karstoft.pro

DNS sikkerhedsrapport

11 bestået
8 advarsler
2 fejlet
D
61/100
Svag konfiguration - væsentlige problemer fundet.
Scannet 16. Jan 2026 kl. 12:31

Website preview

Domæneoplysninger

Alder

9 år, 2 måneder

Moden

Udløber om

275 dage

28. Nov 2026

DNSSEC

Inaktiv

Navneservere

3

servere

Registrar Key-Systems GmbH
Oprettet 28. Nov 2016
Sidst opdateret 16. Jan 2026
Status Aktiv

Navneservere

ns1.digitalocean.com ns2.digitalocean.com ns3.digitalocean.com

Domænestatus (EPP)

client transfer prohibited

Domæne metrics

PageRank

0

Ingen data

Archive.org

0

Ingen historik

Metrics hentet for 1 måned siden

Sikkerhedsoversigt

HTTPS

SSL

HSTS

SPF

DMARC

DNSSEC

Sikkerhed

1 3 2

Ingen SPF record fundet

Tilføj en SPF record for at forhindre email spoofing

High

Ingen DMARC record fundet

Tilføj en DMARC record for at beskytte mod email spoofing

High

Ingen DKIM records fundet (testet almindelige selectors)

Medium

DNSSEC er ikke aktiveret

Aktiver DNSSEC for at beskytte mod DNS spoofing

Medium

Ingen CAA records fundet

Tilføj CAA records for at kontrollere hvilke CAs der kan udstede certifikater

Low

Ingen security.txt fil (RFC 9116)

Overvej at tilføje /.well-known/security.txt med kontaktinfo til sikkerhedsrapportering

MTA-STS ikke konfigureret

MTA-STS sikrer krypteret email-transport. Relevant for NIS2 compliance.

Zone transfer (AXFR) er korrekt blokeret

SSL / HTTPS

4 1

HSTS er ikke aktiveret

Aktiver HSTS for at forbedre sikkerheden

Medium

HTTPS er aktiveret

HTTP redirecter til HTTPS

SSL-certifikat er gyldigt

SSL-certifikat er gyldigt i 72 dage

DNS Records

6

Ingen MX records fundet (domænet modtager muligvis ikke email)

3 nameserver(s) fundet

Multiple nameservers for redundans

Ingen wildcard DNS konfiguration

2 A record(s) fundet

[ { "ip": "172.66.0.96", "ttl": 3598 }, { "ip": "162.159.140.98", "ttl": 3598 } ]

IPv6 (AAAA) understøttet

[ { "ttl": 58, "ipv6": "2a06:98c1:58::60" }, { "ttl": 58, "ipv6": "2606:4700:7::60" } ]

SOA record fundet

{ "mname": "ns1.digitalocean.com", "retry": 3600, "rname": "hostmaster.karstoft.pro", "expire": 604800, "serial": 1756536388, "refresh": 10800, "minimum_ttl": 1800 }

HTTP Headers

4

Strict-Transport-Security (HSTS) header mangler

Tilføj Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

High

X-Frame-Options header mangler

Tilføj X-Frame-Options: DENY

Medium

Content-Security-Policy header mangler

Medium

X-Content-Type-Options header mangler

Low

Referrer-Policy header mangler

Permissions-Policy header mangler

Rå data (JSON)

{
    "dns": {
        "a": [
            {
                "ip": "172.66.0.96",
                "ttl": 3598
            },
            {
                "ip": "162.159.140.98",
                "ttl": 3598
            }
        ],
        "mx": [],
        "ns": [
            {
                "ttl": 1799,
                "host": "ns1.digitalocean.com"
            },
            {
                "ttl": 1799,
                "host": "ns3.digitalocean.com"
            },
            {
                "ttl": 1799,
                "host": "ns2.digitalocean.com"
            }
        ],
        "caa": [],
        "soa": [
            {
                "mname": "ns1.digitalocean.com",
                "retry": 3600,
                "rname": "hostmaster.karstoft.pro",
                "expire": 604800,
                "serial": 1756536388,
                "refresh": 10800,
                "minimum_ttl": 1800
            }
        ],
        "txt": [],
        "aaaa": [
            {
                "ttl": 58,
                "ipv6": "2a06:98c1:58::60"
            },
            {
                "ttl": 58,
                "ipv6": "2606:4700:7::60"
            }
        ],
        "cname": []
    },
    "ssl": {
        "san": [
            "karstoft.pro"
        ],
        "chain": [
            {
                "issuer": "WE1",
                "subject": "karstoft.pro",
                "valid_to": "2026-03-30T09:42:05+00:00"
            },
            {
                "issuer": "GTS Root R4",
                "subject": "WE1",
                "valid_to": "2029-02-20T14:00:00+00:00"
            },
            {
                "issuer": "GlobalSign Root CA",
                "subject": "GTS Root R4",
                "valid_to": "2028-01-28T00:00:42+00:00"
            }
        ],
        "issuer": {
            "country": "US",
            "common_name": "WE1",
            "organization": "Google Trust Services"
        },
        "subject": {
            "state": null,
            "country": null,
            "locality": null,
            "common_name": "karstoft.pro",
            "organization": null,
            "organizational_unit": null
        },
        "is_valid": true,
        "valid_to": "2026-03-30T09:42:05+00:00",
        "is_expired": false,
        "valid_from": "2025-12-30T08:42:15+00:00",
        "chain_length": 3,
        "serial_number": "7AF008A349A8331213787535292E7E99",
        "days_remaining": 72,
        "is_self_signed": false,
        "signature_algorithm": "ecdsa-with-SHA256"
    },
    "tls": {
        "cipher": null,
        "version": null,
        "is_secure": false,
        "is_insecure": false,
        "is_outdated": false
    },
    "https": {
        "has_https": true,
        "hsts_enabled": false,
        "hsts_max_age": null,
        "hsts_preload": false,
        "redirects_to_https": true,
        "hsts_include_subdomains": false
    },
    "whois": {
        "dnssec": false,
        "domain": "karstoft.pro",
        "status": "registered",
        "registrar": "Key-Systems GmbH",
        "raw_status": [
            "client transfer prohibited"
        ],
        "expiry_date": "2026-11-28T21:59:05+00:00",
        "nameservers": [
            "ns1.digitalocean.com",
            "ns2.digitalocean.com",
            "ns3.digitalocean.com"
        ],
        "created_date": "2016-11-28T21:59:05+00:00",
        "updated_date": "2026-01-16T11:31:17+00:00"
    },
    "metrics": {
        "pagerank": 0,
        "fetched_at": "2026-01-16T12:32:36+01:00",
        "wayback_snapshots": null
    },
    "internal_checks": {
        "open_resolver": {
            "checked_at": "2026-01-16T12:31:32+01:00",
            "nameserver": "ns1.digitalocean.com",
            "is_open_resolver": false
        }
    }
}