Initializing diagnostics...

⚡ Live Data: Report generated fresh from authoritative registries. 🔄 Force Refresh
🤖 AI Intelligence Summary

The domain gitlab.herzog-it.de is registered with an undisclosed registrar. It resolves to IP address patty.herzog-it.de.. Email delivery is handled by Self-hosted or Custom. No valid SPF record was detected. DMARC protection is missing or unconfigured. Web traffic is secured with an SSL certificate issued by Let's Encrypt Authority X3.

Domain Overview: gitlab.herzog-it.de

Domain Registration 🌐
Active N/A

Expires in N/A · DNSSEC: Unsigned

Email Security 🛡️
SPF: Missing DKIM: Not Detected DMARC: Missing

Self-hosted or Custom (1 MX)

SSL Certificate 🔒
Valid Chain -2776 Days Left

Issuer: Let's Encrypt Authority X3 (1 SANs)

Server & Hosting 🖥️
N/A N/A

N/A

🌐 Domain & Registration Identity View Full Whois Details →

Domaingitlab.herzog-it.de
Website TitleFavicon N/A
RegisteredN/A
ExpiresN/A
Remaining ValidityN/A
Domain AgeN/A
RegistrarN/A
Domain StatusN/A i
DNSSEC Delegation Unsigned · Zone not signed with DNSSEC keys i
Authoritative Nameservers patty.herzog-it.de i

🛡️ Email Security & Deliverability (SPF, DKIM, DMARC) View Complete Email Security Diagnostics →

Detected Email Provider 📬 Self-hosted or Custom
Primary Mail Server (MX) patty.herzog-it.de (Priority: patty.herzog-it.de.) · 1 MX server configured i
SPF Record (Sender Policy) Missing i
DKIM Authentication Not Detected · (No common third-party selector found; custom keys may be configured) i
DMARC Policy Missing i
SMTP Port 25 Status Failed · Inbound mail server handshake response

🖥️ Web Server, Hosting & Network View Full Server & Tech Details →

Web Server Software N/A i
HTTP Status Code N/A i
Server IP (IPv4) patty.herzog-it.de. View Geo Details →
IPv6 Address (AAAA) patty.herzog-it.de.
Reverse DNS (PTR) None Detected (No PTR Record)
Server Location 📍 N/A
ASN Network & ISP N/A
Hosting Provider N/A i
Control Panel Not Detected i
Technology Stack No third-party framework or CMS fingerprints detected
HTTP Security Headers None Detected (Missing HSTS / CSP) Audit Details →
DNSBL Blacklist Reputation Not Checked

🔒 SSL/TLS Certificate Summary View Full SSL Certificate & Chain →

Primary Hostname (CN) gitlab.herzog-it.de · Multi-Domain SAN (Covers 1 hostnames)
SSL IssuerLet's Encrypt Authority X3
SSL Valid Till2019-03-04
Remaining Validity-2776 Days
Chain Status Valid Trusted Chain
Signature AlgorithmRSA-SHA256

Whois Ownership & Registration for gitlab.herzog-it.de

📄 View Raw Registry Response ↓

Domain Information i

Registrar Information i

Registrant Contact i

Contact information for this role is not provided or redacted.

Administrative Contact i

Contact information for this role is not provided or redacted.

Technical Contact i

Contact information for this role is not provided or redacted.

📄 View Raw Registry Response Legacy Whois (Port 43)
Domain: herzog-it.de
Status: connect

DNS Records for gitlab.herzog-it.de

NS Records i

NameDataCopy
gitlab.herzog-it.de. patty.herzog-it.de.

A Records i

NameDataCopy
gitlab.herzog-it.de. patty.herzog-it.de.
patty.herzog-it.de. 91.250.112.170

AAAA Records i

NameDataCopy
gitlab.herzog-it.de. patty.herzog-it.de.

WWW Records (www.gitlab.herzog-it.de) i

No CNAME or A records found for the 'www' subdomain.

MX Records i

PriorityMail Server TargetCopy
patty.herzog-it.de.

TXT Records i

NameValueCopy
gitlab.herzog-it.de. patty.herzog-it.de.

Email Security (MX, SPF, DKIM, DMARC, SMTP) for gitlab.herzog-it.de

Detected Email Provider
📬 Self-hosted or Custom
✓ Active MX Routing (1 Server)

Mail Exchange (MX) Routing Records i

Priority Mail Server Hostname Copy
patty.herzog-it.de.

SPF Record Validation i

No SPF record found to validate.

Common DKIM Selectors i

No common third-party DKIM selectors found. Custom selectors may be configured.

🔍 Query Custom DKIM Selector

Live DNS Lookup

Using a custom or date-based selector (e.g. crm, newsletter, 2024)? Query its public key live on gitlab.herzog-it.de:

DMARC Policy Validation i

No DMARC record found to validate.

Validation Summary

DMARC Record Published Fail No DMARC record was found.

Optimization Suggestions

A DMARC record is essential for email security. It tells receiving servers what to do with emails that fail SPF and DKIM checks, protecting your domain from spoofing.

SMTP Connectivity Test (Port 25)

Mail ServerStatusLatencyBanner / Handshake Response
patty.herzog-it.de Failed 138ms Connection failed (111: Connection refused). Port 25 may be blocked.

SSL/TLS Certificate Details for gitlab.herzog-it.de

  • Issuer: Let's Encrypt Authority X3
  • Expires In: -2776 Days
  • Chain Status: Valid Chain

🔒 SSL / TLS Protocol Support

Warning
TLS protocol versions
TLS 1.3 Disabled
TLS 1.2 Enabled
TLS 1.1 (deprecated) Enabled
TLS 1.0 (deprecated) Enabled
SSL protocol versions
SSLv3 (deprecated) Disabled
SSLv2 (deprecated) Disabled

Main Leaf Certificate

  • Common Name: gitlab.herzog-it.de
  • SANs: DNS:gitlab.herzog-it.de
  • Organization: N/A
  • Validity: Dec 04, 2018 to Mar 04, 2019
  • Algorithm: RSA-SHA256
↓ Intermediate CA Certificate ↓
  • Common Name: Let's Encrypt Authority X3
  • Organization: Let's Encrypt
  • Valid Till: Mar 17, 2021
  • Issuer: DST Root CA X3

Website & Server Intelligence for gitlab.herzog-it.de

Website Identity

TitleFavicon N/A
Meta DescriptionN/A

Hosting & Server Network

IP Addresspatty.herzog-it.de.
HTTP StatusN/A i
Hosting ProviderN/A i
Web ServerN/A i
Control Panel Not Detected i

Technology Profile

No specific third-party frameworks or CMS fingerprints detected.

HTTP Security Headers

Could not fetch HTTP headers.

IP Details & Geolocation

Could not retrieve detailed IP information.

Understanding Diagnostic Terms for gitlab.herzog-it.de

Domain Status (EPP)

EPP status codes (e.g., clientTransferProhibited, active) indicating if a domain is locked against unauthorized transfer, pending renewal, or active.

Registrar Information

The authorized or accredited organization managing the domain reservation and authoritative registry delegation.

Nameservers (NS)

Authoritative servers that translate domain names into IP addresses and direct web visitors and mail traffic globally.

A & AAAA Records

Primary address records mapping your domain name directly to standard IPv4 (e.g., 192.0.2.1) and newer IPv6 server network addresses.

MX (Mail Exchange)

Priority-ranked records pointing inbound emails to designated mail server hosts (e.g., Google Workspace, Microsoft 365, Zoho).

SPF & DMARC Security

Email authentication standards that verify authorized sender IPs (SPF) and instruct receiving servers how to enforce security policies (DMARC).

DKIM Signatures

Cryptographic public key in DNS used by receiving mail servers to verify digital signatures on your emails, ensuring messages were not tampered with.

SSL Certificate & Chain

Establishes encrypted HTTPS connections and authenticates domain ownership via an intermediate certificate authority chain.

Hosting Provider & ASN

The physical server infrastructure where website files reside and the autonomous system network (ASN) routing global traffic.

Reverse DNS (PTR)

Pointer (PTR) records that map a server's IP address back to its canonical hostname, verifying server identity and preventing email spam rejection.

HTTP Security Headers

Directives like HSTS, CSP, and X-Frame-Options instructed by the server to protect browser visitors against XSS, clickjacking, and packet sniffing.

⚠️ Report Limitations & Data Sources

  • Data Currency: This report uses cached registry and DNS data (freshened within 4 hours) for high-speed resolution. Click "🔄 Refresh Live" to query directly against authoritative registries.
  • DNS Resolution & Propagation: Records are queried via Google Public DNS-over-HTTPS. Global DNS propagation may take up to 24–48 hours across different regional ISP resolvers during recent DNS record changes.
  • Completeness & Scope: This diagnostic tool analyzes standard authoritative records (A, AAAA, MX, NS, TXT, CNAME, SOA). It does not perform invasive brute-force subdomain scans or unauthenticated DNS zone transfers.
  • Email Deliverability & Reputation: The security analysis (SPF, DKIM, DMARC, and Port 25 SMTP handshake) reflects public DNS policies and inbound connection states. Recipient spam filters evaluate internal headers that cannot be checked from outside.
  • Reverse Proxies & CDNs: If a website is behind Cloudflare, Fastly, or another CDN/reverse proxy, the detected IP, web server software, and SSL edge certificate reflect the proxy tier.