F
38/100
0 of 1 fixed
All 1 critical issue marked as fixed
Re-scan to confirm and update your score.
1
Upgrade TLS — deprecated protocol in use
ngt.academy is using unknown, which is deprecated and has known vulnerabilities. This is a compliance failure under PCI-DSS, HIPAA, and NIST guidelines. Immediate upgrade to TLS 1.2 minimum (TLS 1.3 preferred) is required.
PCI-DSS 4.0Req 4.2.1
Strong cryptography for transmission
NIST 800-52r2§3.4
TLS 1.0/1.1 must not be used
HIPAA§164.312(e)
Transmission security
How to fix this
1Disable TLS 1.0 and 1.1 in your web server configuration
2Enable TLS 1.2 and 1.3: ssl_protocols TLSv1.2 TLSv1.3
3Remove weak ciphers: ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:...'
4Verify: openssl s_client -connect ngt.academy:443 -tls1_2
At a glance
Full data from this scan
TLS Version
Issues detected
TLS certificate verification failed on ngt.academy: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1081)
DMARC Policy
Not configured
Issues: No DMARC record found — email spoofing is not prevented; No SPF record found; No DKIM records found for common selectors (domain may use custom selectors — this is not a confirmed gap).
SPF Record
Missing
No SPF record found.
Security Headers
0/0 present
All headers configured.
HSTS
Not enabled
Could not fetch https://ngt.academy — connection failed or timed out.
SSL Certificate
Issues
Issues: Could not retrieve certificate details.
DNSSEC
Not enabled
Strengths: 2 nameservers configured (ns.liquidweb.com., ns1.liquidweb.com.); 1 MX records present; Zone transfers properly restricted. Issues: DNSSEC not configured — DNS responses can be spoofed.
Similar companies