DNS & HTTP Analysis for microsoft.com
- Details
- Category: Tool Processing Reports
Processing Domain microsoft.com on 10/06/2019 05:08:42
- This tool is available free to use at GENSupport
- Help and Support for your DNS or HTTP issues available on our Forum
- Whenever you see a clicking on it will take you to more help
- The version of the data model that was used in this report is 1.008
- The version that produced this report is 1.022b
Processing DNS Records
Basic Checks
Here we check the basic functioning and security of your DNS
- Zone Queries 7 Record Types and 34 Records Found
- Zone Transfer Failed
- Zone Dump
- TXT
- _dmarc.microsoft.com. TTL 3600 "v=DMARC1; p=reject; pct=100; rua=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it.; ruf=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it.; fo=1"
- microsoft.com. TTL 3600 "FbUF6DbkE+Aw1/wi9xgDi8KVrIIZus5v8L6tbIQZkGrQ/rVQKJi8CjQbBtWtE64ey4NJJwj5J65PIggVYNabdQ=="
- microsoft.com. TTL 3600 "adobe-idp-site-verification=8aa35c528af5d72beb19b1bd3ed9b86d87ea7f24b2ba3c99ffcd00c27e9d809c"
- microsoft.com. TTL 3600 "adobe-sign-verification=c1fea9b4cdd4df0d5778517f29e0934"
- microsoft.com. TTL 3600 "atlassian-domain-verification=jbey7I2+3Wyl+PZ0QUCC6fCz2Gu5KO7GQPcy/0c4za7ebQxar/qqujJH4kZLVQHZ"
- microsoft.com. TTL 3600 "docusign=52998482-393d-46f7-95d4-15ac6509bfdd"
- microsoft.com. TTL 3600 "docusign=d5a3737c-c23c-4bd0-9095-d2ff621f2840"
- microsoft.com. TTL 3600 "facebook-domain-verification=bcas5uzlvu0s3mrw139a00os3o66wr"
- microsoft.com. TTL 3600 "facebook-domain-verification=gx5s19fp3o8aczby6a22clfhzm03as"
- microsoft.com. TTL 3600 "facebook-domain-verification=m54hfzczreqq2z1pf99y2p0kpwwpkv"
- microsoft.com. TTL 3600 "google-site-verification=6P08Ow5E-8Q0m6vQ7FMAqAYIDprkVV8fUf_7hZ4Qvc8"
- microsoft.com. TTL 3600 "google-site-verification=8-zFCaUXhhPcvN29EVw2RvtASDCaDPQ02L1HJ8Om8I0"
- microsoft.com. TTL 3600 "google-site-verification=yUE_SrjKKb4FHH1H04VWidfwstTGeS1FLx3Mcsnijjs"
- microsoft.com. TTL 3600 "v=spf1 include:_spf-a.microsoft.com include:_spf-b.microsoft.com include:_spf-c.microsoft.com include:_spf-ssg-a.microsoft.com include:spf-a.hotmail.com ip4:147.243.128.24 ip4:147.243.128.26 ip4:147.243.1.153 ip4:147.243.1.47 ip4:147.243.1.48 -all"
- NS
- microsoft.com. TTL 172800 ns1.msft.net.
- microsoft.com. TTL 172800 ns2.msft.net.
- microsoft.com. TTL 172800 ns3.msft.net.
- microsoft.com. TTL 172800 ns4.msft.net.
- A
- microsoft.com. TTL 3600 104.215.148.63
- microsoft.com. TTL 3600 13.77.161.179
- microsoft.com. TTL 3600 40.112.72.205
- microsoft.com. TTL 3600 40.113.200.201
- microsoft.com. TTL 3600 40.76.4.15
- ns1.msft.net. TTL 300 208.84.0.53
- ns2.msft.net. TTL 172800 208.84.2.53
- ns3.msft.net. TTL 300 193.221.113.53
- ns4.msft.net. TTL 172800 208.76.45.53
- MX
- microsoft.com. TTL 3600 10 microsoft-com.mail.protection.outlook.com.
- SOA
- microsoft.com. TTL 3600 ns1.msft.net. msnhst.microsoft.com. 2019060902 7200 600 2419200 3600
- AAAA
- ns1.msft.net. TTL 300 2620:0:30:0:0:0:0:53
- ns2.msft.net. TTL 172800 2620:0:32:0:0:0:0:53
- ns3.msft.net. TTL 300 2620:0:34:0:0:0:0:53
- ns4.msft.net. TTL 172800 2620:0:37:0:0:0:0:53
- CNAME
- www.microsoft.com. TTL 3600 www.microsoft.com-c-3.edgekey.net.
Nameservers
Here we check the setup of your nameservers. All nameservers on your domain should be listed in the zone and returned in an ANY query along with corresponding A and/or AAAA records resolving their address.
- ns1.msft.net 208.84.0.53 Found and Match. (Found in Address Records)
- ns2.msft.net 208.84.2.53 Found and Match. (Found in Address Records)
- ns3.msft.net 193.221.113.53 Found and Match. (Found in Address Records)
- ns4.msft.net 208.76.45.53 Found and Match. (Found in Address Records)
- All Name Servers on Different Subnets
Processing 14 TXT Records
DMARC Record:
The DMARC Record defines how MTA's should response when parsing DKIM and SPF records
- v=dmarc1 (The Version of this record)
- p=reject (The Policy to implement on FAIL)
- pct=100 (The Percentage of Messages subject to filtering)
- rua=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it. (Reporting URI of aggregate reports)
- ruf=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it. (Reporting URI for forensic reports)
- fo=1 (Dictates what type of authentication/alignment vulnerabilities are reported)
Unknown Record:
We cannot identify this record. If you know what it is and its no longer needed then remove it
- fbuf6dbke+aw1/wi9xgdi8kvriizus5v8l6tbiqzkgrq/rvqkji8cjqbbtwte64ey4njjwj5j65piggvynabdq==
Adobe Enterprise products and services Verification Record
Some Adobe Products allow enterprise user accounts to be linked to a domain name and this record provides verification of ownership
- adobe-idp-site-verification=8aa35c528af5d72beb19b1bd3ed9b86d87ea7f24b2ba3c99ffcd00c27e9d809c
Adobe PDF Signing Verification Record
Adobe Sign allows cloud based signatures
- adobe-sign-verification=c1fea9b4cdd4df0d5778517f29e0934
Atlassian Cloud Verification Record
This record verifies the domain with Atlassian Cloud
- atlassian-domain-verification=jbey7i2+3wyl+pz0qucc6fcz2gu5ko7gqpcy/0c4za7ebqxar/qqujjh4kzlvqhz
Docusign Record
Docusign is a company offering document signing services but since a data breach and other security concerns this is rarely used today and you should consider removing it
- docusign=52998482-393d-46f7-95d4-15ac6509bfdd
Docusign Record
Docusign is a company offering document signing services but since a data breach and other security concerns this is rarely used today and you should consider removing it
- docusign=d5a3737c-c23c-4bd0-9095-d2ff621f2840
Facebook Domain Verification Record
This record is used by Facebook to validate domain ownership when creating company pages
- facebook-domain-verification=bcas5uzlvu0s3mrw139a00os3o66wr
Facebook Domain Verification Record
This record is used by Facebook to validate domain ownership when creating company pages
- facebook-domain-verification=gx5s19fp3o8aczby6a22clfhzm03as
Facebook Domain Verification Record
This record is used by Facebook to validate domain ownership when creating company pages
- facebook-domain-verification=m54hfzczreqq2z1pf99y2p0kpwwpkv
Google Domain Verification Record
This record is used by Google to validate domain ownership when setting up Google Analytics etc
- google-site-verification=6p08ow5e-8q0m6vq7fmaqayidprkvv8fuf_7hz4qvc8
Google Domain Verification Record
This record is used by Google to validate domain ownership when setting up Google Analytics etc
- google-site-verification=8-zfcauxhhpcvn29evw2rvtasdcadpq02l1hj8om8i0
Google Domain Verification Record
This record is used by Google to validate domain ownership when setting up Google Analytics etc
- google-site-verification=yue_srjkkb4fhh1h04vwidfwsttges1flx3mcsnijjs
SPF Record:
The SPF Record defines which IP addresses are permitted to send email on this domain's behalf
- v=spf1 (The SPF Format Version Number)
- include:_spf-a.microsoft.com (An Include - Additional look-ups required, some server's won't bother.)
- include:_spf-b.microsoft.com (An Include - Additional look-ups required, some server's won't bother.)
- include:_spf-c.microsoft.com (An Include - Additional look-ups required, some server's won't bother.)
- include:_spf-ssg-a.microsoft.com (An Include - Additional look-ups required, some server's won't bother.)
- include:spf-a.hotmail.com (An Include - Additional look-ups required, some server's won't bother.)
- ip4:147.243.128.24 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
- ip4:147.243.128.26 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
- ip4:147.243.1.153 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
- ip4:147.243.1.47 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
- ip4:147.243.1.48 (The IPv4 Address of a permitted sender - make sure this scopes your outgoing mail server)
- -all (Permit ONLY the hosts listed)
Processing 1 MX (Mail Exchanger) Records
These Records determine the servers (mail servers) responsible for handling your incomming email. Each service is given a priority and they will be used in that order. If all the priorities are the same then they will be used in a round-robin fashion
- Priority 10 handled by host microsoft-com.mail.protection.outlook.com. [104.47.54.36] Valid
- Email Handled By Microsoft Corporation
- Port 25 (smtp) : Open
- Attempting to Send Email to Postmaster:
-> Connecting to microsoft-com.mail.protection.outlook.com. Connected <- Code [250]:DM3NAM06FT005.mail.protection.outlook.com Hello [81.174.253.181] SIZE 157286400 PIPELINING DSN ENHANCEDSTATUSCODES STARTTLS 8BITMIME BINARYMIME CHUNKING SMTPUTF8 -> MAIL FROM: This email address is being protected from spambots. You need JavaScript enabled to view it. <- Code [250]:2.1.0 Sender OK -> RCPT TO: This email address is being protected from spambots. You need JavaScript enabled to view it. <- Code [250]:2.1.5 Recipient OK -> Sending Test Message <- Code [250]:2.6.0 <6602e909-3318-4ef9-b9cb-a6c6337b0dde@DM3NAM06FT005.Eop-nam06.prod.protection.outlook.com> [InternalId=7065221202068, Hostname=DM6PR21MB1179.namprd21.prod.outlook.com] 8845 bytes in 0.182, 47.419 KB/sec Queued mail for delivery
Processing 1 CNAME (Alias) Records
These records are aliases making one hostname relate to another. These are often used to match hosts back to clusters or internal referencs that may change.
- www.microsoft.com. www.microsoft.com-c-3.edgekey.net.
Processing 9 A (IPv4 Address) Records
These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain. The www record is the most common one and will be used to identify your website address
- Host: microsoft.com. = IP: [104.215.148.63] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: microsoft.com. = IP: [13.77.161.179] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: microsoft.com. = IP: [40.112.72.205] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: microsoft.com. = IP: [40.113.200.201] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: microsoft.com. = IP: [40.76.4.15] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: ns1.msft.net. = IP: [208.84.0.53] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: ns2.msft.net. = IP: [208.84.2.53] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: ns3.msft.net. = IP: [193.221.113.53] Valid Unreachable TX:1 RX:0 LOSS:100%
- Host: ns4.msft.net. = IP: [208.76.45.53] Valid Unreachable TX:1 RX:0 LOSS:100%
Processing AAAA (IPv6 Address) Records
These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain
- Host: ns1.msft.net. = IP: [2620:0:30:0:0:0:0:53] Valid
- Host: ns2.msft.net. = IP: [2620:0:32:0:0:0:0:53] Valid
- Host: ns3.msft.net. = IP: [2620:0:34:0:0:0:0:53] Valid
- Host: ns4.msft.net. = IP: [2620:0:37:0:0:0:0:53] Valid
Processing Domain Public Records
Domain Name WHOIS Information - microsoft.com
- Domain Name MICROSOFT.COM
- Registry Domain ID 2724960_DOMAIN_COM-VRSN
- Registrar WHOIS Server whois.markmonitor.com
- Registrar URL: http://www.markmonitor.com
- Updated Date: 2014-10-09T16:28:25Z
- Creation Date: 1991-05-02T04:00:00Z
- Registry Expiry Date: 2021-05-03T04:00:00Z
- Registrar MarkMonitor Inc.
- Registrar IANA ID 292
- Registrar Abuse Contact Email This email address is being protected from spambots. You need JavaScript enabled to view it.
- Registrar Abuse Contact Phone +1.2083895740
- Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
- Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
- Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
- Domain Status: serverDeleteProhibited https://icann.org/epp#serverDeleteProhibited
- Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
- Domain Status: serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
- Name Server NS1.MSFT.NET
- Name Server NS2.MSFT.NET
- Name Server NS3.MSFT.NET
- Name Server NS4.MSFT.NET
- DNSSEC unsigned
- URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
Website Hosting WHOIS Information - 104.215.148.63
- NetRange 104.208.0.0 - 104.215.255.255
- CIDR 104.208.0.0/13
- NetHandle NET-104-208-0-0-1
- Parent NET104 (NET-104-0-0-0-0)
- NetType Direct Assignment
- OriginAS AS8075
- Organization Microsoft Corporation (MSFT)
- RegDate 2014-10-01
- Updated 2014-10-01
- Ref: https://rdap.arin.net/registry/ip/104.208.0.0
- OrgName Microsoft Corporation
- OrgId MSFT
- Address One Microsoft Way
- City Redmond
- StateProv WA
- PostalCode 98052
- Country US
- RegDate 1998-07-09
- Updated 2017-01-28
- Ref: https://rdap.arin.net/registry/entity/MSFT
- OrgTechHandle MRPD-ARIN
- OrgTechName Microsoft Routing, Peering, and DNS
- OrgTechPhone +1-425-882-8080
- OrgTechEmail IOC@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN
- OrgAbuseHandle MAC74-ARIN
- OrgAbuseName Microsoft Abuse Contact
- OrgAbusePhone +1-425-882-8080
- OrgAbuseEmail abuse@microsoft.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN
Processing Website
Website Headers for www.microsoft.com
We will obtain the headers from your website and parse them for validity
- Web Server Header is Missing
- Request Response HTTP/1.1 200 OK OK
- SSL is available and enabled
/C=US/ST=WA/L=Redmond/O=Microsoft Corporation/OU=Microsoft Corporation/CN=www.microsoft.comUSWA
- Locality Redmond
- Organisation Microsoft Corporation
- Certificate Scope www.microsoft.com
Certificate Issuer
- Country US
- Organisation Microsoft Corporation
- Certificate Scope Microsoft IT TLS CA 4
Certificate Validity
- Valid From 180116212402Z
- Valid To 200116212402Z
Certificate Ciphers
- SN RSA-SHA256
- LN sha256WithRSAEncryption
Certificate Extensions
- Alternative Hostnames DNS:privacy.microsoft.com, DNS:c.s-microsoft.com, DNS:microsoft.com, DNS:i.s-microsoft.com, DNS:staticview.microsoft.com, DNS:www.microsoft.com, DNS:wwwqa.microsoft.com
- Key Usage TLS Web Client Authentication, TLS Web Server Authentication
- There was a redirect to https://www.microsoft.com/en-gb/
General
- allow Valid methods for a specified resource after a 405 : Missing
- location For Redirects specifies the target : Missing
- connection Control options for the current connection [keep-alive]
- x-powered-by Specifies Technology in use - Security Risk : Missing
- x-aspnet-version Specifies the ASP.net version - Security Risk : Missing
- accept-ranges To advertise its support of partial requests : Missing
- link Used to express typed relationship with another resource : Missing
- upgrade HTTP/2 (The latest and faster version of HTTP is available : Missing
Security
- referrer-policy Modifies the algorithm used to populate the Referer Header : Missing
- x-xss-protection Prevents pages loading when XSS is detected [1]
- feature-policy Allow or Deny the use of browser features : Missing
- p3p Platform for Privacy Preferences [CP="NON DSP ADM DEV PSD OUR IND STP PHY PRE NAV UNI"]
- content-security-policy CSP Content Security Policy : Missing
- x-frame-options Can we open this response in an iframe [SAMEORIGIN]
Cross Origin
- access-control-allow-origin Can we share the response with the given origin : Missing
- access-control-allow-credentials Tells Browsers whether to expose the response to frontend JavaScript : Missing
- access-control-expose-headers Indicates which headers can be exposed as part of the Response : Missing
- access-control-max-age Indicates how long the results of a preflight request can be stored : Missing
- access-control-allow-methods Methods allowed when accessing the resource in response to a preflight request [HEAD,GET,POST,PATCH,PUT,OPTIONS]
- access-control-allow-headers Indicates which headers can be used during the actual request : Missing
Content
- content-language The natural language or languages of the intended audience : Missing
- transfer-encoding The form of encoding used : Missing
- content-length The length of the response body : Missing
- content-type The Media type of the Response Body [text/html; charset=utf-8]
- date The date and time of generation [Mon, 10 Jun 2019 05:06:26 GMT]
- content-disposition An opportunity to raise a File Download dialogue box : Missing
- content-encoding The type of encoding/compression used on the Response : Missing
- content-location An alternate location for the returned data : Missing
- content-range Where in a full body message this partial message belongs : Missing
- etag An identifier for a specific version of a resource : Missing
- vary how to match future request headers : Missing
- x-content-type-options Types in Content-Type should NOT be changed [nosniff]
Cache
- cache-control Tells caches whether they may cache this object [no-cache, no-store, no-transform]
- expires Gives the date/time after which the response is considered stale [-1]
- last-modified The last modified date for the requested object : Missing
- pragma Implementation-specific fields for caching [no-cache]
- x-cache-action From an Intermediate cache : Missing
- x-cache-hits Intermediate Cache Hits count : Missing
- x-cache-age Intermediate Cache Content Age : Missing
- via Informs the client of proxies through which the response was sent : Missing
- age The Age this page has been cached in a proxy : Missing
- x-served-by The Cache that served this response : Missing
- x-cache Indicates if the cache served cached content : Missing
- x-via-fastly Specific headers from Fastly : Missing
Strict Transport Security (HSTS) Policy
Cookies and Fragments
- set-cookie Cookie Data to store locally [akacd_OneRF=1567919186~rv=14~id=7a9d248a8a07d5bf3d64134f037f13ce; path=/; Expires=Sun, 08 Sep 2019 05:06:26 GMT]
Other
- x-backend-server Identifies the backend server providing this response : Missing
- x-robots-tag Search engine Robot Directive : Missing
- gen Used by some of the GEN Tools to verify zone ownership : Missing
- cf-cache-status Cloudflare Specific Header indicating cache status for this response : Missing
- x-aspnetmvc-version ASP MVC Version Number - Security Risk : Missing
Not Profiled
- x-ua-compatible [IE=Edge;chrome=1]
- x-activity-id [01943b72-759b-4f7f-a1be-8b2e183ff9d2]
- ms-cv [lgxJiEPaAkGAa0uo.0]
- x-appversion [1.0.7083.39717]
- x-az [{did:92e7dc58ca2143cfb2c818b047cc5cd1, rid]
- ms-operation-id [f966ac3fd0fd7f48834e8fb4dad62ca2]
- x-edgeconnect-midmile-rtt [9]
- x-edgeconnect-origin-mex-latency [56]
- tls_version [tls1.2]
- x-rtag [RT]
Robots.txt
- You have a robots.txt file and it appears to be valid
- Allow Entries (25) - Specific Allow
- Disallow Entries (85) - Specific Disallow
- Sitemap Entries (9) - Sitemaps
- https://www.microsoft.com/en-us/explore/msft_sitemap_index.xml
- https://www.microsoft.com/learning/sitemap.xml
- https://www.microsoft.com/en-us/licensing/sitemap.xml
- https://www.microsoft.com/en-us/legal/sitemap.xml
- https://www.microsoft.com/filedata/sitemaps/rw5xn8
- https://www.microsoft.com/store/collections.xml
- https://www.microsoft.com/store/productdetailpages.index.xml
- https://www.microsoft.com/store/sitemaps/custom-index.xml
- https://www.microsoft.com/en-us/store/locations/store-locations-sitemap.xml
- Other Entries (1)
Processing Website Profile Data
Website Render for www.microsoft.com
Technology Profile microsoft.com
We will check for fingerprints of common website technologies
- Failed to succesfully profile the website, it is likely either custom or plain HTML.
MOZ Rank Profile https://www.microsoft.com/en-gb/
We will retrieve your Ranking Profile from Moz.com
- 1104381 The number of external, equity links
- 1107863 The number of internal and external equity and non-equity links
- 99 The Domain Authority (DA) ( 0->100 )
- 73 The Page Authority (PA) ( 0->100 )
- 7.300000191 The MozRank of the Domain ( 0->10 )
Google Safe Browsing https://www.microsoft.com/en-gb/
We will retrieve Safe Browsing Status from Google
PhishTank Lookup https://www.microsoft.com/en-gb/
We will check PhishTank to see if your site is listed
Alexa Rank Profile https://www.microsoft.com/en-gb/
We will retrieve your Ranking Profile from Alexa.com
Meta Profile https://www.microsoft.com/en-gb/
We will check the entire body for metadata
- viewport : width=device-width, initial-scale=1
- twitter:url : https://www.microsoft.com/en-gb
- twitter:title : Microsoft - Official Home Page
- twitter:description : At Microsoft our mission and values are to help people and businesses throughout the world realize their full potential.
- twitter:card : summary
- description : At Microsoft our mission and values are to help people and businesses throughout the world realize their full potential.
Processing Completed
- Performance Profile
- DNS Lookups : 0.45 seconds
- DNS Folding/Unfolding : 0.00 seconds
- DNS Nameserver Checks : 0.00 seconds
- DNS TXT Records : 0.00 seconds
- DNS MX Records : 2.46 seconds
- DNS CNAME : 0.00 seconds
- DNS Address : 90.09 seconds
- WHOIS Lookups : 0.39 seconds
- First CURL : 0.09 seconds
- Second CURL : 0.26 seconds
- SSL Lookup : 0.35 seconds
- Header Parsing : 0.00 seconds
- Robots.txt Parsing : 0.09 seconds
- Website Profile : 4.83 seconds
- Website MozData : 0.26 seconds
- Safe Browsing : 0.09 seconds
- PhishTank : 0.17 seconds
- Website Alexa : 0.86 seconds
- Website META : 0.20 seconds
The process is now completed and the results are shown above. The raw processing data is available HERE. Please take a moment to consider each test and its response. DNS, SMTP and HTTP are not simple protocols and it is way beyond the scope of this tool to suggest improvements, but you are welcome to request assistance via our Forum.