citrix.weima.com
Scanned 3 hours ago · Oct 11, 2026, 3:56 PM
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
- no Strict-Transport-Security (HSTS) header
Protocol baseline
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.
Certificate
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
- no Strict-Transport-Security header
- no Permissions-Policy header
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "Apache"
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
- at least one reachable mail server does not support STARTTLS
- no SPF record
- no DMARC record
Mail servers
Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.