css-connect.de

Scanned 9 days ago · Aug 28, 2026, 1:22 PM

A-

TLS & Certificate

Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.

Score85%
  • the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
  • the HSTS max-age is shorter than 6 months
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSenabled, max-age=2592000

Citrix 2026 protocol baseline

YesTLS 1.3 enabled
YesTLS 1.2 enabled
YesTLS 1.1 disabled
YesTLS 1.0 disabled

Cipher suites probed

Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.

ECDHE-ECDSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureAccepted
ECDHE-RSA-CHACHA20-POLY1305
SecureAccepted
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakAccepted
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakAccepted
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered

Certificate

Subjectcss-connect.de
IssuerWE1
Additional namescss-connect.de, *.css-connect.de
ValidJul 9, 2026, 10:29 AM – Oct 7, 2026, 11:29 AM (expires in 40 days)
KeyEC prime256v1
Signature algorithmunknown
SHA-256 fingerprintBC:0F:15:EF:79:DD:C7:42:7C:0E:A3:FE:B7:34:FF:2F:92:C3:18:89:B6:36:B7:AB:22:7A:D0:B6:B5:D5:97:E1
Certificate chain3 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
A-

Security Headers

The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.

Score85%
  • no Cross-Origin-Opener-Policy header
  • no Cross-Origin-Resource-Policy header
  • the Server header discloses "cloudflare"
Content-Security-Policydefault-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'; worker-src 'self' *.css-connect.de blob:; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://cdnjs.cloudflare.com https://code.jquery.com https://app.usercentrics.eu https://app.eu.usercentrics.eu https://maps.googleapis.com https://karriere.css-connect.de https://blog.css-connect.de https://www.css-connect.de https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.wcs-hitachivantarashowcase-decssconnectgmbh.swcontentsyndication.com https://wcs-hitachivantarashowcase-decssconnectgmbh.swcontentsyndication.com;
Strict-Transport-Securitymax-age=2592000; includeSubDomains; preload
X-Content-Type-Optionsnosniff
X-Frame-Optionsnot set
Referrer-Policysame-origin
Permissions-Policyinterest-cohort=()
Cross-Origin-Opener-Policynot set
Cross-Origin-Resource-Policynot set
C

Email

Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.

Score69%
  • at least one reachable mail server does not support STARTTLS
SPFv=spf1 a a:mail.css-connect.de ip4:62.225.119.70 include:spf.protection.outlook.com include:spf.hornetsecurity.com include:amazonses.com ~all
DMARCv=DMARC1; p=reject; pct=100; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected]; sp=none; aspf=r; adkim=r;
MX recordsmail.css-connect.de

Mail servers

Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.

mail.css-connect.deMX preference 10
25 SMTPreachable, STARTTLS not offered
587 Submissionno response - the port is filtered, or blocked between our scanner and the host
465 SMTPSno response - the port is filtered, or blocked between our scanner and the host
143 IMAPno response - the port is filtered, or blocked between our scanner and the host
993 IMAPSno response - the port is filtered, or blocked between our scanner and the host
110 POP3no response - the port is filtered, or blocked between our scanner and the host
995 POP3Sno response - the port is filtered, or blocked between our scanner and the host