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384

DH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xAA
FS

TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256

DH
RSA
CHACHA20/POLY1305(256)
AEAD




DHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0x00,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

DH
RSA
AESGCM(256)
AEAD




ECDHE-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x61
FS

TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384

ECDH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-AES256-CCM8
(Secure)
TLSv1.2
0xC0,0xA3
FS

TLS_DHE_RSA_WITH_AES_256_CCM_8

DH
RSA
AESCCM8(256)
AEAD




DHE-RSA-AES256-CCM
(Secure)
TLSv1.2
0xC0,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_CCM

DH
RSA
AESCCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




DHE-RSA-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x52
FS

TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256

DH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0x00,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

DH
RSA
AESGCM(128)
AEAD




ECDHE-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x60
FS

TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256

ECDH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-CCM8
(Secure)
TLSv1.2
0xC0,0xA2
FS

TLS_DHE_RSA_WITH_AES_128_CCM_8

DH
RSA
AESCCM8(128)
AEAD




DHE-RSA-AES128-CCM
(Secure)
TLSv1.2
0xC0,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_CCM

DH
RSA
AESCCM(128)
AEAD




ECDHE-RSA-CAMELLIA256-SHA384
(Weak)
TLSv1.2
0xC0,0x77
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384

ECDH
RSA
Camellia(256)
SHA384




DHE-RSA-CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC4
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256

DH
RSA
Camellia(256)
SHA256




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




DHE-RSA-AES256-SHA256
(Weak)
TLSv1.2
0x00,0x6B
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

DH
RSA
AES(256)
SHA256




CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC0
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256

RSA
RSA
Camellia(256)
SHA256




ARIA256-GCM-SHA384
(Weak)
TLSv1.2
0xC0,0x51
No FS

TLS_RSA_WITH_ARIA_256_GCM_SHA384

RSA
RSA
ARIAGCM(256)
AEAD




AES256-GCM-SHA384
(Weak)
TLSv1.2
0x00,0x9D
No FS

TLS_RSA_WITH_AES_256_GCM_SHA384

RSA
RSA
AESGCM(256)
AEAD




AES256-SHA256
(Weak)
TLSv1.2
0x00,0x3D
No FS

TLS_RSA_WITH_AES_256_CBC_SHA256

RSA
RSA
AES(256)
SHA256




AES256-CCM8
(Weak)
TLSv1.2
0xC0,0xA1
No FS

TLS_RSA_WITH_AES_256_CCM_8

RSA
RSA
AESCCM8(256)
AEAD




AES256-CCM
(Weak)
TLSv1.2
0xC0,0x9D
No FS

TLS_RSA_WITH_AES_256_CCM

RSA
RSA
AESCCM(256)
AEAD




ECDHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0xC0,0x76
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

ECDH
RSA
Camellia(128)
SHA256




DHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBE
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

DH
RSA
Camellia(128)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




DHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0x00,0x67
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

DH
RSA
AES(128)
SHA256




CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBA
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256

RSA
RSA
Camellia(128)
SHA256




ARIA128-GCM-SHA256
(Weak)
TLSv1.2
0xC0,0x50
No FS

TLS_RSA_WITH_ARIA_128_GCM_SHA256

RSA
RSA
ARIAGCM(128)
AEAD




AES128-GCM-SHA256
(Weak)
TLSv1.2
0x00,0x9C
No FS

TLS_RSA_WITH_AES_128_GCM_SHA256

RSA
RSA
AESGCM(128)
AEAD




AES128-SHA256
(Weak)
TLSv1.2
0x00,0x3C
No FS

TLS_RSA_WITH_AES_128_CBC_SHA256

RSA
RSA
AES(128)
SHA256




AES128-CCM8
(Weak)
TLSv1.2
0xC0,0xA0
No FS

TLS_RSA_WITH_AES_128_CCM_8

RSA
RSA
AESCCM8(128)
AEAD




AES128-CCM
(Weak)
TLSv1.2
0xC0,0x9C
No FS

TLS_RSA_WITH_AES_128_CCM

RSA
RSA
AESCCM(128)
AEAD




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




DHE-RSA-CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x88
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

DH
RSA
Camellia(256)
SHA1




DHE-RSA-AES256-SHA
(Weak)
SSLv3
0x00,0x39
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

DH
RSA
AES(256)
SHA1




CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x84
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA

RSA
RSA
Camellia(256)
SHA1




AES256-SHA
(Weak)
SSLv3
0x00,0x35
No FS

TLS_RSA_WITH_AES_256_CBC_SHA

RSA
RSA
AES(256)
SHA1




DHE-RSA-CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x45
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

DH
RSA
Camellia(128)
SHA1




DHE-RSA-AES128-SHA
(Weak)
SSLv3
0x00,0x33
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

DH
RSA
AES(128)
SHA1




DHE-RSA-SEED-SHA
(Weak)
SSLv3
0x00,0x9A
FS

TLS_DHE_RSA_WITH_SEED_CBC_SHA

DH
RSA
SEED(128)
SHA1




CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x41
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA

RSA
RSA
Camellia(128)
SHA1




AES128-SHA
(Weak)
SSLv3
0x00,0x2F
No FS

TLS_RSA_WITH_AES_128_CBC_SHA

RSA
RSA
AES(128)
SHA1




SEED-SHA
(Weak)
SSLv3
0x00,0x96
No FS

TLS_RSA_WITH_SEED_CBC_SHA

RSA
RSA
SEED(128)
SHA1

www.safaricom.et
102.218.49.49
443
ECDHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xA8
FS
46 Ciphers, 221.79 sec
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
RSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x30
FS

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDH
RSA
AESGCM(256)
AEAD




DHE-RSA-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x53
FS

TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384

DH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-CHACHA20-POLY1305
(Secure)
TLSv1.2
0xCC,0xAA
FS

TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256

DH
RSA
CHACHA20/POLY1305(256)
AEAD




DHE-RSA-AES256-GCM-SHA384
(Secure)
TLSv1.2
0x00,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

DH
RSA
AESGCM(256)
AEAD




ECDHE-ARIA256-GCM-SHA384
(Secure)
TLSv1.2
0xC0,0x61
FS

TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384

ECDH
RSA
ARIAGCM(256)
AEAD




DHE-RSA-AES256-CCM8
(Secure)
TLSv1.2
0xC0,0xA3
FS

TLS_DHE_RSA_WITH_AES_256_CCM_8

DH
RSA
AESCCM8(256)
AEAD




DHE-RSA-AES256-CCM
(Secure)
TLSv1.2
0xC0,0x9F
FS

TLS_DHE_RSA_WITH_AES_256_CCM

DH
RSA
AESCCM(256)
AEAD




ECDHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x2F
FS

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

ECDH
RSA
AESGCM(128)
AEAD




DHE-RSA-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x52
FS

TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256

DH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-GCM-SHA256
(Secure)
TLSv1.2
0x00,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

DH
RSA
AESGCM(128)
AEAD




ECDHE-ARIA128-GCM-SHA256
(Secure)
TLSv1.2
0xC0,0x60
FS

TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256

ECDH
RSA
ARIAGCM(128)
AEAD




DHE-RSA-AES128-CCM8
(Secure)
TLSv1.2
0xC0,0xA2
FS

TLS_DHE_RSA_WITH_AES_128_CCM_8

DH
RSA
AESCCM8(128)
AEAD




DHE-RSA-AES128-CCM
(Secure)
TLSv1.2
0xC0,0x9E
FS

TLS_DHE_RSA_WITH_AES_128_CCM

DH
RSA
AESCCM(128)
AEAD




ECDHE-RSA-CAMELLIA256-SHA384
(Weak)
TLSv1.2
0xC0,0x77
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384

ECDH
RSA
Camellia(256)
SHA384




DHE-RSA-CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC4
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256

DH
RSA
Camellia(256)
SHA256




ECDHE-RSA-AES256-SHA384
(Weak)
TLSv1.2
0xC0,0x28
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384

ECDH
RSA
AES(256)
SHA384




DHE-RSA-AES256-SHA256
(Weak)
TLSv1.2
0x00,0x6B
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

DH
RSA
AES(256)
SHA256




CAMELLIA256-SHA256
(Weak)
TLSv1.2
0x00,0xC0
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256

RSA
RSA
Camellia(256)
SHA256




ARIA256-GCM-SHA384
(Weak)
TLSv1.2
0xC0,0x51
No FS

TLS_RSA_WITH_ARIA_256_GCM_SHA384

RSA
RSA
ARIAGCM(256)
AEAD




AES256-GCM-SHA384
(Weak)
TLSv1.2
0x00,0x9D
No FS

TLS_RSA_WITH_AES_256_GCM_SHA384

RSA
RSA
AESGCM(256)
AEAD




AES256-SHA256
(Weak)
TLSv1.2
0x00,0x3D
No FS

TLS_RSA_WITH_AES_256_CBC_SHA256

RSA
RSA
AES(256)
SHA256




AES256-CCM8
(Weak)
TLSv1.2
0xC0,0xA1
No FS

TLS_RSA_WITH_AES_256_CCM_8

RSA
RSA
AESCCM8(256)
AEAD




AES256-CCM
(Weak)
TLSv1.2
0xC0,0x9D
No FS

TLS_RSA_WITH_AES_256_CCM

RSA
RSA
AESCCM(256)
AEAD




ECDHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0xC0,0x76
FS

TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

ECDH
RSA
Camellia(128)
SHA256




DHE-RSA-CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBE
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256

DH
RSA
Camellia(128)
SHA256




ECDHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0xC0,0x27
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

ECDH
RSA
AES(128)
SHA256




DHE-RSA-AES128-SHA256
(Weak)
TLSv1.2
0x00,0x67
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

DH
RSA
AES(128)
SHA256




CAMELLIA128-SHA256
(Weak)
TLSv1.2
0x00,0xBA
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256

RSA
RSA
Camellia(128)
SHA256




ARIA128-GCM-SHA256
(Weak)
TLSv1.2
0xC0,0x50
No FS

TLS_RSA_WITH_ARIA_128_GCM_SHA256

RSA
RSA
ARIAGCM(128)
AEAD




AES128-GCM-SHA256
(Weak)
TLSv1.2
0x00,0x9C
No FS

TLS_RSA_WITH_AES_128_GCM_SHA256

RSA
RSA
AESGCM(128)
AEAD




AES128-SHA256
(Weak)
TLSv1.2
0x00,0x3C
No FS

TLS_RSA_WITH_AES_128_CBC_SHA256

RSA
RSA
AES(128)
SHA256




AES128-CCM8
(Weak)
TLSv1.2
0xC0,0xA0
No FS

TLS_RSA_WITH_AES_128_CCM_8

RSA
RSA
AESCCM8(128)
AEAD




AES128-CCM
(Weak)
TLSv1.2
0xC0,0x9C
No FS

TLS_RSA_WITH_AES_128_CCM

RSA
RSA
AESCCM(128)
AEAD




ECDHE-RSA-AES256-SHA
(Weak)
TLSv1
0xC0,0x14
FS

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

ECDH
RSA
AES(256)
SHA1




ECDHE-RSA-AES128-SHA
(Weak)
TLSv1
0xC0,0x13
FS

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

ECDH
RSA
AES(128)
SHA1




DHE-RSA-CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x88
FS

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

DH
RSA
Camellia(256)
SHA1




DHE-RSA-AES256-SHA
(Weak)
SSLv3
0x00,0x39
FS

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

DH
RSA
AES(256)
SHA1




CAMELLIA256-SHA
(Weak)
SSLv3
0x00,0x84
No FS

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA

RSA
RSA
Camellia(256)
SHA1




AES256-SHA
(Weak)
SSLv3
0x00,0x35
No FS

TLS_RSA_WITH_AES_256_CBC_SHA

RSA
RSA
AES(256)
SHA1




DHE-RSA-CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x45
FS

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

DH
RSA
Camellia(128)
SHA1




DHE-RSA-AES128-SHA
(Weak)
SSLv3
0x00,0x33
FS

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

DH
RSA
AES(128)
SHA1




DHE-RSA-SEED-SHA
(Weak)
SSLv3
0x00,0x9A
FS

TLS_DHE_RSA_WITH_SEED_CBC_SHA

DH
RSA
SEED(128)
SHA1




CAMELLIA128-SHA
(Weak)
SSLv3
0x00,0x41
No FS

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA

RSA
RSA
Camellia(128)
SHA1




AES128-SHA
(Weak)
SSLv3
0x00,0x2F
No FS

TLS_RSA_WITH_AES_128_CBC_SHA

RSA
RSA
AES(128)
SHA1




SEED-SHA
(Weak)
SSLv3
0x00,0x96
No FS

TLS_RSA_WITH_SEED_CBC_SHA

RSA
RSA
SEED(128)
SHA1

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=d423f15d-7c99-4ea8-90ba-1de4f24b9d6a

 

Last Result: https://check-your-website.server-daten.de/?q=safaricom.et - 2025-09-03 11:25:04

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=safaricom.et" target="_blank">Check this Site: safaricom.et</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=safaricom.et