DNS & HTTP Analysis for centos.org

Processing Domain centos.org on 30/03/2019 21:02:39


  • This tool is available free to use at GENSupport
  • Help and Support for your DNS or HTTP issues available on our Forum
  • Whenever you see a clicking on it will take you to more help
  • The version of the data model that was used in this report is 1.004
  • The version that produced this report is 1.015b

Processing DNS Records

Basic Checks

Here we check the basic functioning and security of your DNS

  • Zone Queries 6 Record Types and 14 Records Found
  • Zone Transfer Failed
  • Zone Dump
    • NS
      • centos.org. TTL 14400 ns1.centos.org.
      • centos.org. TTL 14400 ns3.centos.org.
      • centos.org. TTL 14400 ns4.centos.org.
    • MX
      • centos.org. TTL 3600 10 mail.centos.org.
    • SOA
      • centos.org. TTL 3600 ns1.centos.org. hostmaster.centos.org. 2019032902 28800 7200 2400000 3600
    • TXT
      • centos.org. TTL 3600 "google-site-verification=xFWz31gRBrIYS5zOQLeT6oY88Z2UPuW031lo3iGaXBI"
      • centos.org. TTL 3600 "v=spf1 mx ip4:208.100.23.70 ip6:2607:f128:40:1600:225:90ff:fe00:bf20 ip4:176.67.173.46 ip6:2a02:2498:1:3d:21d:9ff:fe65:aedd ip4:164.177.170.49 ip4:85.214.222.242 ip4:50.28.24.115 ip4:85.13.208.9 ip6:2a01:c0:2:4:0:55ff:fe0d:d009 ip4:85.13.226.35 " "ip6:2a01:c0:2:4:92b1:1cff:fe49:2995 ip4:8.43.84.199 -all"
    • A
      • centos.org. TTL 600 85.12.30.226
      • mail.centos.org. TTL 600 208.100.23.70
      • ns1.centos.org. TTL 600 199.187.126.93
      • ns3.centos.org. TTL 600 88.208.217.170
      • ns4.centos.org. TTL 600 62.141.54.220
    • AAAA
      • centos.org. TTL 600 2a01:788:a002:0:225:90ff:fe33:f34c
      • mail.centos.org. TTL 600 2607:f128:40:1600:225:90ff:fe00:bf20

Nameservers

Here we check the setup of your nameservers. All nameservers on your domain should be listed in the zone and returned in an ANY query along with corresponding A and/or AAAA records resolving their address.

  • ns3.centos.org 88.208.217.170 Found and Match. (Found in Address Records)
  • ns1.centos.org 199.187.126.93 Found and Match. (Found in Address Records)
  • ns4.centos.org 62.141.54.220 Found and Match. (Found in Address Records)

Processing TXT Records

Google Domain Verification Record

This record is used by Google to validate domain ownership when setting up Google Analytics etc

  • google-site-verification=xfwz31grbriys5zoqlet6oy88z2upuw031lo3igaxbi

SPF Record:

The SPF Record defines which IP addresses are permitted to send email on this domain's behalf

  • v=spf1 (The SPF Format Version Number)
  • mx (Permit servers listed in MX records - Not a great idea)
  • ip4:208.100.23.70 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip6:2607:f128:40:1600:225:90ff:fe00:bf20 (The IPv6 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip4:176.67.173.46 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip6:2a02:2498:1:3d:21d:9ff:fe65:aedd (Permit servers listed in A records - Not a great idea)
  • ip4:164.177.170.49 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip4:85.214.222.242 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip4:50.28.24.115 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip4:85.13.208.9 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip6:2a01:c0:2:4:0:55ff:fe0d:d009 (Permit servers listed in A records - Not a great idea)
  • ip4:85.13.226.35 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • ip6:2a01:c0:2:4:92b1:1cff:fe49:2995 (Permit servers listed in A records - Not a great idea)
  • ip4:8.43.84.199 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
  • -all (Permit servers listed in A records - Not a great idea)

Processing MX (Mail Exchanger) Records

These Records determine the servers (mail servers) responsible for handling your incomming email. Each service is given a priority and they will be used in that order. If all the priorities are the same then they will be used in a round-robin fashion

  • Priority 10 handled by host mail.centos.org. [208.100.23.70] Valid
    • Email Handled Locally
    • Forward DNS 208.100.23.70 mail.centos.org
    • Reverse DNS mail.centos.org 208.100.23.70
    • Port 25 (smtp) : Open
      • Not Listed in any blacklists

Processing CNAME (Alias) Records

These records are aliases making one hostname relate to another. These are often used to match hosts back to clusters or internal referencs that may change.

    Processing A (IPv4 Address) Records

    These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain. The www record is the most common one and will be used to identify your website address

    • Host: centos.org. = IP: [85.12.30.226] Valid Reachable (19.927ms)
    • Host: mail.centos.org. = IP: [208.100.23.70] Valid Reachable (100.729ms)
    • Host: ns1.centos.org. = IP: [199.187.126.93] Valid Reachable (87.989ms)
    • Host: ns3.centos.org. = IP: [88.208.217.170] Valid Reachable (18.093ms)
    • Host: ns4.centos.org. = IP: [62.141.54.220] Valid Reachable (32.218ms)

    Processing AAAA (IPv6 Address) Records

    These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain

    • Host: centos.org. = IP: [2a01:788:a002:0:225:90ff:fe33:f34c] Valid
    • Host: mail.centos.org. = IP: [2607:f128:40:1600:225:90ff:fe00:bf20] Valid

    Processing Domain Public Records

    • We have been unable to find the website IP from the zone
    • Performed an additional out-of-zone lookup to find website host [85.12.30.226]
    • Domain Name WHOIS Information - centos.org

      • Domain Name CENTOS.ORG
      • Registry Domain ID D103409469-LROR
      • Registrar WHOIS Server whois.comlaude.com
      • Registrar URL: https://comlaude.com/whois
      • Updated Date: 2018-11-05T23:06:17Z
      • Creation Date: 2003-12-04T12:28:30Z
      • Registry Expiry Date: 2019-12-04T12:28:30Z
      • Registrar Registration Expiration Date
      • Registrar Nom-iq Ltd. dba COM LAUDE
      • Registrar IANA ID 470
      • Registrar Abuse Contact Email This email address is being protected from spambots. You need JavaScript enabled to view it.
      • Registrar Abuse Contact Phone +44.2074218250
      • Reseller
      • Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
      • Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
      • Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
      • Registrant Organization Red Hat, Inc.
      • Registrant State/Province NC
      • Registrant Country US
      • Name Server NS1.CENTOS.ORG
      • Name Server NS3.CENTOS.ORG
      • Name Server NS4.CENTOS.ORG
      • DNSSEC unsigned
      • URL of the ICANN Whois Inaccuracy Complaint Form https //www.icann.org/wicf/)

      Website Hosting WHOIS Information - 85.12.30.226

      • NetRange 85.0.0.0 - 85.255.255.255
      • CIDR 85.0.0.0/8
      • NetHandle NET-85-0-0-0-1
      • Parent ()
      • NetType Allocated to RIPE NCC
      • OriginAS
      • Organization RIPE Network Coordination Centre (RIPE)
      • RegDate 2004-04-01
      • Updated 2009-05-18
      • Ref: https://rdap.arin.net/registry/ip/85.0.0.0
      • ResourceLink: https://apps.db.ripe.net/search/query.html
      • ResourceLink whois.ripe.net
      • OrgName RIPE Network Coordination Centre
      • OrgId RIPE
      • Address P.O. Box 10096
      • City Amsterdam
      • StateProv
      • PostalCode 1001EB
      • Country NL
      • RegDate
      • Updated 2013-07-29
      • Ref: https://rdap.arin.net/registry/entity/RIPE
      • ReferralServer: whois://whois.ripe.net
      • ResourceLink: https://apps.db.ripe.net/search/query.html
      • OrgAbuseHandle ABUSE3850-ARIN
      • OrgAbuseName Abuse Contact
      • OrgAbusePhone +31205354444
      • OrgAbuseEmail This email address is being protected from spambots. You need JavaScript enabled to view it.
      • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
      • OrgTechHandle RNO29-ARIN
      • OrgTechName RIPE NCC Operations
      • OrgTechPhone +31 20 535 4444
      • OrgTechEmail This email address is being protected from spambots. You need JavaScript enabled to view it.
      • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
      • inetnum 85.12.0.0 - 85.12.63.255
      • country NL
      • org ORG-EA207-RIPE
      • admin-c BIP11-RIPE
      • tech-c BIP11-RIPE
      • status ALLOCATED PA
      • mnt-by RIPE-NCC-HM-MNT
      • mnt-by BASEIP-MNT
      • mnt-domains BASEIP-MNT
      • mnt-routes BASEIP-MNT
      • created: 2005-03-04T15:31:25Z
      • last-modified: 2016-09-15T12:34:48Z
      • organisation ORG-EA207-RIPE
      • org-name Base IP B.V.
      • org-type LIR
      • address Staten Bolwerk 1
      • address 2011MK
      • address Haarlem
      • address NETHERLANDS
      • phone +31857733066
      • fax-no +31857733069
      • mnt-ref RIPE-NCC-HM-MNT
      • mnt-ref BASEIP-MNT
      • mnt-by RIPE-NCC-HM-MNT
      • mnt-by BASEIP-MNT
      • admin-c PS12989-RIPE
      • admin-c PB6260-RIPE
      • tech-c BIP11-RIPE
      • abuse-c BIP11-RIPE
      • created: 2005-02-24T06:59:15Z
      • last-modified: 2016-09-15T12:35:06Z
      • role Base IP Network Management
      • address Staten Bolwerk 1
      • address 2011MK HAARLEM
      • address The Netherlands
      • abuse-mailbox This email address is being protected from spambots. You need JavaScript enabled to view it.
      • nic-hdl BIP11-RIPE
      • mnt-by BASEIP-MNT
      • created: 2011-08-10T08:02:48Z
      • last-modified: 2018-03-08T14:48:08Z
      • route 85.12.0.0/18
      • origin AS34305
      • mnt-by BASEIP-MNT
      • created: 2013-09-23T08:26:45Z
      • last-modified: 2013-09-23T08:26:45Z
      • source RIPE

    Processing Website

      Website Headers for www.centos.org

      We will obtain the headers from your website and parse them for validity

      • Web Server is nginx/1.12.2
      • Request Response HTTP/1.1 200 OK OK
      • SSL is available and enabled
        • Certificate Name /C=US/ST=North Carolina/L=Raleigh/O=Red Hat Inc./CN=centos.org
        • Certificate Issued To
          • Country US
          • City North Carolina
          • Locality Raleigh
          • Organisation Red Hat Inc.
          • Certificate Scope centos.org
          Certificate Issuer
          • Country US
          • Organisation DigiCert Inc
          • Certificate Scope DigiCert SHA2 High Assurance Server CA
          Certificate Validity
          • Valid From 170703000000Z
          • Valid To 200909120000Z
          Certificate Ciphers
          • SN RSA-SHA256
          • LN sha256WithRSAEncryption
          Certificate Extensions
          • Alternative Hostnames DNS:centos.org, DNS:www.centos.org, DNS:projects.centos.org, DNS:bugs.centos.org, DNS:wiki.centos.org, DNS:fr.centos.org
          • Key Usage TLS Web Server Authentication, TLS Web Client Authentication
      • There was a redirect to https://www.centos.org/
      • General

        • allow Valid methods for a specified resource after a 405 Missing
        • location For Redirects specifies the target Missing
        • connection Control options for the current connection [keep-alive]
        • x-powered-by Specifies Technology in use - Security Risk Missing
        • x-aspnet-version Specifies the ASP.net version - Security Risk Missing
        • accept-ranges To advertise its support of partial requests [bytes]

        Security

        • referrer-policy Modifies the algorithm used to populate the Referer Header [same-origin]
        • x-xss-protection Prevents pages loading when XSS is detected [1; mode=block]
        • feature-policy Allow or Deny the use of browser features Missing
        • p3p Platform for Privacy Preferences Missing
        • content-security-policy CSP Content Security Policy Missing
        • x-frame-options Can we open this response in an iframe [SAMEORIGIN]

        Cross Origin

        • access-control-allow-origin Can we share the response with the given origin Missing
        • access-control-allow-credentials Tells Browsers whether to expose the response to frontend JavaScript Missing
        • access-control-expose-headers Indicates which headers can be exposed as part of the Response Missing
        • access-control-max-age Indicates how long the results of a preflight request can be stored Missing
        • access-control-allow-methods Methods allowed when accessing the resource in response to a preflight request Missing
        • access-control-allow-headers Indicates which headers can be used during the actual request Missing

        Content

        • content-language The natural language or languages of the intended audience Missing
        • transfer-encoding The form of encoding used Missing
        • content-length The length of the response body [20784]
        • content-type The Media type of the Response Body [text/html; charset=UTF-8]
        • date The date and time of generation [Sat, 30 Mar 2019 20:59:00 GMT]
        • content-disposition An opportunity to raise a File Download dialogue box Missing
        • content-encoding The type of encoding/compression used on the Response Missing
        • content-location An alternate location for the returned data Missing
        • content-range Where in a full body message this partial message belongs Missing
        • etag An identifier for a specific version of a resource ["5130-5854a2723024c"]
        • vary how to match future request headers Missing
        • x-content-type-options Types in Content-Type should NOT be changed [nosniff]

        Cache

        • cache-control Tells caches whether they may cache this object Missing
        • expires Gives the date/time after which the response is considered stale Missing
        • last-modified The last modified date for the requested object [Sat, 30 Mar 2019 06:46:54 GMT]
        • pragma Implementation-specific fields for caching Missing
        • x-cache-action From an Intermediate cache Missing
        • x-cache-hits Intermediate Cache Hits count Missing
        • x-cache-age Intermediate Cache Content Age Missing
        • via Informs the client of proxies through which the response was sent Missing
        • age The Age this page has been cached in a proxy Missing

        Strict Transport Security (HSTS) Policy

        • strict-transport-security A HSTS Policy for the client with scope [max-age=31536000]

        Cookies and Fragments

        • set-cookie Cookie Data to store locally Missing

        Other

        • x-backend-server Identifies the backend server providing this response Missing
        • x-robots-tag Search engine Robot Directive Missing
        • gen= Used by some of the GEN Tools to verify zone ownership Missing
        • cf-cache-status Cloudflare Specific Header indicating cache status for this response Missing

      Robots.txt

      • You have a robots.txt file and it appears to be valid
        • Allow Entries (0) - Specific Allow
          • Disallow Entries (11) - Specific Disallow
            • /scripts/
            • /themes/
            • /docs/2/
            • /docs/3/
            • /docs/4/
            • /forums/posting.php
            • /forums/search.php
            • /forums/app.php
            • /forums/ucp.php
            • /forums/memberlist.php
            • /forums/report.php
          • Sitemap Entries (1) - Sitemaps
            • http://www.centos.org/sitemap.xml
          • Other Entries (2)

      Processing Website Profile Data

        Website Render for www.centos.org

        Technology Profile centos.org

        We will check for fingerprints of common website technologies

          • Failed to succesfully profile the website, it is likely either custom or plain HTML.

        Meta Profile https://www.centos.org/

        We will check the entire body for metadata

        • viewport : width=device-width, initial-scale=1.0
        • description :
        • author :

      Processing Completed

      • Performance Profile
        • DNS Lookups : 0.48 seconds
        • DNS Folding/Unfolding : 0.00 seconds
        • DNS Nameserver Checks : 0.00 seconds
        • DNS TXT Records : 0.00 seconds
        • DNS MX Records : 0.10 seconds
        • DNS CNAME : 0.00 seconds
        • DNS Address : 0.32 seconds
        • WHOIS Lookups : 0.57 seconds
        • First CURL : 0.07 seconds
        • Second CURL : 0.21 seconds
        • SSL Lookup : 0.17 seconds
        • Header Parsing : 0.00 seconds
        • Robots.txt Parsing : 0.08 seconds
        • Website Profile : 0.56 seconds
        • Website META : 0.10 seconds

      The process is now completed and the results are shown above. Please take a moment to consider each test and its response. DNS, SMTP and HTTP are not simple protocols and it is way beyond the scope of this tool to suggest improvements, but you are welcome to request assistance via our Forum.