Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

E

 

Wrong redirect http ⇒ https with new domain name

 

Checked:
03.09.2025 05:52:48

 

Older results

No older results found

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
thenewleafjournal.com
A
5.161.72.160
Ashburn/Virginia/United States (US) - Hetzner Online GmbH
Hostname: static.160.72.161.5.clients.your-server.de
yes
1
0

AAAA
2a01:4ff:f0:86ce::1
Ashburn/Virginia/United States (US) - Hetzner Online GmbH

yes


www.thenewleafjournal.com
A
5.161.72.160
Ashburn/Virginia/United States (US) - Hetzner Online GmbH
Hostname: static.160.72.161.5.clients.your-server.de
yes
1
0

AAAA
2a01:4ff:f0:86ce::1
Ashburn/Virginia/United States (US) - Hetzner Online GmbH

yes


*.thenewleafjournal.com
A
Name Error
yes



AAAA
Name Error
yes



CNAME
Name Error
yes


 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=






Status: Valid because published






4 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 46441, Flags 256






Public Key with Algorithm 8, KeyTag 53148, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 20.09.2025, 00:00:00 +, Signature-Inception: 30.08.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: com

com
1 DS RR in the parent zone found






DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=






1 RRSIG RR to validate DS RR found






RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 15.09.2025, 17:00:00 +, Signature-Inception: 02.09.2025, 16:00:00 +, KeyTag 46441, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46441 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 13, KeyTag 19718, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 13, KeyTag 20545, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner com., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 14.09.2025, 14:02:35 +, Signature-Inception: 30.08.2025, 13:57:35 +, KeyTag 19718, Signer-Name: com






Status: Good - Algorithmus 13 and DNSKEY with KeyTag 19718 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest "isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: thenewleafjournal.com

thenewleafjournal.com
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "lgdc9mia8kqdgqo713cpm4qnaij46pt0" between the hashed NSEC3-owner "lgdc4d46nn00aj8l8rqvadlap6ggjrou" and the hashed NextOwner "lgdcebi8nnsvpcjhh7qc6njg3vocht81". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner lgdc4d46nn00aj8l8rqvadlap6ggjrou.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 09.09.2025, 01:29:34 +, Signature-Inception: 02.09.2025, 00:19:34 +, KeyTag 20545, Signer-Name: com






DS-Query in the parent zone sends valid NSEC3 RR with the Hash "ck0pojmg874ljref7efn8430qvit8bsm" as Owner. That's the Hash of "com" with the NextHashedOwnerName "ck0q3udg8cekkae7rukpgct1dvssh8ll". So that domain name is the Closest Encloser of "thenewleafjournal.com". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner ck0pojmg874ljref7efn8430qvit8bsm.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 08.09.2025, 00:26:03 +, Signature-Inception: 31.08.2025, 23:16:03 +, KeyTag 20545, Signer-Name: com






0 DNSKEY RR found









Zone: www.thenewleafjournal.com

www.thenewleafjournal.com
0 DS RR in the parent zone found

 

3. Name Servers

DomainNameserverNS-IP
www.thenewleafjournal.com
  curitiba.ns.porkbun.com

thenewleafjournal.com
  curitiba.ns.porkbun.com
173.245.58.37
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::adf5:3a25
San Francisco/California/United States (US) - CLOUDFLARE


  fortaleza.ns.porkbun.com
162.159.8.140
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:88c
San Francisco/California/United States (US) - CLOUDFLARE


  maceio.ns.porkbun.com
162.159.11.180
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:bb4
San Francisco/California/United States (US) - CLOUDFLARE


  salvador.ns.porkbun.com
162.159.10.150
Toronto/Ontario/Canada (CA) - Cloudflare, Inc.


 
2400:cb00:2049:1::a29f:a96
San Francisco/California/United States (US) - CLOUDFLARE

com
  a.gtld-servers.net


  b.gtld-servers.net


  c.gtld-servers.net


  d.gtld-servers.net


  e.gtld-servers.net


  f.gtld-servers.net


  g.gtld-servers.net


  h.gtld-servers.net


  i.gtld-servers.net


  j.gtld-servers.net


  k.gtld-servers.net


  l.gtld-servers.net


  m.gtld-servers.net

 

4. SOA-Entries


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1756871540
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:12


Domain:com
Zone-Name:com
Primary:a.gtld-servers.net
Mail:nstld.verisign-grs.com
Serial:1756871560
Refresh:1800
Retry:900
Expire:604800
TTL:900
num Entries:1


Domain:thenewleafjournal.com
Zone-Name:thenewleafjournal.com
Primary:curitiba.ns.porkbun.com
Mail:dns.cloudflare.com
Serial:2379498181
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:8


Domain:www.thenewleafjournal.com
Zone-Name:thenewleafjournal.com
Primary:curitiba.ns.porkbun.com
Mail:dns.cloudflare.com
Serial:2379498181
Refresh:10000
Retry:2400
Expire:604800
TTL:1800
num Entries:1


5. Screenshots

Startaddress: https://thenewleafjournal.com/, address used: https://thenewleafjournal.com/, Screenshot created 2025-09-03 06:00:05 +00:0

 

Mobil (412px x 732px)

 

1071 milliseconds

 

Screenshot mobile - https://thenewleafjournal.com/
Mobil + Landscape (732px x 412px)

 

1063 milliseconds

 

Screenshot mobile landscape - https://thenewleafjournal.com/
Screen (1280px x 1680px)

 

1166 milliseconds

 

Screenshot Desktop - https://thenewleafjournal.com/

 

Mobile- and other Chrome-Checks


widthheight
visual Viewport397732
content Size3972211

 

Good: No horizontal scrollbar. Content-size width = visual Viewport width.

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://thenewleafjournal.com/
5.161.72.160
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
0.263
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:22 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Content-Type: text/html
Content-Length: 162

• http://thenewleafjournal.com/
2a01:4ff:f0:86ce::1
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
0.243
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:22 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Content-Type: text/html
Content-Length: 162

• http://www.thenewleafjournal.com/
5.161.72.160
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
0.134
E
Server: nginx
Date: Wed, 03 Sep 2025 03:53:22 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Content-Type: text/html
Content-Length: 162

• http://www.thenewleafjournal.com/
2a01:4ff:f0:86ce::1
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
0.134
E
Server: nginx
Date: Wed, 03 Sep 2025 03:53:22 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Content-Type: text/html
Content-Length: 162

• https://www.thenewleafjournal.com/
5.161.72.160
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
5.120
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:36 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Type: text/html
Content-Length: 162

• https://www.thenewleafjournal.com/
2a01:4ff:f0:86ce::1
301
https://thenewleafjournal.com/
Html is minified: 109.46 %
4.107
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:43 GMT
Connection: keep-alive
Location: https://thenewleafjournal.com/
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Type: text/html
Content-Length: 162

• https://thenewleafjournal.com/
5.161.72.160 gzip used - 14642 / 62980 - 76.75 %
200

Html is minified: 293.09 %
5.523
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:23 GMT
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Permissions-Policy: geolocation=(self)
Accept-Ranges: bytes
Cache-Control: public, max-age=0
Vary: Accept-Encoding
Content-Security-Policy: font-src https: data:; img-src https: data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self';
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Type: text/html; charset=UTF-8
Content-Length: 14642
Last-Modified: Wed, 03 Sep 2025 03:44:39 GMT
Expires: Wed, 03 Sep 2025 03:53:23 GMT
Content-Encoding: gzip
Content-Language: en-US

• https://thenewleafjournal.com/
2a01:4ff:f0:86ce::1 gzip used - 14642 / 62980 - 76.75 %
200

Html is minified: 293.09 %
4.524
A
Server: nginx
Date: Wed, 03 Sep 2025 03:53:30 GMT
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Permissions-Policy: geolocation=(self)
Accept-Ranges: bytes
Cache-Control: public, max-age=0
Vary: Accept-Encoding
Content-Security-Policy: font-src https: data:; img-src https: data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self';
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Type: text/html; charset=UTF-8
Content-Length: 14642
Last-Modified: Wed, 03 Sep 2025 03:44:39 GMT
Expires: Wed, 03 Sep 2025 03:53:30 GMT
Content-Encoding: gzip
Content-Language: en-US

• http://thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
5.161.72.160
404

Html is minified: 110.61 %
0.133
A
Not Found
Visible Content:
Server: nginx
Date: Wed, 03 Sep 2025 03:53:49 GMT
Connection: keep-alive
Content-Type: text/html
Content-Length: 146

• http://thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2a01:4ff:f0:86ce::1
404

Html is minified: 110.61 %
0.124
A
Not Found
Visible Content:
Server: nginx
Date: Wed, 03 Sep 2025 03:53:49 GMT
Connection: keep-alive
Content-Type: text/html
Content-Length: 146

• http://www.thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
5.161.72.160
404

Html is minified: 110.61 %
0.130
A
Not Found
Visible Content:
Server: nginx
Date: Wed, 03 Sep 2025 03:53:49 GMT
Connection: keep-alive
Content-Type: text/html
Content-Length: 146

• http://www.thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2a01:4ff:f0:86ce::1
404

Html is minified: 110.61 %
0.124
A
Not Found
Visible Content:
Server: nginx
Date: Wed, 03 Sep 2025 03:53:49 GMT
Connection: keep-alive
Content-Type: text/html
Content-Length: 146

• https://5.161.72.160/
5.161.72.160 No Compression used - 1451 / 2556 - 56.77 % possible
200

Html is minified: 182.31 %
5.097
N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Server: nginx
Date: Wed, 03 Sep 2025 03:53:50 GMT
Connection: keep-alive
ETag: "681b1ae6-9fc"
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Security-Policy: default-src 'none'; frame-src 'self' cloudron.io *.cloudron.io; connect-src wss: https: 'self' *.cloudron.io; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; img-src * blob: data:; style-src https: 'unsafe-inline'; object-src 'none'; font-src https: 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'self';
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 2556
Last-Modified: Wed, 07 May 2025 08:33:42 GMT

• https://[2a01:04ff:00f0:86ce:0000:0000:0000:0001]/
2a01:4ff:f0:86ce::1 No Compression used - 1451 / 2556 - 56.77 % possible
200

Html is minified: 182.31 %
4.693
N
Certificate error: RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Server: nginx
Date: Wed, 03 Sep 2025 03:53:56 GMT
Connection: keep-alive
ETag: "681b1ae6-9fc"
Strict-Transport-Security: max-age=63072000
X-XSS-Protection: 1; mode=block
X-Download-Options: noopen
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
Referrer-Policy: same-origin
Content-Security-Policy: default-src 'none'; frame-src 'self' cloudron.io *.cloudron.io; connect-src wss: https: 'self' *.cloudron.io; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; img-src * blob: data:; style-src https: 'unsafe-inline'; object-src 'none'; font-src https: 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'self';
Accept-Ranges: bytes
Content-Type: text/html
Content-Length: 2556
Last-Modified: Wed, 07 May 2025 08:33:42 GMT

 

7. Comments


1. General Results, most used to calculate the result

Aname "thenewleafjournal.com" is domain, public suffix is ".com", top-level-domain is ".com", top-level-domain-type is "generic", tld-manager is "VeriSign Global Registry Services", num .com-domains preloaded: 108094 (complete: 276475)
AGood: All ip addresses are public addresses
AGood: Minimal 2 ip addresses per domain name found: thenewleafjournal.com has 2 different ip addresses (authoritative).
AGood: Minimal 2 ip addresses per domain name found: www.thenewleafjournal.com has 2 different ip addresses (authoritative).
AGood: Ipv4 and Ipv6 addresses per domain name found: thenewleafjournal.com has 1 ipv4, 1 ipv6 addresses
AGood: Ipv4 and Ipv6 addresses per domain name found: www.thenewleafjournal.com has 1 ipv4, 1 ipv6 addresses
AGood: No asked Authoritative Name Server had a timeout
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: non-www is preferred
AGood: No cookie sent via http.
AGood: every https has a Strict Transport Security Header
AGood: HSTS max-age is long enough, 63072000 seconds = 730 days
HSTS-Preload-Status: Rejected. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.Domain was added and removed without being preloaded.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):2 complete Content-Type - header (8 urls)
http://thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 5.161.72.160


Url with incomplete Content-Type - header - missing charset
http://thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2a01:4ff:f0:86ce::1


Url with incomplete Content-Type - header - missing charset
http://www.thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 5.161.72.160


Url with incomplete Content-Type - header - missing charset
http://www.thenewleafjournal.com/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de 2a01:4ff:f0:86ce::1


Url with incomplete Content-Type - header - missing charset
https://5.161.72.160/ 5.161.72.160


Url with incomplete Content-Type - header - missing charset
https://[2a01:04ff:00f0:86ce:0000:0000:0000:0001]/ 2a01:4ff:f0:86ce::1


Url with incomplete Content-Type - header - missing charset
Ahttp://thenewleafjournal.com/ 5.161.72.160
301
https://thenewleafjournal.com/
Correct redirect http - https with the same domain name
Ahttp://thenewleafjournal.com/ 2a01:4ff:f0:86ce::1
301
https://thenewleafjournal.com/
Correct redirect http - https with the same domain name
Ehttp://www.thenewleafjournal.com/ 5.161.72.160
301
https://thenewleafjournal.com/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Ehttp://www.thenewleafjournal.com/ 2a01:4ff:f0:86ce::1
301
https://thenewleafjournal.com/
Wrong redirect one domain http to other domain https. First redirect to https without new dns query, so the server can send the HSTS header. That's fundamental using HSTS (Http Strict Transport Security). First step: Add correct redirects http ⇒ https. Perhaps in your port 80 vHost something like "RewriteEngine on" + "RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,QSA,R=permanent]" (two rows, without the "). Don't add this in your port 443 vHost, that would create a loop. Then recheck your domain, should be Grade C. There is the rule to select one https version as preferred version.
Nhttps://5.161.72.160/ 5.161.72.160
200

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
Nhttps://[2a01:04ff:00f0:86ce:0000:0000:0000:0001]/ 2a01:4ff:f0:86ce::1
200

Error - Certificate isn't trusted, RemoteCertificateNameMismatch, RemoteCertificateChainErrors
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain thenewleafjournal.com, 2 ip addresses.
AGood: More then one ip address per domain name found, checking all ip addresses the same http status and the same certificate found: Domain www.thenewleafjournal.com, 2 ip addresses.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain thenewleafjournal.com, 2 ip addresses.
Info: Checking all ip addresses of that domain without sending the hostname only one certificate found. Checking all ip addresses and sending the hostname only one certificate found. Both certificates are different. So that domain requires Server Name Indication (SNI), so the server is able to select the correct certificate.: Domain www.thenewleafjournal.com, 2 ip addresses.
BNo _mta-sts TXT record found (mta-sts: Mail Transfer Agent Strict Transport Security - see RFC 8461). Read the result of server-daten.de (Url-Checks, Comments, Connections and DomainServiceRecords) to see a complete definition. Domainname: _mta-sts.thenewleafjournal.com

2. Header-Checks

Athenewleafjournal.com 5.161.72.160
Content-Security-Policy
Ok: Header without syntax errors found: font-src https: data:; img-src https: data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self';
F

Bad: Missing default-src directive. A default-src directive is used if one of the specialized fetch directives (child-src, connect-src, font-src, frame-src, img-src, manifest-src, media-src, object-src, prefetch-src, script-src, style-src, worker-src) isn't defined. Missing default-src, all sources are allowed, that's bad. A default-src with 'none' or 'self' blocks that.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
E

Bad: No frame-ancestors directive found. Use one to limit the pages allowed to use this page in frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
A

Good: base-uri directive found. That limits the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
A

Good: object-src only with 'none' or 'self' found, no scheme, no other urls. That blocks object / embed / applet - elements.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
Permissions-Policy
Ok: Header without syntax errors found: geolocation=(self)
A
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
X-Xss-Protection
Ok: Header without syntax errors found: 1; mode=block
B

Info: Header is deprecated. May not longer work in modern browsers. 1; mode=block
Athenewleafjournal.com 2a01:4ff:f0:86ce::1
Content-Security-Policy
Ok: Header without syntax errors found: font-src https: data:; img-src https: data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self';
F

Bad: Missing default-src directive. A default-src directive is used if one of the specialized fetch directives (child-src, connect-src, font-src, frame-src, img-src, manifest-src, media-src, object-src, prefetch-src, script-src, style-src, worker-src) isn't defined. Missing default-src, all sources are allowed, that's bad. A default-src with 'none' or 'self' blocks that.
E

Bad: No form-action directive found. Use one to limit the form - action - destinations. form-action is a navigation-directive, so default-src isn't used.
E

Bad: No frame-ancestors directive found. Use one to limit the pages allowed to use this page in frame / iframe / object / embed / applet. frame-ancestors is a navigation-directive, so default-src isn't used.
A

Good: base-uri directive found. That limits the URLs which can be used in a document's <base> element. Because it's a document directive, default-src isn't used, so an own directive is required.
A

Good: object-src only with 'none' or 'self' found, no scheme, no other urls. That blocks object / embed / applet - elements.
F

Critical: script-src with 'unsafe-inline' or 'unsafe-eval' and without a nonce found. That's dangerous, don't use it. If you really need one of these unsafe directives, add a nonce.
A

Good: script-src without * and a scheme found.
A

Good: script-src without data: schema found. Why is this important? The data: schema allows hidden code injection. Insert <script src='data:application/javascript;base64,YWxlcnQoJ1hTUycpOw=='></script> in your page and see what happens.
A
X-Content-Type-Options
Ok: Header without syntax errors found: nosniff
A
Referrer-Policy
Ok: Header without syntax errors found: same-origin
A
Permissions-Policy
Ok: Header without syntax errors found: geolocation=(self)
A
X-Frame-Options
Ok: Header without syntax errors found: SAMEORIGIN
B

Info: Header is deprecated. May not longer work in modern browsers. SAMEORIGIN. Better solution: Use a Content-Security-Policy Header with a frame-ancestors directive. DENY - use 'none', SAMEORIGIN - use 'self'. If you want to allow some domains to frame your page, add these urls.
A
X-Xss-Protection
Ok: Header without syntax errors found: 1; mode=block
B

Info: Header is deprecated. May not longer work in modern browsers. 1; mode=block
Bthenewleafjournal.com 5.161.72.160
Cross-Origin-Embedder-Policy
Info: Missing Header
Bthenewleafjournal.com 5.161.72.160
Cross-Origin-Opener-Policy
Info: Missing Header
Bthenewleafjournal.com 5.161.72.160
Cross-Origin-Resource-Policy
Info: Missing Header
Bthenewleafjournal.com 2a01:4ff:f0:86ce::1
Cross-Origin-Embedder-Policy
Info: Missing Header
Bthenewleafjournal.com 2a01:4ff:f0:86ce::1
Cross-Origin-Opener-Policy
Info: Missing Header
Bthenewleafjournal.com 2a01:4ff:f0:86ce::1
Cross-Origin-Resource-Policy
Info: Missing Header

3. DNS- and NameServer - Checks

AInfo:: 25 Root-climbing DNS Queries required to find all IPv4- and IPv6-Addresses of 0 Name Servers.
AInfo:: 25 Queries complete, 25 with IPv6, 0 with IPv4.
AGood: All DNS Queries done via IPv6.
AInfo:: 4 different Name Servers found: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com, 4 Name Servers included in Delegation: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com, 4 Name Servers included in 1 Zone definitions: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com, 1 Name Servers listed in SOA.Primary: curitiba.ns.porkbun.com.
AGood: Only one SOA.Primary Name Server found.: curitiba.ns.porkbun.com.
AGood: SOA.Primary Name Server included in the delegation set.: curitiba.ns.porkbun.com.
AGood: Consistency between delegation and zone. The set of NS records served by the authoritative name servers must match those proposed for the delegation in the parent zone. Ordered list of name servers: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com
AGood: All Name Server Domain Names have a Public Suffix.
AGood: All Name Server Domain Names ending with a Public Suffix have minimal one IPv4- or IPv6 address.
AGood: All Name Server ip addresses are public.
AGood: Minimal 2 different name servers (public suffix and public ip address) found: 4 different Name Servers found
AGood: All name servers have ipv4- and ipv6-addresses.: 4 different Name Servers found
Warning: All Name Servers have the same Top Level Domain / Public Suffix. If there is a problem with that Top Level Domain, your domain may be affected. Better: Use Name Servers with different top level domains.: 4 Name Servers, 1 Top Level Domain: com
Warning: All Name Servers have the same domain name. If there is a problem with that domain name (or with the name servers of that domain name), your domain may be affected. Better: Use Name Servers with different domain names / different top level domains.: Only one domain name used: porkbun.com
AGood: Name servers with different Country locations found: 4 Name Servers, 2 Countries: CA, US
AInfo: Ipv4-Subnet-list: 4 Name Servers, 2 different subnets (first Byte): 162., 173., 2 different subnets (first two Bytes): 162.159., 173.245., 4 different subnets (first three Bytes): 162.159.10., 162.159.11., 162.159.8., 173.245.58.
AGood: Name Server IPv4-addresses from different subnet found:
AInfo: IPv6-Subnet-list: 4 Name Servers with IPv6, 1 different subnets (first block): 2400:, 1 different subnets (first two blocks): 2400:cb00:, 1 different subnets (first three blocks): 2400:cb00:2049:, 1 different subnets (first four blocks): 2400:cb00:2049:0001:
Fatal: All Name Server IPv6 addresses from the same subnet.
AGood: Nameserver supports TCP connections: 8 good Nameserver
AGood: Nameserver supports Echo Capitalization: 8 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 8 good Nameserver
AGood: All SOA have the same Serial Number
Warning: No CAA entry with issue/issuewild found, every CAA can create a certificate. Read https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization to learn some basics about the idea of CAA. Your name server must support such an entry. Not all dns providers support CAA entries.

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Every https result with status 200 and greater 1024 Bytes is compressed (gzip, deflate, br checked).
https://thenewleafjournal.com/ 5.161.72.160
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://thenewleafjournal.com/ 2a01:4ff:f0:86ce::1
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://5.161.72.160/ 5.161.72.160
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
https://[2a01:04ff:00f0:86ce:0000:0000:0000:0001]/ 2a01:4ff:f0:86ce::1
200

Warning: Https result with status 200 found, Html-Content is too big. Should be max. 110 %. May contain inline CSS / JavaScript, too much comments or white space. Re-used ressources - create files with a long Cache-Control max-age header. Remove comments and white space.
AGood: Every https connection via port 443 supports the http/2 protocol via ALPN.
AInfo: No img element found, no alt attribute checked
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
ADuration: 444187 milliseconds, 444.187 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
thenewleafjournal.com
5.161.72.160
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
thenewleafjournal.com
5.161.72.160
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=thenewleafjournal.com


2CN=E6, O=Let's Encrypt, C=US


thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=thenewleafjournal.com


2CN=E6, O=Let's Encrypt, C=US


www.thenewleafjournal.com
5.161.72.160
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

www.thenewleafjournal.com
5.161.72.160
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.thenewleafjournal.com


2CN=E6, O=Let's Encrypt, C=US


www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
ok
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
ok
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
SNI required
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Chain (complete)

1CN=*.thenewleafjournal.com


2CN=E6, O=Let's Encrypt, C=US


5.161.72.160
5.161.72.160
443
Certificate/chain invalid and wrong name
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

5.161.72.160
5.161.72.160
443
Certificate/chain invalid and wrong name
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Self signed certificate

1CN=cloudron-2024-05-20T02:29:18.818Z


[2a01:04ff:00f0:86ce:0000:0000:0000:0001]
2a01:4ff:f0:86ce::1
443
Certificate/chain invalid and wrong name
Tls12
ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok

[2a01:04ff:00f0:86ce:0000:0000:0000:0001]
2a01:4ff:f0:86ce::1
443
Certificate/chain invalid and wrong name
Tls12

ECDH Ephermal
255
Aes256
256
Sha384
not supported
ok
http/2 via ALPN supported 
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
http/2 via ALPN supported
Cert sent without SNI
Tls.1.2
no Tls.1.1
no Tls.1.0
no Ssl3
no Ssl2
Self signed certificate

1CN=cloudron-2024-05-20T02:29:18.818Z

 

9. Certificates

1.
1.
CN=thenewleafjournal.com
14.07.2025
12.10.2025
331 days expired
thenewleafjournal.com - 1 entry
1.
1.
CN=thenewleafjournal.com
14.07.2025

12.10.2025
331 days expired


thenewleafjournal.com - 1 entry

KeyalgorithmEC Public Key (256 bit, prime256v1)
Signatur:ECDSA SHA384
Serial Number:06F3EACCC461369E84A712988509DF4EBB07
Thumbprint:A54F3226F1D928CC207C07985FB6018C449A2F7F
SHA256 / Certificate:Rj6z5tJlZ5nPpi26czCSh3Fly3AF1i2i+kaz4sNntTs=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):75201357d354dd9d3bdc5877999671141b909a86b9fc01323975c770989bd299
SHA256 hex / Subject Public Key Information (SPKI):75201357d354dd9d3bdc5877999671141b909a86b9fc01323975c770989bd299 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=E6, O=Let's Encrypt, C=US
13.03.2024
13.03.2027
expires in 186 days


2.
CN=E6, O=Let's Encrypt, C=US
13.03.2024

13.03.2027
expires in 186 days




KeyalgorithmEC Public Key (384 bit, secp384r1)
Signatur:SHA256 With RSA-Encryption
Serial Number:00B0573E9173972770DBB487CB3A452B38
Thumbprint:C94DC4831A901A9FEC0FB49B71BD49B5AAD4FAD0
SHA256 / Certificate:duniiKr8Djf0OQy/lGqtmX1cHJAbPOUT09j626viq4U=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):d016e1fe311948aca64f2de44ce86c9a51ca041df6103bb52a88eb3f761f57d7
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015
04.06.2035
expires in 3191 days


3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015

04.06.2035
expires in 3191 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:008210CFB0D240E3594463E0BB63828B00
Thumbprint:CABD2A79A1076A31F21D253635CB039D4329A5E8
SHA256 / Certificate:lrzsBiZJdvN0YHeazyjFp8/oo8Cq4RqP/O4FwL3fCMY=
SHA256 hex / Cert (DANE * 0 1):96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
SHA256 hex / PublicKey (DANE * 1 1):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SHA256 hex / Subject Public Key Information (SPKI):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




2.
1.
CN=*.thenewleafjournal.com
14.07.2025
12.10.2025
331 days expired
*.thenewleafjournal.com - 1 entry
2.
1.
CN=*.thenewleafjournal.com
14.07.2025

12.10.2025
331 days expired


*.thenewleafjournal.com - 1 entry

KeyalgorithmEC Public Key (256 bit, prime256v1)
Signatur:ECDSA SHA384
Serial Number:052931CD689E7A2E35B292DDAA6BB14470F6
Thumbprint:7385476C139EE3B5A3554D5DCEDDDE310C6A72CA
SHA256 / Certificate:/4t2TAzmEJ0YSYFVt6qhUWrZ8TErPCZFfmHZkrvpOXc=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):c9afa895b731fc3f7a000c4e43331047dfa294fc7b5b553855ba43533a84a9ce
SHA256 hex / Subject Public Key Information (SPKI):c9afa895b731fc3f7a000c4e43331047dfa294fc7b5b553855ba43533a84a9ce (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Serverauthentifizierung (1.3.6.1.5.5.7.3.1), Clientauthentifizierung (1.3.6.1.5.5.7.3.2)




2.
CN=E6, O=Let's Encrypt, C=US
13.03.2024
13.03.2027
expires in 186 days


2.
CN=E6, O=Let's Encrypt, C=US
13.03.2024

13.03.2027
expires in 186 days




KeyalgorithmEC Public Key (384 bit, secp384r1)
Signatur:SHA256 With RSA-Encryption
Serial Number:00B0573E9173972770DBB487CB3A452B38
Thumbprint:C94DC4831A901A9FEC0FB49B71BD49B5AAD4FAD0
SHA256 / Certificate:duniiKr8Djf0OQy/lGqtmX1cHJAbPOUT09j626viq4U=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):d016e1fe311948aca64f2de44ce86c9a51ca041df6103bb52a88eb3f761f57d7
SHA256 hex / Subject Public Key Information (SPKI):
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Check unknown. No result 404 / 200
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:Clientauthentifizierung (1.3.6.1.5.5.7.3.2), Serverauthentifizierung (1.3.6.1.5.5.7.3.1)




3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015
04.06.2035
expires in 3191 days


3.
CN=ISRG Root X1, O=Internet Security Research Group, C=US
04.06.2015

04.06.2035
expires in 3191 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:008210CFB0D240E3594463E0BB63828B00
Thumbprint:CABD2A79A1076A31F21D253635CB039D4329A5E8
SHA256 / Certificate:lrzsBiZJdvN0YHeazyjFp8/oo8Cq4RqP/O4FwL3fCMY=
SHA256 hex / Cert (DANE * 0 1):96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
SHA256 hex / PublicKey (DANE * 1 1):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SHA256 hex / Subject Public Key Information (SPKI):0b9fa5a59eed715c26c1020c711b4f6ec42d58b0015e14337a39dad301c5afc3
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




3.
1.
CN=cloudron-2024-05-20T02:29:18.818Z
20.05.2024
29.07.2026
41 days expired

3.
1.
CN=cloudron-2024-05-20T02:29:18.818Z
20.05.2024

29.07.2026
41 days expired




KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:5321DE3CEA721BFFF236B419E0D51AAAA5343004
Thumbprint:C7584B555F9E51219E3898283AA2E09E858846DB
SHA256 / Certificate:yn8WJ0Sh05rMcxkH9WVyLEX9TbHkX3sFDtOkjxw7YjI=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):fe1bda26b9e369ea4ead540cfdf214caff946282c5336a7fc02dba7eb05500e5
SHA256 hex / Subject Public Key Information (SPKI):fe1bda26b9e369ea4ead540cfdf214caff946282c5336a7fc02dba7eb05500e5 (is buggy, ignore the result)
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:


UntrustedRoot: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.


 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Issuerlast 7 daysactivenum Certs
CN=E6, O=Let's Encrypt, C=US
0
0
1
CN=R10, O=Let's Encrypt, C=US
0
0
1

CertSpotter-IdIssuernot beforenot afterDomain namesLE-Duplicatenext LE
11331411193
leaf cert
CN=R10, O=Let's Encrypt, C=US
2025-08-01 00:46:01
2025-10-30 00:46:00
*.thenewleafjournal.com, thenewleafjournal.com - 2 entries


11116297788
leaf cert
CN=E6, O=Let's Encrypt, C=US
2025-07-14 16:13:26
2025-10-12 16:13:25
thenewleafjournal.com - 1 entries


 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

No CRT - CT-Log entries found

 

11. Html-Content - Entries

No Html-Content entries found. Only checked if https + status 200/401/403/404

 

12. Html-Parsing via https://validator.w3.org/nu/

Url used (first standard-https-result with http status 200): https://thenewleafjournal.com/

Summary

Good: No non-document-errors
2 errors
3 warnings

TypeMessagenum found
1.errorCSS: contain-intrinsic-size: Property contain-intrinsic-size doesn't exist.1
2.errorElement style not allowed as child of element body in this context. (Suppressing further errors from this subtree.)1
3.warningThe type attribute for the style element is not needed and should be omitted.3

Details


TypeMessage + Sample
1errorCSS: contain-intrinsic-size: Property contain-intrinsic-size doesn't exist.

From line 7, column 93 to line 7, column 93

: 3000px 1500px}</style> <sc
2errorElement style not allowed as child of element body in this context. (Suppressing further errors from this subtree.)

From line 612, column 1 to line 612, column 53

v> </div> <style id='global-styles-inline-css' type='text/css'> :root
3warningThe type attribute for the style element is not needed and should be omitted.

From line 58, column 4 to line 58, column 63

2/" /> <style id='classic-theme-styles-inline-css' type='text/css'> /*! T
4warningThe type attribute for the style element is not needed and should be omitted.

From line 79, column 3 to line 79, column 44

int" /> <style type="text/css" id="wp-custom-css"> bo
5warningThe type attribute for the style element is not needed and should be omitted.

From line 612, column 1 to line 612, column 53

v> </div> <style id='global-styles-inline-css' type='text/css'> :root

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers: curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com

 

QNr.DomainTypeNS used
1
com
NS
f.root-servers.net (2001:500:2f::f)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
2
curitiba.ns.porkbun.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-1328.awsdns-38.org, ns-1982.awsdns-55.co.uk, ns-199.awsdns-24.com, ns-586.awsdns-09.net

Answer: ns-199.awsdns-24.com
205.251.192.199
3
fortaleza.ns.porkbun.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-1328.awsdns-38.org, ns-1982.awsdns-55.co.uk, ns-199.awsdns-24.com, ns-586.awsdns-09.net

Answer: ns-199.awsdns-24.com
205.251.192.199
4
maceio.ns.porkbun.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-1328.awsdns-38.org, ns-1982.awsdns-55.co.uk, ns-199.awsdns-24.com, ns-586.awsdns-09.net

Answer: ns-199.awsdns-24.com
205.251.192.199
5
salvador.ns.porkbun.com
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: ns-1328.awsdns-38.org, ns-1982.awsdns-55.co.uk, ns-199.awsdns-24.com, ns-586.awsdns-09.net

Answer: ns-199.awsdns-24.com
205.251.192.199
6
org
NS
b.root-servers.net (2001:500:200::b)

Answer: a0.org.afilias-nst.info, a2.org.afilias-nst.info, b0.org.afilias-nst.org, b2.org.afilias-nst.org, c0.org.afilias-nst.info, d0.org.afilias-nst.org
7
ns-1328.awsdns-38.org
NS
a0.org.afilias-nst.info (2001:500:e::1)

Answer: g-ns-1065.awsdns-38.org, g-ns-1638.awsdns-38.org, g-ns-166.awsdns-38.org, g-ns-744.awsdns-38.org

Answer: g-ns-1065.awsdns-38.org
205.251.196.41, 2600:9000:5304:2900::1

Answer: g-ns-1638.awsdns-38.org
205.251.198.102, 2600:9000:5306:6600::1

Answer: g-ns-166.awsdns-38.org
205.251.192.166, 2600:9000:5300:a600::1

Answer: g-ns-744.awsdns-38.org
205.251.194.232, 2600:9000:5302:e800::1
8
uk
NS
a.root-servers.net (2001:503:ba3e::2:30)

Answer: dns1.nic.uk, dns2.nic.uk, dns3.nic.uk, dns4.nic.uk, nsa.nic.uk, nsb.nic.uk, nsc.nic.uk, nsd.nic.uk
9
ns-1982.awsdns-55.co.uk
NS
dns1.nic.uk (2a01:618:400::1)

Answer: g-ns-1530.awsdns-55.co.uk, g-ns-1851.awsdns-55.co.uk, g-ns-375.awsdns-55.co.uk, g-ns-951.awsdns-55.co.uk

Answer: g-ns-1530.awsdns-55.co.uk
205.251.197.250, 2600:9000:5305:fa00::1

Answer: g-ns-1851.awsdns-55.co.uk
205.251.199.59, 2600:9000:5307:3b00::1

Answer: g-ns-375.awsdns-55.co.uk
205.251.193.119, 2600:9000:5301:7700::1

Answer: g-ns-951.awsdns-55.co.uk
205.251.195.183, 2600:9000:5303:b700::1
10
net
NS
d.root-servers.net (2001:500:2d::d)

Answer: a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net, e.gtld-servers.net, f.gtld-servers.net, g.gtld-servers.net, h.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, k.gtld-servers.net, l.gtld-servers.net, m.gtld-servers.net
11
ns-586.awsdns-09.net
NS
a.gtld-servers.net (2001:503:a83e::2:30)

Answer: g-ns-1353.awsdns-09.net, g-ns-1929.awsdns-09.net, g-ns-458.awsdns-09.net, g-ns-779.awsdns-09.net

Answer: g-ns-1353.awsdns-09.net
205.251.197.73, 2600:9000:5305:4900::1

Answer: g-ns-1929.awsdns-09.net
205.251.199.137, 2600:9000:5307:8900::1

Answer: g-ns-458.awsdns-09.net
205.251.193.202, 2600:9000:5301:ca00::1

Answer: g-ns-779.awsdns-09.net
205.251.195.11, 2600:9000:5303:b00::1
12
ns-1328.awsdns-38.org: 205.251.197.48
A
g-ns-1065.awsdns-38.org (2600:9000:5304:2900::1)
13
ns-1328.awsdns-38.org: 2600:9000:5305:3000::1
AAAA
g-ns-1065.awsdns-38.org (2600:9000:5304:2900::1)
14
ns-1982.awsdns-55.co.uk: 205.251.199.190
A
g-ns-1530.awsdns-55.co.uk (2600:9000:5305:fa00::1)
15
ns-1982.awsdns-55.co.uk: 2600:9000:5307:be00::1
AAAA
g-ns-1530.awsdns-55.co.uk (2600:9000:5305:fa00::1)
16
ns-586.awsdns-09.net: 205.251.194.74
A
g-ns-1353.awsdns-09.net (2600:9000:5305:4900::1)
17
ns-586.awsdns-09.net: 2600:9000:5302:4a00::1
AAAA
g-ns-1353.awsdns-09.net (2600:9000:5305:4900::1)
18
curitiba.ns.porkbun.com: No A record found
A
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
19
curitiba.ns.porkbun.com: No AAAA record found
AAAA
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
20
fortaleza.ns.porkbun.com: No A record found
A
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
21
fortaleza.ns.porkbun.com: No AAAA record found
AAAA
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
22
maceio.ns.porkbun.com: No A record found
A
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
23
maceio.ns.porkbun.com: No AAAA record found
AAAA
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
24
salvador.ns.porkbun.com: No A record found
A
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)
25
salvador.ns.porkbun.com: No AAAA record found
AAAA
ns-1328.awsdns-38.org (2600:9000:5305:3000::1)

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
www.thenewleafjournal.com
0

no CAA entry found
1
0
thenewleafjournal.com
0

no CAA entry found
1
0
com
0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
thenewleafjournal.com
google-site-verification=vKnOpTY3T_6RvALJIakT79ipT2GEd7TrNfRMTyMdf6k
ok
1
0
thenewleafjournal.com
sl-verification=zezdizteormjhvbnrkpefiyzblvcja
ok
1
0
thenewleafjournal.com
v=spf1 a:my.emucafe.org ~all
ok
1
0
thenewleafjournal.com
v=spf1 include:simplelogin.co ~all
ok
1
0
www.thenewleafjournal.com

ok
1
0
_acme-challenge.thenewleafjournal.com
SvyBO88lCBWuL6Y39hK4TDcMystsUbjjyWsvoY2IN6s
looks good, correct length, correct characters
1
0
_acme-challenge.thenewleafjournal.com
tGVzm-z0a_VTcgIEIzM_pY2KudVtC2ItTSyxwcS2C0c
looks good, correct length, correct characters
1
0
_acme-challenge.www.thenewleafjournal.com

Name Error - The domain name does not exist
1
0
_acme-challenge.thenewleafjournal.com.thenewleafjournal.com

Name Error - The domain name does not exist
1
0
_acme-challenge.www.thenewleafjournal.com.thenewleafjournal.com

Name Error - The domain name does not exist
1
0
_acme-challenge.www.thenewleafjournal.com.www.thenewleafjournal.com

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

TypeDomainPrefValueDNS-errornum AnswersStatusDescription
MX

thenewleafjournal.com
10
mx1.simplelogin.co
02ok

A


176.119.200.136
02ok

A


185.205.70.136
02ok

CNAME


00ok
MX

thenewleafjournal.com
20
mx2.simplelogin.co
02ok

A


185.205.70.136
02ok

A


176.119.200.136
02ok

CNAME


00ok
SPF
TXT
thenewleafjournal.com

v=spf1 a:my.emucafe.org ~all
1PermError: More than one TXT record found. Merge your entries in one.
SPF
TXT
thenewleafjournal.com

v=spf1 include:simplelogin.co ~all
1PermError: More than one TXT record found. Merge your entries in one.
_dmarc
TXT
_dmarc.thenewleafjournal.com

v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s
1PermError: More than one _dmarc-TXT record found. DMARC-definition ignored.
_dmarc
TXT
_dmarc.thenewleafjournal.com

v=DMARC1; p=reject; pct=100
1PermError: More than one _dmarc-TXT record found. DMARC-definition ignored.

 

 

17. Cipher Suites

Summary
DomainIPPortnum CipherstimeStd.ProtocolForward Secrecy
thenewleafjournal.com
5.161.72.160
443
3 Ciphers70.86 sec
0 without, 3 FS
100.00 %
thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
3 Ciphers58.97 sec
0 without, 3 FS
100.00 %
www.thenewleafjournal.com
5.161.72.160
443
3 Ciphers70.30 sec
0 without, 3 FS
100.00 %
www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
443
3 Ciphers58.66 sec
0 without, 3 FS
100.00 %
Complete

4
12 Ciphers
3.00 Ciphers/Check
258.79 sec64.70 sec/Check
0 without, 12 FS
100.00 %

Details
DomainIPPortCipher (OpenSsl / IANA)
thenewleafjournal.com
5.161.72.160
443
ECDHE-ECDSA-CHACHA20-POLY1305
(Recommended)
TLSv1.2
0xCC,0xA9
FS
3 Ciphers, 70.86 sec
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
ECDSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-ECDSA-AES256-GCM-SHA384
(Recommended)
TLSv1.2
0xC0,0x2C
FS

TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

ECDH
ECDSA
AESGCM(256)
AEAD




ECDHE-ECDSA-AES128-GCM-SHA256
(Recommended)
TLSv1.2
0xC0,0x2B
FS

TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

ECDH
ECDSA
AESGCM(128)
AEAD


2a01:4ff:f0:86ce::1
443
ECDHE-ECDSA-CHACHA20-POLY1305
(Recommended)
TLSv1.2
0xCC,0xA9
FS
3 Ciphers, 58.97 sec
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
ECDSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-ECDSA-AES256-GCM-SHA384
(Recommended)
TLSv1.2
0xC0,0x2C
FS

TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

ECDH
ECDSA
AESGCM(256)
AEAD




ECDHE-ECDSA-AES128-GCM-SHA256
(Recommended)
TLSv1.2
0xC0,0x2B
FS

TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

ECDH
ECDSA
AESGCM(128)
AEAD

www.thenewleafjournal.com
5.161.72.160
443
ECDHE-ECDSA-CHACHA20-POLY1305
(Recommended)
TLSv1.2
0xCC,0xA9
FS
3 Ciphers, 70.30 sec
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
ECDSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-ECDSA-AES256-GCM-SHA384
(Recommended)
TLSv1.2
0xC0,0x2C
FS

TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

ECDH
ECDSA
AESGCM(256)
AEAD




ECDHE-ECDSA-AES128-GCM-SHA256
(Recommended)
TLSv1.2
0xC0,0x2B
FS

TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

ECDH
ECDSA
AESGCM(128)
AEAD


2a01:4ff:f0:86ce::1
443
ECDHE-ECDSA-CHACHA20-POLY1305
(Recommended)
TLSv1.2
0xCC,0xA9
FS
3 Ciphers, 58.66 sec
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

ECDH
ECDSA
CHACHA20/POLY1305(256)
AEAD




ECDHE-ECDSA-AES256-GCM-SHA384
(Recommended)
TLSv1.2
0xC0,0x2C
FS

TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

ECDH
ECDSA
AESGCM(256)
AEAD




ECDHE-ECDSA-AES128-GCM-SHA256
(Recommended)
TLSv1.2
0xC0,0x2B
FS

TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

ECDH
ECDSA
AESGCM(128)
AEAD

 

18. Portchecks

DomainIPPortDescriptionResultAnswer
thenewleafjournal.com
5.161.72.160
21
FTP



thenewleafjournal.com
5.161.72.160
21
FTP



thenewleafjournal.com
5.161.72.160
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13

thenewleafjournal.com
5.161.72.160
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13
Bad: SSH without DNS SSHFP Record found
thenewleafjournal.com
5.161.72.160
25
SMTP



thenewleafjournal.com
5.161.72.160
25
SMTP



thenewleafjournal.com
5.161.72.160
53
DNS



thenewleafjournal.com
5.161.72.160
53
DNS



thenewleafjournal.com
5.161.72.160
110
POP3



thenewleafjournal.com
5.161.72.160
110
POP3



thenewleafjournal.com
5.161.72.160
143
IMAP



thenewleafjournal.com
5.161.72.160
143
IMAP



thenewleafjournal.com
5.161.72.160
465
SMTP (encrypted)



thenewleafjournal.com
5.161.72.160
465
SMTP (encrypted)



thenewleafjournal.com
5.161.72.160
587
SMTP (encrypted, submission)



thenewleafjournal.com
5.161.72.160
587
SMTP (encrypted, submission)



thenewleafjournal.com
5.161.72.160
993
IMAP (encrypted)



thenewleafjournal.com
5.161.72.160
993
IMAP (encrypted)



thenewleafjournal.com
5.161.72.160
995
POP3 (encrypted)



thenewleafjournal.com
5.161.72.160
995
POP3 (encrypted)



thenewleafjournal.com
5.161.72.160
1433
MS SQL



thenewleafjournal.com
5.161.72.160
1433
MS SQL



thenewleafjournal.com
5.161.72.160
2082
cPanel (http)



thenewleafjournal.com
5.161.72.160
2082
cPanel (http)



thenewleafjournal.com
5.161.72.160
2083
cPanel (https)



thenewleafjournal.com
5.161.72.160
2083
cPanel (https)



thenewleafjournal.com
5.161.72.160
2086
WHM (http)



thenewleafjournal.com
5.161.72.160
2086
WHM (http)



thenewleafjournal.com
5.161.72.160
2087
WHM (https)



thenewleafjournal.com
5.161.72.160
2087
WHM (https)



thenewleafjournal.com
5.161.72.160
2089
cPanel Licensing



thenewleafjournal.com
5.161.72.160
2089
cPanel Licensing



thenewleafjournal.com
5.161.72.160
2095
cPanel Webmail (http)



thenewleafjournal.com
5.161.72.160
2095
cPanel Webmail (http)



thenewleafjournal.com
5.161.72.160
2096
cPanel Webmail (https)



thenewleafjournal.com
5.161.72.160
2096
cPanel Webmail (https)



thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (http)



thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (http)



thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (https)



thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (https)



thenewleafjournal.com
5.161.72.160
3306
mySql



thenewleafjournal.com
5.161.72.160
3306
mySql



thenewleafjournal.com
5.161.72.160
5224
Plesk Licensing



thenewleafjournal.com
5.161.72.160
5224
Plesk Licensing



thenewleafjournal.com
5.161.72.160
5432
PostgreSQL



thenewleafjournal.com
5.161.72.160
5432
PostgreSQL



thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (http)



thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (http)



thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (https)



thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (https)



thenewleafjournal.com
5.161.72.160
8083
VestaCP http



thenewleafjournal.com
5.161.72.160
8083
VestaCP http



thenewleafjournal.com
5.161.72.160
8083
VestaCP https



thenewleafjournal.com
5.161.72.160
8083
VestaCP https



thenewleafjournal.com
5.161.72.160
8443
Plesk Administration (https)



thenewleafjournal.com
5.161.72.160
8443
Plesk Administration (https)



thenewleafjournal.com
5.161.72.160
8447
Plesk Installer + Updates



thenewleafjournal.com
5.161.72.160
8447
Plesk Installer + Updates



thenewleafjournal.com
5.161.72.160
8880
Plesk Administration (http)



thenewleafjournal.com
5.161.72.160
8880
Plesk Administration (http)



thenewleafjournal.com
5.161.72.160
10000
Webmin (http)



thenewleafjournal.com
5.161.72.160
10000
Webmin (http)



thenewleafjournal.com
5.161.72.160
10000
Webmin (https)



thenewleafjournal.com
5.161.72.160
10000
Webmin (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
21
FTP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
21
FTP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13

thenewleafjournal.com
2a01:4ff:f0:86ce::1
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13
Bad: SSH without DNS SSHFP Record found
thenewleafjournal.com
2a01:4ff:f0:86ce::1
25
SMTP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
25
SMTP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
53
DNS



thenewleafjournal.com
2a01:4ff:f0:86ce::1
53
DNS



thenewleafjournal.com
2a01:4ff:f0:86ce::1
110
POP3



thenewleafjournal.com
2a01:4ff:f0:86ce::1
110
POP3



thenewleafjournal.com
2a01:4ff:f0:86ce::1
143
IMAP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
143
IMAP



thenewleafjournal.com
2a01:4ff:f0:86ce::1
465
SMTP (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
465
SMTP (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
587
SMTP (encrypted, submission)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
587
SMTP (encrypted, submission)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
993
IMAP (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
993
IMAP (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
995
POP3 (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
995
POP3 (encrypted)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
1433
MS SQL



thenewleafjournal.com
2a01:4ff:f0:86ce::1
1433
MS SQL



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2082
cPanel (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2082
cPanel (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2083
cPanel (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2083
cPanel (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2086
WHM (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2086
WHM (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2087
WHM (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2087
WHM (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2089
cPanel Licensing



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2089
cPanel Licensing



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2095
cPanel Webmail (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2095
cPanel Webmail (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2096
cPanel Webmail (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2096
cPanel Webmail (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
3306
mySql



thenewleafjournal.com
2a01:4ff:f0:86ce::1
3306
mySql



thenewleafjournal.com
2a01:4ff:f0:86ce::1
5224
Plesk Licensing



thenewleafjournal.com
2a01:4ff:f0:86ce::1
5224
Plesk Licensing



thenewleafjournal.com
2a01:4ff:f0:86ce::1
5432
PostgreSQL



thenewleafjournal.com
2a01:4ff:f0:86ce::1
5432
PostgreSQL



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP http



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP http



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP https



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP https



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8443
Plesk Administration (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8443
Plesk Administration (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8447
Plesk Installer + Updates



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8447
Plesk Installer + Updates



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8880
Plesk Administration (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
8880
Plesk Administration (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (http)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (https)



thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (https)



www.thenewleafjournal.com
5.161.72.160
21
FTP



www.thenewleafjournal.com
5.161.72.160
21
FTP



www.thenewleafjournal.com
5.161.72.160
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13

www.thenewleafjournal.com
5.161.72.160
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13
Bad: SSH without DNS SSHFP Record found
www.thenewleafjournal.com
5.161.72.160
25
SMTP



www.thenewleafjournal.com
5.161.72.160
25
SMTP



www.thenewleafjournal.com
5.161.72.160
53
DNS



www.thenewleafjournal.com
5.161.72.160
53
DNS



www.thenewleafjournal.com
5.161.72.160
110
POP3



www.thenewleafjournal.com
5.161.72.160
110
POP3



www.thenewleafjournal.com
5.161.72.160
143
IMAP



www.thenewleafjournal.com
5.161.72.160
143
IMAP



www.thenewleafjournal.com
5.161.72.160
465
SMTP (encrypted)



www.thenewleafjournal.com
5.161.72.160
465
SMTP (encrypted)



www.thenewleafjournal.com
5.161.72.160
587
SMTP (encrypted, submission)



www.thenewleafjournal.com
5.161.72.160
587
SMTP (encrypted, submission)



www.thenewleafjournal.com
5.161.72.160
993
IMAP (encrypted)



www.thenewleafjournal.com
5.161.72.160
993
IMAP (encrypted)



www.thenewleafjournal.com
5.161.72.160
995
POP3 (encrypted)



www.thenewleafjournal.com
5.161.72.160
995
POP3 (encrypted)



www.thenewleafjournal.com
5.161.72.160
1433
MS SQL



www.thenewleafjournal.com
5.161.72.160
1433
MS SQL



www.thenewleafjournal.com
5.161.72.160
2082
cPanel (http)



www.thenewleafjournal.com
5.161.72.160
2082
cPanel (http)



www.thenewleafjournal.com
5.161.72.160
2083
cPanel (https)



www.thenewleafjournal.com
5.161.72.160
2083
cPanel (https)



www.thenewleafjournal.com
5.161.72.160
2086
WHM (http)



www.thenewleafjournal.com
5.161.72.160
2086
WHM (http)



www.thenewleafjournal.com
5.161.72.160
2087
WHM (https)



www.thenewleafjournal.com
5.161.72.160
2087
WHM (https)



www.thenewleafjournal.com
5.161.72.160
2089
cPanel Licensing



www.thenewleafjournal.com
5.161.72.160
2089
cPanel Licensing



www.thenewleafjournal.com
5.161.72.160
2095
cPanel Webmail (http)



www.thenewleafjournal.com
5.161.72.160
2095
cPanel Webmail (http)



www.thenewleafjournal.com
5.161.72.160
2096
cPanel Webmail (https)



www.thenewleafjournal.com
5.161.72.160
2096
cPanel Webmail (https)



www.thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (http)



www.thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (http)



www.thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (https)



www.thenewleafjournal.com
5.161.72.160
2222
DirectAdmin (https)



www.thenewleafjournal.com
5.161.72.160
3306
mySql



www.thenewleafjournal.com
5.161.72.160
3306
mySql



www.thenewleafjournal.com
5.161.72.160
5224
Plesk Licensing



www.thenewleafjournal.com
5.161.72.160
5224
Plesk Licensing



www.thenewleafjournal.com
5.161.72.160
5432
PostgreSQL



www.thenewleafjournal.com
5.161.72.160
5432
PostgreSQL



www.thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (http)



www.thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (http)



www.thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (https)



www.thenewleafjournal.com
5.161.72.160
8080
Ookla Speedtest (https)



www.thenewleafjournal.com
5.161.72.160
8083
VestaCP http



www.thenewleafjournal.com
5.161.72.160
8083
VestaCP http



www.thenewleafjournal.com
5.161.72.160
8083
VestaCP https



www.thenewleafjournal.com
5.161.72.160
8083
VestaCP https



www.thenewleafjournal.com
5.161.72.160
8443
Plesk Administration (https)



www.thenewleafjournal.com
5.161.72.160
8443
Plesk Administration (https)



www.thenewleafjournal.com
5.161.72.160
8447
Plesk Installer + Updates



www.thenewleafjournal.com
5.161.72.160
8447
Plesk Installer + Updates



www.thenewleafjournal.com
5.161.72.160
8880
Plesk Administration (http)



www.thenewleafjournal.com
5.161.72.160
8880
Plesk Administration (http)



www.thenewleafjournal.com
5.161.72.160
10000
Webmin (http)



www.thenewleafjournal.com
5.161.72.160
10000
Webmin (http)



www.thenewleafjournal.com
5.161.72.160
10000
Webmin (https)



www.thenewleafjournal.com
5.161.72.160
10000
Webmin (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
21
FTP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
21
FTP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13

www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
22
SSH
open
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13
Bad: SSH without DNS SSHFP Record found
www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
25
SMTP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
25
SMTP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
53
DNS



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
53
DNS



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
110
POP3



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
110
POP3



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
143
IMAP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
143
IMAP



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
465
SMTP (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
465
SMTP (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
587
SMTP (encrypted, submission)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
587
SMTP (encrypted, submission)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
993
IMAP (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
993
IMAP (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
995
POP3 (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
995
POP3 (encrypted)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
1433
MS SQL



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
1433
MS SQL



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2082
cPanel (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2082
cPanel (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2083
cPanel (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2083
cPanel (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2086
WHM (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2086
WHM (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2087
WHM (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2087
WHM (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2089
cPanel Licensing



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2089
cPanel Licensing



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2095
cPanel Webmail (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2095
cPanel Webmail (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2096
cPanel Webmail (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2096
cPanel Webmail (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
2222
DirectAdmin (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
3306
mySql



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
3306
mySql



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
5224
Plesk Licensing



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
5224
Plesk Licensing



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
5432
PostgreSQL



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
5432
PostgreSQL



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8080
Ookla Speedtest (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP http



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP http



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP https



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8083
VestaCP https



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8443
Plesk Administration (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8443
Plesk Administration (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8447
Plesk Installer + Updates



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8447
Plesk Installer + Updates



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8880
Plesk Administration (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
8880
Plesk Administration (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (http)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (https)



www.thenewleafjournal.com
2a01:4ff:f0:86ce::1
10000
Webmin (https)



 

 

Permalink: https://check-your-website.server-daten.de/?i=2a352c24-5cac-4aab-b758-a658855fdcb0

 

Last Result: https://check-your-website.server-daten.de/?q=thenewleafjournal.com - 2025-09-03 05:52:48

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=thenewleafjournal.com" target="_blank">Check this Site: thenewleafjournal.com</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=thenewleafjournal.com