Check DNS, Urls + Redirects, Certificates and Content of your Website


 

 

A

 

Top config

 

Checked:
28.08.2019 17:28:02

 

Older results

No older results found

 

1. IP-Addresses

HostTypeIP-Addressis auth.∑ Queries∑ Timeout
vragenlijst.cbs.nl
CNAME
adc4.cbs.nl
yes
1
0

A
87.213.43.244
Utrecht/Provincie Utrecht/Netherlands (NL) - Tele 2 Nederland B.V.
No Hostname found
yes



AAAA
2001:67c:14b0:1816::244
Liten/Central Bohemia/Czechia (CZ) - Tele 2 Nederland B.V.

yes


www.vragenlijst.cbs.nl

Name Error
yes
1
0

 

2. DNSSEC

Zone (*)DNSSEC - Informations


Zone: (root)

(root)
1 DS RR published






Status: Valid because published






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 59944, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 10.09.2019, 00:00:00 +, Signature-Inception: 20.08.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: nl

nl
1 DS RR in the parent zone found






2 RRSIG RR to validate DS RR found






RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.09.2019, 05:00:00 +, Signature-Inception: 28.08.2019, 04:00:00 +, KeyTag 59944, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59944 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 17593, Flags 256






Public Key with Algorithm 8, KeyTag 34112, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 08.09.2019, 22:04:06 +, Signature-Inception: 25.08.2019, 22:07:02 +, KeyTag 34112, Signer-Name: nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 34112 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest "PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: cbs.nl

cbs.nl
1 DS RR in the parent zone found






2 RRSIG RR to validate DS RR found






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 01:28:11 +, Signature-Inception: 21.08.2019, 06:08:02 +, KeyTag 17593, Signer-Name: nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 17593 used to validate the DS RRSet in the parent zone






4 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 26180, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 30174, Flags 256






Public Key with Algorithm 8, KeyTag 51505, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 59260, Flags 256






2 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 14:40:20 +, Signature-Inception: 28.08.2019, 13:40:20 +, KeyTag 26180, Signer-Name: cbs.nl






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 14:40:20 +, Signature-Inception: 28.08.2019, 13:40:20 +, KeyTag 30174, Signer-Name: cbs.nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26180 used to validate the DNSKEY RRSet






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30174 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26180, DigestType 2 and Digest "RRbzgwj8qMJpDNjJmoAJhX55+Mw3Wx8RuGh05CMiH1I=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: vragenlijst.cbs.nl

vragenlijst.cbs.nl
0 DS RR in the parent zone found



Zone: www.vragenlijst.cbs.nl

www.vragenlijst.cbs.nl
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "nj99kknio3ci8nh0pm1i9oqiv8vp0av4" between the hashed NSEC3-owner "neochk7dssa8m0bdt1qc157r6s2vej6a" and the hashed NextOwner "nl9p81oecf2tr5dquolsb1barn0ksrgf". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner neochk7dssa8m0bdt1qc157r6s2vej6a.cbs.nl., Algorithm: 8, 3 Labels, original TTL: 7200 sec, Signature-expiration: 04.09.2019, 02:39:49 +, Signature-Inception: 25.08.2019, 01:39:49 +, KeyTag 30174, Signer-Name: cbs.nl



Zone: (root)

(root)
1 DS RR published






Status: Valid because published






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 59944, Flags 256






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 10.09.2019, 00:00:00 +, Signature-Inception: 20.08.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: nl

nl
1 DS RR in the parent zone found






2 RRSIG RR to validate DS RR found






RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.09.2019, 05:00:00 +, Signature-Inception: 28.08.2019, 04:00:00 +, KeyTag 59944, Signer-Name: (root)






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59944 used to validate the DS RRSet in the parent zone






2 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 17593, Flags 256






Public Key with Algorithm 8, KeyTag 34112, Flags 257 (SEP = Secure Entry Point)






1 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 08.09.2019, 22:04:06 +, Signature-Inception: 25.08.2019, 22:07:02 +, KeyTag 34112, Signer-Name: nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 34112 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest "PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: cbs.nl

cbs.nl
1 DS RR in the parent zone found






2 RRSIG RR to validate DS RR found






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 01:28:11 +, Signature-Inception: 21.08.2019, 06:08:02 +, KeyTag 17593, Signer-Name: nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 17593 used to validate the DS RRSet in the parent zone






4 DNSKEY RR found






Public Key with Algorithm 8, KeyTag 26180, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 30174, Flags 256






Public Key with Algorithm 8, KeyTag 51505, Flags 257 (SEP = Secure Entry Point)






Public Key with Algorithm 8, KeyTag 59260, Flags 256






2 RRSIG RR to validate DNSKEY RR found






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 14:40:20 +, Signature-Inception: 28.08.2019, 13:40:20 +, KeyTag 26180, Signer-Name: cbs.nl






RRSIG-Owner cbs.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.09.2019, 14:40:20 +, Signature-Inception: 28.08.2019, 13:40:20 +, KeyTag 30174, Signer-Name: cbs.nl






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26180 used to validate the DNSKEY RRSet






Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30174 used to validate the DNSKEY RRSet






Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26180, DigestType 2 and Digest "RRbzgwj8qMJpDNjJmoAJhX55+Mw3Wx8RuGh05CMiH1I=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone



Zone: adc4.cbs.nl

adc4.cbs.nl
0 DS RR in the parent zone found






DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "ses964oomh7qbc6kc3j3vpb6ipifa5dr" between the hashed NSEC3-owner "ses964oomh7qbc6kc3j3vpb6ipifa5dr" and the hashed NextOwner "sgc2sv0hbo4tf6o3g68a9th434u1vv32". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, TXT, AAAA, RRSIG Validated: RRSIG-Owner ses964oomh7qbc6kc3j3vpb6ipifa5dr.cbs.nl., Algorithm: 8, 3 Labels, original TTL: 7200 sec, Signature-expiration: 04.09.2019, 02:39:49 +, Signature-Inception: 25.08.2019, 01:39:49 +, KeyTag 30174, Signer-Name: cbs.nl






0 DNSKEY RR found












RRSIG Type 1 validates the A - Result: 87.213.43.244
Validated: RRSIG-Owner adc4.cbs.nl., Algorithm: 8, 3 Labels, original TTL: 7200 sec, Signature-expiration: 04.09.2019, 02:39:49 +, Signature-Inception: 25.08.2019, 01:39:49 +, KeyTag 30174, Signer-Name: cbs.nl






RRSIG Type 16 validates the TXT - Result: v=spf1 mx -all
Validated: RRSIG-Owner adc4.cbs.nl., Algorithm: 8, 3 Labels, original TTL: 7200 sec, Signature-expiration: 04.09.2019, 02:39:49 +, Signature-Inception: 25.08.2019, 01:39:49 +, KeyTag 30174, Signer-Name: cbs.nl






RRSIG Type 28 validates the AAAA - Result: 2001:067C:14B0:1816:0000:0000:0000:0244
Validated: RRSIG-Owner adc4.cbs.nl., Algorithm: 8, 3 Labels, original TTL: 7200 sec, Signature-expiration: 04.09.2019, 02:39:49 +, Signature-Inception: 25.08.2019, 01:39:49 +, KeyTag 30174, Signer-Name: cbs.nl






RRSIG Type 50, expiration 2019-09-04 02:39:49 + validates the NSEC3 RR that proves the not-existence of the CNAME RR.
Bitmap: A, TXT, AAAA, RRSIG






RRSIG Type 50, expiration 2019-09-04 02:39:49 + validates the NSEC3 RR that proves the not-existence of the TLSA RR.
Bitmap: A, AAAA, RRSIG






RRSIG Type 50, expiration 2019-09-04 02:39:49 + validates the NSEC3 RR that proves the not-existence of the TLSA RR.
Bitmap: A, TXT, AAAA, RRSIG






RRSIG Type 50, expiration 2019-09-04 02:39:49 + validates the NSEC3 RR that proves the not-existence of the CAA RR.
Bitmap: A, TXT, AAAA, RRSIG

 

3. Name Servers

DomainNameserverNS-IP
www.vragenlijst.cbs.nl
  dnsa4.cbs.nl

cbs.nl
  cbs01.dns.internl.net / cbs01.dns.internl.net


  dnsa3.cbs.nl


  dnsa4.cbs.nl

nl
  ns1.dns.nl / LHR2


  ns2.dns.nl / s2.amx


  ns3.dns.nl / tld-nl-fra2


  sns-pb.isc.org / pb-ams-ns2.sns.isc.org


adc4.cbs.nl
  dnsa4.cbs.nl
87.213.43.203
Utrecht/Provincie Utrecht/Netherlands (NL) - Tele 2 Nederland B.V.


 
2001:67c:14b0:1805::16
Liten/Central Bohemia/Czechia (CZ) - Tele 2 Nederland B.V.

cbs.nl
  cbs01.dns.internl.net / cbs01.dns.internl.net


  dnsa3.cbs.nl


  dnsa4.cbs.nl

nl
  ns1.dns.nl / LHR2


  ns2.dns.nl / s2.amx


  ns3.dns.nl / tld-nl-fra2


  sns-pb.isc.org / pb-ams-ns2.sns.isc.org

 

4. SOA-Entries


Domain:nl
Zone-Name:
Primary:ns1.dns.nl
Mail:hostmaster.domain-registry.nl
Serial:2019082834
Refresh:3600
Retry:600
Expire:2419200
TTL:600
num Entries:4


Domain:cbs.nl
Zone-Name:
Primary:dnsa4.cbs.nl
Mail:postmaster.cbs.nl
Serial:2017034867
Refresh:14400
Retry:3600
Expire:1209600
TTL:7200
num Entries:3


Domain:www.vragenlijst.cbs.nl
Zone-Name:
Primary:
Mail:
Serial:
Refresh:
Retry:
Expire:
TTL:
num Entries:1



Domain:nl
Zone-Name:
Primary:ns1.dns.nl
Mail:hostmaster.domain-registry.nl
Serial:2019082834
Refresh:3600
Retry:600
Expire:2419200
TTL:600
num Entries:4


Domain:cbs.nl
Zone-Name:
Primary:dnsa4.cbs.nl
Mail:postmaster.cbs.nl
Serial:2017034867
Refresh:14400
Retry:3600
Expire:1209600
TTL:7200
num Entries:3


Domain:adc4.cbs.nl
Zone-Name:
Primary:dnsa4.cbs.nl
Mail:postmaster.cbs.nl
Serial:2017034867
Refresh:14400
Retry:3600
Expire:1209600
TTL:7200
num Entries:2


5. Screenshots

No Screenshot listed, because no screenshot found. Perhaps the check is too old, the feature startet 2019-12-23.

 

 

6. Url-Checks


:

:
DomainnameHttp-StatusredirectSec.G
• http://vragenlijst.cbs.nl/
87.213.43.244
301
https://vragenlijst.cbs.nl/

0.047
A
Location: https://vragenlijst.cbs.nl/
Connection: close
Cache-Control: no-cache
Pragma: no-cache

• http://vragenlijst.cbs.nl/
2001:67c:14b0:1816::244
301
https://vragenlijst.cbs.nl/

0.060
A
Location: https://vragenlijst.cbs.nl/
Connection: close
Cache-Control: no-cache
Pragma: no-cache

• https://vragenlijst.cbs.nl/
87.213.43.244
200


3.267
A
Content-Type: text/html
Last-Modified: Wed, 29 Apr 2015 07:31:00 GMT
Accept-Ranges: bytes
ETag: "0527c704e82d01:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 28 Aug 2019 15:28:44 GMT
Content-Length: 2059
Strict-Transport-Security: max-age=31536000

• https://vragenlijst.cbs.nl/
2001:67c:14b0:1816::244
200


3.376
A
Content-Type: text/html
Last-Modified: Wed, 29 Apr 2015 07:31:00 GMT
Accept-Ranges: bytes
ETag: "0527c704e82d01:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 28 Aug 2019 15:28:41 GMT
Content-Length: 2059
Strict-Transport-Security: max-age=31536000

• http://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
87.213.43.244
301
https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

0.063
A
Visible Content:
Location: https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Connection: close
Cache-Control: no-cache
Pragma: no-cache

• http://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
2001:67c:14b0:1816::244
301
https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

0.047
A
Visible Content:
Location: https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
Connection: close
Cache-Control: no-cache
Pragma: no-cache

• https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de

404


3.266
A
Not Found
Visible Content:
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 28 Aug 2019 15:28:48 GMT
Content-Length: 1245
Strict-Transport-Security: max-age=31536000

 

7. Comments


1. General Results, most used to calculate the result

Aname "vragenlijst.cbs.nl" is subdomain, public suffix is "nl", top-level-domain-type is "country-code", Country is Netherlands (the), tld-manager is "SIDN (Stichting Internet Domeinregistratie Nederland)"
AGood: All ip addresses are public addresses
AGood: No asked Authoritative Name Server had a timeout
ADNS: "Name Error" means: No www-dns-entry defined. This isn't a problem
AGood: destination is https
AGood - only one version with Http-Status 200
AGood: one preferred version: non-www is preferred
AGood: every https has a Strict Transport Security Header
AGood: HSTS max-age is long enough, 31536000 seconds = 365 days
HSTS-Preload-Status: unknown. Domain never included in the Preload-list. Check https://hstspreload.org/ to learn some basics about the Google-Preload-List.
AGood: Some urls with http status 200/404 have a complete Content-Type header (MediaType / MediaSubType + correct charset):0 complete Content-Type - header (3 urls)
https://vragenlijst.cbs.nl/ 87.213.43.244


Url with incomplete Content-Type - header - missing charset
https://vragenlijst.cbs.nl/ 2001:67c:14b0:1816::244


Url with incomplete Content-Type - header - missing charset
https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de


Url with incomplete Content-Type - header - missing charset
Ahttp://vragenlijst.cbs.nl/ 87.213.43.244
301
https://vragenlijst.cbs.nl/
Correct redirect http - https with the same domain name
Ahttp://vragenlijst.cbs.nl/ 2001:67c:14b0:1816::244
301
https://vragenlijst.cbs.nl/
Correct redirect http - https with the same domain name

2. Header-Checks


3. DNS- and NameServer - Checks

AGood: Nameserver supports TCP connections: 6 good Nameserver
AGood: Nameserver supports Echo Capitalization: 6 good Nameserver
AGood: Nameserver supports EDNS with max. 512 Byte Udp payload, message is smaller: 6 good Nameserver
AGood: Nameserver has passed 10 EDNS-Checks (OP100, FLAGS, V1, V1OP100, V1FLAGS, DNSSEC, V1DNSSEC, NSID, COOKIE, CLIENTSUBNET): 6 good Nameserver
Nameserver doesn't pass all EDNS-Checks: dnsa4.cbs.nl: OP100: no result. FLAGS: no result. V1: no result. V1OP100: no result. V1FLAGS: no result. DNSSEC: no result. V1DNSSEC: no result. NSID: no result. COOKIE: no result. CLIENTSUBNET: no result.
Nameserver doesn't pass all EDNS-Checks: sns-pb.isc.org: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found (pb-ams-ns2.sns.isc.org). COOKIE: fatal timeout. CLIENTSUBNET: ok.
Nameserver doesn't pass all EDNS-Checks: sns-pb.isc.org: OP100: ok. FLAGS: ok. V1: ok. V1OP100: ok. V1FLAGS: ok. DNSSEC: ok. V1DNSSEC: ok. NSID: SOA expected, but NOT found, NOERR expectend and NOERR found, Version 0 expectend and found (pb-ams-ns2.sns.isc.org). COOKIE: fatal timeout. CLIENTSUBNET: ok.
AGood: All SOA have the same Serial Number
AGood: CAA entries found, creating certificate is limited: letsencrypt.org is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: pkioverheid.nl is allowed to create certificates
AGood: CAA entries found, creating certificate is limited: quovadisglobal.com is allowed to create certificates

4. Content- and Performance-critical Checks

AGood: All checks /.well-known/acme-challenge/random-filename without redirects answer with the expected http status 404 - Not Found. Creating a Letsencrypt certificate via http-01 challenge should work. If it doesn't work: Check your vHost configuration (apachectl -S, httpd -S, nginx -T). Every combination of port and ServerName / ServerAlias (Apache) or Server (Nginx) must be unique. Merge duplicated entries in one vHost. If you use an IIS, extensionless files must be allowed in the /.well-known/acme-challenge subdirectory. Create a web.config in that directory. Content: <configuration><system.webServer><staticContent><mimeMap fileExtension="." mimeType="text/plain" /></staticContent></system.webServer></configuration>. If you have a redirect http ⇒ https, that's ok, Letsencrypt follows such redirects to port 80 / 443 (same or other server). There must be a certificate. But the certificate may be expired, self signed or with a not matching domain name. Checking the validation file Letsencrypt ignores such certificate errors. Trouble creating a certificate? Use https://community.letsencrypt.org/ to ask.
AGood: Domainname is not on the "Specially Designated Nationals And Blocked Persons List" (SDN). That's an US-list of individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries. It also lists individuals, groups, and entities, such as terrorists and narcotics traffickers designated under programs that are not country-specific. Collectively, such individuals and companies are called "Specially Designated Nationals" or "SDNs." Their assets are blocked and U.S. persons are generally prohibited from dealing with them. So if a domain name is on that list, it's impossible to create a Letsencrypt certificate with that domain name. Check the list manual - https://www.treasury.gov/resource-center/sanctions/sdn-list/pages/default.aspx
https://vragenlijst.cbs.nl/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
404
3.266 seconds
Warning: 404 needs more then one second
ADuration: 59420 milliseconds, 59.420 seconds

 

8. Connections

DomainIPPortCert.ProtocolKeyExchangeStrengthCipherStrengthHashAlgorithmOCSP stapling
Domain/KeyExchangeIP/StrengthPort/CipherCert./StrengthProtocol/HashAlgorithmOCSP stapling
vragenlijst.cbs.nl
87.213.43.244
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
vragenlijst.cbs.nl
87.213.43.244
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
 
no Tls.1.2
no Tls.1.1
no Tls.1.0

no Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)

1CN=vragenlijst.cbs.nl, OU=BTS, O=Centraal Bureau voor de Statistiek, L='s-Gravenhage, C=NL, ST=Zuid-Holland


2CN=QuoVadis Global SSL ICA G3, O=QuoVadis Limited, C=BM


vragenlijst.cbs.nl
2001:67c:14b0:1816::244
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

vragenlijst.cbs.nl
2001:67c:14b0:1816::244
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
 
no Tls.1.2
no Tls.1.1
no Tls.1.0

no Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)

1CN=vragenlijst.cbs.nl, OU=BTS, O=Centraal Bureau voor de Statistiek, L='s-Gravenhage, C=NL, ST=Zuid-Holland


2CN=QuoVadis Global SSL ICA G3, O=QuoVadis Limited, C=BM


vragenlijst.cbs.nl
vragenlijst.cbs.nl
443
ok
Tls12
ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok

vragenlijst.cbs.nl
vragenlijst.cbs.nl
443
ok
Tls12

ECDH Ephermal
256
Aes128
128
Sha256
error checking OCSP stapling
ok
 
no Tls.1.2
no Tls.1.1
no Tls.1.0

no Tls.1.2
no Tls.1.1
no Tls.1.0
Chain (complete)

1CN=vragenlijst.cbs.nl, OU=BTS, O=Centraal Bureau voor de Statistiek, L='s-Gravenhage, C=NL, ST=Zuid-Holland


2CN=QuoVadis Global SSL ICA G3, O=QuoVadis Limited, C=BM

 

9. Certificates

1.
1.
CN=vragenlijst.cbs.nl, OU=BTS, O=Centraal Bureau voor de Statistiek, L='s-Gravenhage, S=Zuid-Holland, C=NL
23.08.2019
23.08.2020
1666 days expired
vragenlijst.cbs.nl - 1 entry
1.
1.
CN=vragenlijst.cbs.nl, OU=BTS, O=Centraal Bureau voor de Statistiek, L='s-Gravenhage, S=Zuid-Holland, C=NL
23.08.2019

23.08.2020
1666 days expired


vragenlijst.cbs.nl - 1 entry

KeyalgorithmRSA encryption (2048 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:62567E6694EF0C06188498B5C345EA812CAAB714
Thumbprint:A3CF8D782EE1A36D4899B0B1ED91A7C4DADA22A3
SHA256 / Certificate:uIjWiuG3stmq3JkxD+LNF7VswR8TERMTTiEBFrQ2JKA=
SHA256 hex / Cert (DANE * 0 1):e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA256 hex / PublicKey (DANE * 1 1):2068d76ffd6329f28b48d1b18fda2f423a36e685485e0ec13cf216af18153a6d
SHA256 hex / Subject Public Key Information (SPKI):2068d76ffd6329f28b48d1b18fda2f423a36e685485e0ec13cf216af18153a6d
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.quovadisglobal.com
OCSP - must staple:no
Certificate Transparency:yes
Enhanced Key Usage:Client Authentication (1.3.6.1.5.5.7.3.2), Server Authentication (1.3.6.1.5.5.7.3.1)




2.
CN=QuoVadis Global SSL ICA G3, O=QuoVadis Limited, C=BM
06.11.2012
06.11.2022
861 days expired


2.
CN=QuoVadis Global SSL ICA G3, O=QuoVadis Limited, C=BM
06.11.2012

06.11.2022
861 days expired




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:7ED6E79CC9AD81C4C8193EF95D4428770E341317
Thumbprint:E90BCCA3D134127EF646E854723F137D7971DB64
SHA256 / Certificate:yrnBLb3jrV0rwCAbVLGL4gnNXhRqqghau98kGwlt/0c=
SHA256 hex / Cert (DANE * 0 1):cab9c12dbde3ad5d2bc0201b54b18be209cd5e146aaa085abbdf241b096dff47
SHA256 hex / PublicKey (DANE * 1 1):28cde264f49c781fa1818b8d23e7128382d1813894c427868eb7d7450018e91b
SHA256 hex / Subject Public Key Information (SPKI):28cde264f49c781fa1818b8d23e7128382d1813894c427868eb7d7450018e91b
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:http://ocsp.quovadisglobal.com
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




3.
CN=QuoVadis Root CA 2 G3, O=QuoVadis Limited, C=BM
12.01.2012
12.01.2042
expires in 6146 days


3.
CN=QuoVadis Root CA 2 G3, O=QuoVadis Limited, C=BM
12.01.2012

12.01.2042
expires in 6146 days




KeyalgorithmRSA encryption (4096 bit)
Signatur:SHA256 With RSA-Encryption
Serial Number:445734245B81899B35F2CEB82B3B5BA726F07528
Thumbprint:093C61F38B8BDC7D55DF7538020500E125F5C836
SHA256 / Certificate:j+T7Cvk6TQ1n2wvrsj43xxvzJdy83SQOoE2vWLR+GEA=
SHA256 hex / Cert (DANE * 0 1):8fe4fb0af93a4d0d67db0bebb23e37c71bf325dcbcdd240ea04daf58b47e1840
SHA256 hex / PublicKey (DANE * 1 1):4a49edbd2f8f8230bd5592b313573fe1c172a45fa98011cc1eddbb36ade3fce5
SHA256 hex / Subject Public Key Information (SPKI):4a49edbd2f8f8230bd5592b313573fe1c172a45fa98011cc1eddbb36ade3fce5
SPKI checked via https://v1.pwnedkeys.com/spki-hash:Good: Key isn't compromised
OCSP - Url:
OCSP - must staple:no
Certificate Transparency:no
Enhanced Key Usage:




 

10. Last Certificates - Certificate Transparency Log Check

1. Source CertSpotter - active certificates (one check per day)

Small Code Update - wait one minute

 

2. Source crt.sh - old and new certificates, sometimes very slow - only certificates with "not after" > of the last months are listed

Small Code Update - wait one minute

 

11. Html-Content - Entries

Summary

No data found or small Code-update

 

Details (currently limited to 500 rows - some problems with spam users)

Small Code Update - wait one minute

 

12. Html-Parsing via https://validator.w3.org/nu/

Small Code update, wait one minute

 

13. Nameserver - IP-Adresses

Required Root-climbing DNS-Queries to find ip addresses of all Name Servers:

 

No NameServer - IP address informations found. The feature is new (2020-05-07), so recheck this domain.

 

14. CAA - Entries

DomainnameflagNameValue∑ Queries∑ Timeout
vragenlijst.cbs.nl



1
0
adc4.cbs.nl
0

no CAA entry found
1
0
cbs.nl
5
issue
letsencrypt.org
1
0

5
issue
letsencrypt.org
1
0

5
iodef
mailto:rpgr@cbs.nl
1
0

5
iodef
mailto:rpgr@cbs.nl
1
0

5
issue
pkioverheid.nl
1
0

5
issue
pkioverheid.nl
1
0

5
issue
quovadisglobal.com
1
0

5
issue
quovadisglobal.com
1
0
nl
0

no CAA entry found
1
0

0

no CAA entry found
1
0

 

15. TXT - Entries

DomainnameTXT EntryStatus∑ Queries∑ Timeout
cbs.nl
804bc80c-cca6-4d27-b5ae-e4ffb0f082a2-04072018
ok
1
0
cbs.nl
804bc80c-cca6-4d27-b5ae-e4ffb0f082a2-04072018
ok
1
0
cbs.nl
MS=FD936BDBA3E8034A3C49BD3B5D6D4AC48E42B64E
ok
1
0
cbs.nl
MS=FD936BDBA3E8034A3C49BD3B5D6D4AC48E42B64E
ok
1
0
cbs.nl
MS=ms84063695
ok
1
0
cbs.nl
MS=ms84063695
ok
1
0
cbs.nl
v=spf1 mx include:_spf_mx.solvinity.com include:_spf.salesforce.com include:spf.afas.online -all
ok
1
0
cbs.nl
v=spf1 mx include:_spf_mx.solvinity.com include:_spf.salesforce.com include:spf.afas.online -all
ok
1
0
adc4.cbs.nl
v=spf1 mx -all
ok
1
0
vragenlijst.cbs.nl
v=spf1 mx -all
ok
1
0
_acme-challenge.adc4.cbs.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.adc4.cbs.nl.cbs.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.vragenlijst.cbs.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.adc4.cbs.nl.adc4.cbs.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.vragenlijst.cbs.nl.cbs.nl

Name Error - The domain name does not exist
1
0
_acme-challenge.vragenlijst.cbs.nl.vragenlijst.cbs.nl

Name Error - The domain name does not exist
1
0

 

16. DomainService - Entries

No DomainServiceEntries entries found

 

 

17. Cipher Suites

No Ciphers found

 

18. Portchecks

No open Ports <> 80 / 443 found, so no additional Ports checked.

 

 

Permalink: https://check-your-website.server-daten.de/?i=c5369d21-5e18-4850-8153-236d74dec37c

 

Last Result: https://check-your-website.server-daten.de/?q=vragenlijst.cbs.nl - 2019-08-28 17:28:02

 

Do you like this page? Support this tool, add a link on your page:

 

<a href="https://check-your-website.server-daten.de/?q=vragenlijst.cbs.nl" target="_blank">Check this Site: vragenlijst.cbs.nl</a>

 

 

Do you really want to support this project? Donate: Check-your-website, IBAN DE98 1001 0010 0575 2211 07, SWIFT/BIC PBNKDEFF, Euro

 

QR-Code of this page - https://check-your-website.server-daten.de/?d=vragenlijst.cbs.nl