css.de
Scanned 5 days ago · Aug 14, 2026, 10:48 AM
C
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
Score69%
- the certificate chain is not trusted by common trust stores
- the server does not support TLS 1.3
- the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
- no Strict-Transport-Security (HSTS) header
NegotiatedTLSv1.2, ECDHE-RSA-AES128-GCM-SHA256
Forward secrecyYes
HSTSnot enabled
Protocol support
NoTLS 1.3
YesTLS 1.2
NoTLS 1.1 (deprecated)
NoTLS 1.0 (deprecated)
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - “accepted” means the server completed a handshake using it, not merely that it's listed as a possibility.
ECDHE-ECDSA-AES256-GCM-SHA384
SecureNot offered
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureNot offered
ECDHE-RSA-CHACHA20-POLY1305
SecureNot offered
DHE-RSA-AES256-GCM-SHA384
SecureAccepted
DHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES256-SHA384
WeakAccepted
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakAccepted
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered
Certificate
Subject*.css.de
IssuerSectigo Public Server Authentication CA DV R36
Additional names*.css.de, css.de
ValidNov 10, 2025, 12:00 AM – Nov 27, 2026, 11:59 PM (expires in 106 days)
KeyRSA 2048 bit
Certificate chain1 certificate(s)
Trusted by common trust storesNo
Matches the scanned hostnameYes
Self-signedNo
–
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
Scoren/a
- could not fetch https://css.de/
A+Email
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
Score100%
- port 25 was not reachable on any mail server from our scanner (commonly blocked by cloud providers) - mail transport security could not be verified
SPFv=spf1 ip4:109.230.198.46 ip4:212.227.233.210 include:_spf-eu.ionos.com include:spf.hornetsecurity.com include:notification.fortinet.net include:mail.zendesk.com include:spf.protection.outlook.com include:26246248.spf04.hubspotemail.net ip4:91.26.120.106 include:_spf.atlassian.net ~all
DMARCv=DMARC1; p=quarantine; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1; adkim=r; aspf=r;
Mail servers
mx23a.antispameurope.comnot reachable on port 25 from our scanner
mx23b.antispameurope.comnot reachable on port 25 from our scanner
mx23c.antispameurope.comnot reachable on port 25 from our scanner