css-connect.de
Scanned 9 days ago · Aug 28, 2026, 1:22 PM
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
- the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
- the HSTS max-age is shorter than 6 months
Citrix 2026 protocol baseline
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.
Certificate
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "cloudflare"
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
- at least one reachable mail server does not support STARTTLS
Mail servers
Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.