connect-app.net
Scanned 1 hour ago · Sep 24, 2026, 8:50 AM
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
- the server still accepts TLS 1.0 and/or TLS 1.1, both deprecated
- the server does not support TLS 1.3
- the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
Protocol baseline
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.
Certificate
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
- no Content-Security-Policy header
- no X-Content-Type-Options: nosniff
- no clickjacking protection (X-Frame-Options or frame-ancestors)
- no Referrer-Policy header
- no Permissions-Policy header
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "Apache/2.2.15 (CentOS)"
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
- at least one reachable mail server does not support STARTTLS
- no DMARC record
Mail servers
Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.