aethercert

api.serverplus9.com

Scanned 2 hours ago · Oct 11, 2026, 5:29 PM

A

TLS & Certificate

Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.

Score90%
  • no Strict-Transport-Security (HSTS) header
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSnot enabled

Protocol baseline

YesTLS 1.3 enabled
YesTLS 1.2 enabled
YesTLS 1.1 disabled
YesTLS 1.0 disabled

Cipher suites probed

Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.

ECDHE-ECDSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-RSA-AES256-GCM-SHA384
SecureNot offered
ECDHE-ECDSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-ECDSA-CHACHA20-POLY1305
SecureAccepted
ECDHE-RSA-CHACHA20-POLY1305
SecureNot offered
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakNot offered
ECDHE-RSA-AES128-SHA256
WeakNot offered
AES256-GCM-SHA384
WeakNot offered
AES128-GCM-SHA256
WeakNot offered
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered

Certificate

Subjectserverplus9.com
IssuerWE1
Additional namesserverplus9.com, *.serverplus9.com
ValidAug 17, 2026, 2:55 PM – Nov 15, 2026, 3:53 PM (expires in 35 days)
KeyEC prime256v1
Signature algorithmunknown
SHA-256 fingerprintDD:59:9B:CE:45:9A:C5:64:DC:69:40:50:BD:47:E5:58:67:9A:77:FE:53:D9:DA:6E:DF:08:90:02:23:AE:BD:79
Certificate chain3 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
A-

Security Headers

The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.

Score80%
  • no Strict-Transport-Security header
  • the Server header discloses "cloudflare"
Content-Security-Policydefault-src 'none'; script-src 'nonce-RLQV78gvt8quQUPcfGZQox' 'unsafe-eval' https://challenges.cloudflare.com; script-src-attr 'none'; style-src 'unsafe-inline'; img-src 'self' https://challenges.cloudflare.com; connect-src 'self' https://challenges.cloudflare.com; frame-src 'self' https://challenges.cloudflare.com blob:; child-src 'self' https://challenges.cloudflare.com blob:; worker-src blob:; form-action http: https:; base-uri 'self'
Strict-Transport-Securitynot set
X-Content-Type-Optionsnosniff
X-Frame-OptionsSAMEORIGIN
Referrer-Policysame-origin
Permissions-Policyaccelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Cross-Origin-Opener-Policysame-origin
Cross-Origin-Resource-Policysame-origin
–

Email

Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.

Scoren/a
  • no mail servers (MX records) found for this domain