staebler.online

Scanned 2 hours ago · Sep 28, 2026, 8:28 AM

A-

TLS & Certificate

Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.

Score80%
  • the server accepts 2 weak cipher suite(s): ECDHE-RSA-AES128-SHA256, AES128-GCM-SHA256
  • no Strict-Transport-Security (HSTS) header
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSnot enabled

Protocol baseline

YesTLS 1.3 enabled
YesTLS 1.2 enabled
YesTLS 1.1 disabled
YesTLS 1.0 disabled

Cipher suites probed

Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.

ECDHE-ECDSA-AES256-GCM-SHA384
SecureNot offered
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureNot offered
ECDHE-RSA-CHACHA20-POLY1305
SecureNot offered
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakNot offered
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakNot offered
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered

Certificate

Subjectstaebler.online
IssuerSectigo Public Server Authentication CA DV R36
Additional namesstaebler.online, www.staebler.online
ValidFeb 24, 2026, 12:00 AM – Mar 17, 2027, 11:59 PM (expires in 171 days)
KeyRSA 2048 bit
Signature algorithmunknown
SHA-256 fingerprintB3:43:42:42:D6:90:7E:B7:B6:18:33:D3:08:C2:49:66:C4:E0:1B:04:89:27:09:5C:72:ED:09:1E:28:A6:D5:16
Certificate chain4 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
F

Security Headers

The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.

Score10%
  • no Content-Security-Policy header
  • no Strict-Transport-Security header
  • no X-Content-Type-Options: nosniff
  • no clickjacking protection (X-Frame-Options or frame-ancestors)
  • no Referrer-Policy header
  • no Permissions-Policy header
  • no Cross-Origin-Opener-Policy header
  • no Cross-Origin-Resource-Policy header
  • the Server header discloses "Apache"
Content-Security-Policynot set
Strict-Transport-Securitynot set
X-Content-Type-Optionsnot set
X-Frame-Optionsnot set
Referrer-Policynot set
Permissions-Policynot set
Cross-Origin-Opener-Policynot set
Cross-Origin-Resource-Policynot set
B

Email

Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.

Score79%
  • no SPF record
SPFnot set
DMARCv=DMARC1;p=reject;
MX recordssmtpin.rzone.de

Mail servers

Each mail port is probed with a full TLS handshake - STARTTLS on 25, 587, 143 and 110, implicit TLS on 465, 993 and 995 - to read the certificate actually bound to it. Only inbound SMTP on port 25 affects the grade.

smtpin.rzone.deMX preference 5
25 SMTPTLSv1.3, TLS_AES_256_GCM_SHA384
587 Submissionconnection refused - nothing is listening on this port
465 SMTPSconnection refused - nothing is listening on this port
143 IMAPconnection refused - nothing is listening on this port
993 IMAPSconnection refused - nothing is listening on this port
110 POP3connection refused - nothing is listening on this port
995 POP3Sconnection refused - nothing is listening on this port

Certificate on port 25

Subjectsmtpin.rzone.de
IssuerTelekom Security ServerID OV Class 2 CA
Additional namessmtpin.rzone.de
ValidJan 13, 2026, 8:55 AM – Jan 17, 2027, 11:59 PM (expires in 112 days)
KeyRSA 4096 bit
Signature algorithmunknown
SHA-256 fingerprint39:B7:14:C3:C2:2C:25:29:3E:99:18:4C:11:82:61:60:D1:3F:A9:96:15:12:9F:D8:BA:4C:C7:B9:AE:62:7D:2B
Certificate chain3 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo