staebler.online
Scanned 2 hours ago · Sep 28, 2026, 8:28 AM
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
- the server accepts 2 weak cipher suite(s): ECDHE-RSA-AES128-SHA256, AES128-GCM-SHA256
- no Strict-Transport-Security (HSTS) header
Protocol baseline
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.
Certificate
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
- no Content-Security-Policy header
- no Strict-Transport-Security header
- no X-Content-Type-Options: nosniff
- no clickjacking protection (X-Frame-Options or frame-ancestors)
- no Referrer-Policy header
- no Permissions-Policy header
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "Apache"
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
- no SPF record
Mail servers
Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.
Certificate on port 25