DNS & HTTP Analysis for candoinsurance.co.uk

Processing Domain candoinsurance.co.uk on 27/04/2020 12:23:31


  • This tool is available free to use at GENSupport
  • Help and Support for your DNS or HTTP issues available on our Forum
  • Whenever you see a clicking on it will take you to more help
  • The version of the data model that was used in this report is 1.008
  • The version that produced this report is 1.023b

Processing DNS Records

Basic Checks

Here we check the basic functioning and security of your DNS

  • Zone Queries 5 Record Types and 9 Records Found
  • Zone Transfer Failed
  • Zone Dump
    • A
      • candoinsurance.co.uk. TTL 86400 178.238.139.203
      • ns0.ukfast.net. TTL 300 185.226.220.128
      • ns1.ukfast.net. TTL 300 185.226.221.128
    • MX
      • candoinsurance.co.uk. TTL 86400 10 mx1.candoinsurance.co.uk.
    • NS
      • candoinsurance.co.uk. TTL 86400 ns0.ukfast.net.
      • candoinsurance.co.uk. TTL 86400 ns1.ukfast.net.
    • SOA
      • candoinsurance.co.uk. TTL 86400 ns0.ukfast.net. support.ukfast.co.uk. 2020021101 7200 3600 604800 86400
    • TXT
      • candoinsurance.co.uk. TTL 86400 "google-site-verification=sAvX7B4cIaUVzWBQPf7nmxxCst7EWAmwZJERjA2zkig"
      • candoinsurance.co.uk. TTL 86400 "v=spf1 mx a ~all"

Nameservers

Here we check the setup of your nameservers. All nameservers on your domain should be listed in the zone and returned in an ANY query along with corresponding A and/or AAAA records resolving their address.

  • ns1.ukfast.net 185.226.221.128 Found and Match. (Found in Address Records)
  • ns0.ukfast.net 185.226.220.128 Found and Match. (Found in Address Records)
  • All Name Servers on Different Subnets

Processing 2 TXT Records

Google Domain Verification Record

This record is used by Google to validate domain ownership when setting up Google Analytics etc

  • google-site-verification=savx7b4ciauvzwbqpf7nmxxcst7ewamwzjerja2zkig

SPF Record:

The SPF Record defines which IP addresses are permitted to send email on this domain's behalf

  • v=spf1 (The SPF Format Version Number)
  • mx (Permit servers listed in MX records -extra lookup, some server's won't bother)
  • a (Permit servers listed in A records -extra lookup, some server's won't bother)
  • ~all (Permit other hosts but take note)

Processing 1 MX (Mail Exchanger) Records

These Records determine the servers (mail servers) responsible for handling your incomming email. Each service is given a priority and they will be used in that order. If all the priorities are the same then they will be used in a round-robin fashion

  • Priority 10 handled by host mx1.candoinsurance.co.uk. [178.238.139.203] Valid
    • Email Handled Third Party
    • Port 25 (smtp) : Open

Processing 0 CNAME (Alias) Records

These records are aliases making one hostname relate to another. These are often used to match hosts back to clusters or internal referencs that may change.

    Processing 3 A (IPv4 Address) Records

    These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain. The www record is the most common one and will be used to identify your website address

    • Host: candoinsurance.co.uk. = IP: [178.238.139.203] Valid Unreachable TX:1 RX:0 LOSS:100%
    • Host: ns0.ukfast.net. = IP: [185.226.220.128] Valid Reachable (8.944ms)
    • Host: ns1.ukfast.net. = IP: [185.226.221.128] Valid Reachable (8.612ms)

    Processing AAAA (IPv6 Address) Records

    These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain

      Processing Domain Public Records

      • We have been unable to find the website IP from the zone
      • Performed an additional out-of-zone lookup to find website host [178.238.139.203]
      • Domain Name WHOIS Information - candoinsurance.co.uk

        • Domain name
        • candoinsurance.co.uk
        • Data validation
        • Nominet was able to match the registrant's name and address against a 3rd party data source on 20-Apr-2018
        • Registrar
        • GoDaddy.com, LLC. [Tag = GODADDY]
        • URL: http://uk.godaddy.com
        • Relevant dates
        • Registered on 20-Apr-2018
        • Expiry date 20-Apr-2022
        • Last updated 20-Apr-2020
        • Registration status
        • Registered until expiry date.
        • Name servers
        • ns0.ukfast.net
        • ns1.ukfast.net
        • WHOIS lookup made at 13:19:02 27-Apr-2020

        Website Hosting WHOIS Information - 178.238.139.203

        • NetRange 178.0.0.0 - 178.255.255.255
        • CIDR 178.0.0.0/8
        • NetHandle NET-178-0-0-0-1
        • Parent ()
        • NetType Allocated to RIPE NCC
        • OriginAS
        • Organization RIPE Network Coordination Centre (RIPE)
        • RegDate 2009-01-30
        • Updated 2009-05-18
        • Ref: https://rdap.arin.net/registry/ip/178.0.0.0
        • ResourceLink: https://apps.db.ripe.net/search/query.html
        • ResourceLink whois.ripe.net
        • OrgName RIPE Network Coordination Centre
        • OrgId RIPE
        • Address P.O. Box 10096
        • City Amsterdam
        • StateProv
        • PostalCode 1001EB
        • Country NL
        • RegDate
        • Updated 2013-07-29
        • Ref: https://rdap.arin.net/registry/entity/RIPE
        • ReferralServer: whois://whois.ripe.net
        • ResourceLink: https://apps.db.ripe.net/search/query.html
        • OrgTechHandle RNO29-ARIN
        • OrgTechName RIPE NCC Operations
        • OrgTechPhone +31 20 535 4444
        • OrgTechEmail hostmaster@ripe.net
        • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
        • OrgAbuseHandle ABUSE3850-ARIN
        • OrgAbuseName Abuse Contact
        • OrgAbusePhone +31205354444
        • OrgAbuseEmail abuse@ripe.net
        • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
        • inetnum 178.238.139.0 - 178.238.139.255
        • country GB
        • admin-c NL202-RIPE
        • tech-c NL202-RIPE
        • status ASSIGNED PA
        • mnt-by UKFAST-MNT
        • mnt-lower UKFAST-MNT
        • mnt-routes UKFAST-MNT
        • created: 2014-05-06T20:48:08Z
        • last-modified: 2014-05-06T20:48:08Z
        • source RIPE
        • person Neil Lathwood
        • address UKFast Campus
        • address Manchester
        • address M15 5QJ
        • mnt-by UKFAST-MNT
        • phone +44 845 458 4545
        • fax-no +44 870 458 4545
        • nic-hdl NL202-RIPE
        • created: 2002-08-23T13:58:36Z
        • last-modified: 2017-11-21T10:34:21Z
        • route 178.238.128.0/20
        • origin AS61323
        • mnt-by UKFAST-MNT
        • created: 2019-06-20T10:40:21Z
        • last-modified: 2019-06-20T10:40:21Z
        • source RIPE

      Processing Website

        Website Headers for www.candoinsurance.co.uk

        We will obtain the headers from your website and parse them for validity

        • Web Server is nginx
        • Server header does not contain version information
        • Request Response HTTP/1.1 301 Moved Permanently Moved Permanently
        • SSL is available and enabled
          • /CN=candoinsurance.co.uk
          • Locality
          • Organisation
          • Certificate Scope candoinsurance.co.uk
          Certificate Issuer
          • Country US
          • Organisation Let's Encrypt
          • Certificate Scope Let's Encrypt Authority X3
          Certificate Validity
          • Valid From 200313120024Z
          • Valid To 200611120024Z
          Certificate Ciphers
          • SN RSA-SHA256
          • LN sha256WithRSAEncryption
          Certificate Extensions
          • Alternative Hostnames DNS:candoinsurance.co.uk, DNS:webmail.candoinsurance.co.uk, DNS:www.candoinsurance.co.uk
          • Key Usage TLS Web Server Authentication, TLS Web Client Authentication
      • There was a redirect to http://candoinsurance.co.uk/
      • There was a SECOND redirect https://candoinsurance.co.uk/
      • General

        • allow Valid methods for a specified resource after a 405 : Missing
        • location For Redirects specifies the target [https://candoinsurance.co.uk/]
        • connection Control options for the current connection [keep-alive]
        • x-powered-by Specifies Technology in use - Security Risk [PleskLin]
        • x-aspnet-version Specifies the ASP.net version - Security Risk : Missing
        • accept-ranges To advertise its support of partial requests : Missing
        • link Used to express typed relationship with another resource : Missing
        • upgrade HTTP/2 (The latest and faster version of HTTP is available : Missing

        Security

        • referrer-policy Modifies the algorithm used to populate the Referer Header : Missing
        • x-xss-protection Prevents pages loading when XSS is detected : Missing
        • feature-policy Allow or Deny the use of browser features : Missing
        • p3p Platform for Privacy Preferences : Missing
        • content-security-policy CSP Content Security Policy : Missing
        • x-frame-options Can we open this response in an iframe : Missing

        Cross Origin

        • access-control-allow-origin Can we share the response with the given origin : Missing
        • access-control-allow-credentials Tells Browsers whether to expose the response to frontend JavaScript : Missing
        • access-control-expose-headers Indicates which headers can be exposed as part of the Response : Missing
        • access-control-max-age Indicates how long the results of a preflight request can be stored : Missing
        • access-control-allow-methods Methods allowed when accessing the resource in response to a preflight request : Missing
        • access-control-allow-headers Indicates which headers can be used during the actual request : Missing

        Content

        • content-language The natural language or languages of the intended audience : Missing
        • transfer-encoding The form of encoding used : Missing
        • content-length The length of the response body : Missing
        • content-type The Media type of the Response Body [text/html; charset=utf-8]
        • date The date and time of generation [Mon, 27 Apr 2020 12:19:03 GMT]
        • content-disposition An opportunity to raise a File Download dialogue box : Missing
        • content-encoding The type of encoding/compression used on the Response : Missing
        • content-location An alternate location for the returned data : Missing
        • content-range Where in a full body message this partial message belongs : Missing
        • etag An identifier for a specific version of a resource : Missing
        • vary how to match future request headers : Missing
        • x-content-type-options Types in Content-Type should NOT be changed [nosniff]

        Cache

        • cache-control Tells caches whether they may cache this object [no-store, no-cache, must-revalidate, post-check=0, pre-check=0]
        • expires Gives the date/time after which the response is considered stale [Wed, 17 Aug 2005 00:00:00 GMT]
        • last-modified The last modified date for the requested object [Mon, 27 Apr 2020 12:19:03 GMT]
        • pragma Implementation-specific fields for caching [no-cache]
        • x-cache-action From an Intermediate cache : Missing
        • x-cache-hits Intermediate Cache Hits count : Missing
        • x-cache-age Intermediate Cache Content Age : Missing
        • via Informs the client of proxies through which the response was sent : Missing
        • age The Age this page has been cached in a proxy : Missing
        • x-served-by The Cache that served this response : Missing
        • x-cache Indicates if the cache served cached content : Missing
        • x-via-fastly Specific headers from Fastly : Missing

        Strict Transport Security (HSTS) Policy

        • strict-transport-security A HSTS Policy for the client with scope : Missing

        Cookies and Fragments

        • set-cookie Cookie Data to store locally [e3939b550fbc36c44e883da48bf7c41b=8asg45iitvtinr744fo74q18ad; path=/; secure; HttpOnly]

        Other

        • x-backend-server Identifies the backend server providing this response : Missing
        • x-robots-tag Search engine Robot Directive : Missing
        • gen Used by some of the GEN Tools to verify zone ownership : Missing
        • cf-cache-status Cloudflare Specific Header indicating cache status for this response : Missing
        • x-aspnetmvc-version ASP MVC Version Number - Security Risk : Missing

      Robots.txt

      • You have a robots.txt file and it appears to be valid
        • Allow Entries (5) - Specific Allow
          • Disallow Entries (11) - Specific Disallow
            • Sitemap Entries (1) - Sitemaps
              • https://candoinsurance.co.uk/index.php?option=com_jmap&view=sitemap&format=xml
            • Other Entries (6)

          Processing Website Profile Data

            Website Render for www.candoinsurance.co.uk

            Technology Profile candoinsurance.co.uk

            We will check for fingerprints of common website technologies

              • Name : Joomla
              • Confidence : high
              • Version : 3.9.16

            MOZ Rank Profile http://candoinsurance.co.uk/

            We will retrieve your Ranking Profile from Moz.com

            • 0 The number of external, equity links
            • 3 The number of internal and external equity and non-equity links
            • 1 The Domain Authority (DA) ( 0->100 )
            • 6 The Page Authority (PA) ( 0->100 )
            • 0.6000000238 The MozRank of the Domain ( 0->10 )

            Google Safe Browsing http://candoinsurance.co.uk/

            We will retrieve Safe Browsing Status from Google

            • This site is NOT listed as being unsafe by Google

            PhishTank Lookup http://candoinsurance.co.uk/

            We will check PhishTank to see if your site is listed

            • This site is NOT listed as being unsafe by PhishTank

            Alexa Rank Profile http://candoinsurance.co.uk/

            We will retrieve your Ranking Profile from Alexa.com

            • The number of external in links
            • Un-Ranked Your Alexa Rank

            Meta Profile http://candoinsurance.co.uk/

            We will check the entire body for metadata

            • viewport : width=device-width, initial-scale=1.0
            • keywords : insurance,cando,cando insurance,buildings insurance,contents insurance,buildings and contents insurance,tenants contents insurance
            • description : CanDo Insurance Services take the best products available in the Insurance market place and present them in a simple and easy to use online format.
            • generator : Joomla! - Open Source Content Management
            • msapplication-tilecolor : #2b5797
            • theme-color : #ffffff

          Processing Completed

          • Performance Profile
            • DNS Lookups : 0.21 seconds
            • DNS Folding/Unfolding : 0.00 seconds
            • DNS Nameserver Checks : 0.00 seconds
            • DNS TXT Records : 0.00 seconds
            • DNS MX Records : 0.07 seconds
            • DNS CNAME : 0.00 seconds
            • DNS Address : 10.05 seconds
            • WHOIS Lookups : 0.47 seconds
            • First CURL : 0.22 seconds
            • Second CURL : 0.53 seconds
            • SSL Lookup : 1.59 seconds
            • Header Parsing : 0.00 seconds
            • Robots.txt Parsing : 0.27 seconds
            • Website Profile : 7.01 seconds
            • Website MozData : 0.31 seconds
            • Safe Browsing : 0.25 seconds
            • PhishTank : 0.06 seconds
            • Website Alexa : 0.48 seconds
            • Website META : 1.08 seconds

          The process is now completed and the results are shown above. The raw processing data is available HERE. Please take a moment to consider each test and its response. DNS, SMTP and HTTP are not simple protocols and it is way beyond the scope of this tool to suggest improvements, but you are welcome to request assistance via our Forum.