147.ch
HTML metadata
Technology
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns5.nine.ch
- ns6.nine.ch
- MX
-
- 0 147-ch.mail.protection.outlook.com
- TXT
-
nz=fbcaf6fde9d1f079a14962dcef950564
- Verified for
-
- Meta
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwDfKbj/JGCZfJ4UJU3OvR0waf1oASgHoQ0LlKBh63c7uNrYl2FvfPh5TqNTqRyR67V0g8HTLAW3p/yZEqO… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqLrv/GiJsniZRQ4Rp1Si5RrODH/NNICK+ScolIe+S/djdan/vy9SJ80IJoekY2C9HrQkK6PerMpNRf9dZO…
selectors probed - s1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 84 days
HTTP security headers
- present
-
- content-security-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
Header values
- permissions-policy
unload=*- content-security-policy
default-src 'self'; script-src 'self' blob: https://delivery.contentbird-convert.com https://www.tiktok.com https://*.ttwstatic.com https://*.tiktokcdn.com https://app.usercentrics.eu https://beobachten.147.ch https://www.google-analytics.com https://www.googletagmanager.com https://*.doubleclick.net https://*.google.com https://*.google.ch https://*.google.de https://*.google.sk https://cdn.jsdelivr.net https://popupmaker.com https://*.hotjar.com https://*.hotjar.io 'unsafe-eval' 'unsafe-inline'; connect-src 'self' https://delivery.contentbird-convert.com https://cms.147.ch https://147cms.azurewebsites.net https://147-cms-dgg6dkchf0ejefbr.westeurope-01.azurewebsites.net https://counseling-centers-cms-fwg7fse2d5hxb2ej.westeurope-01.azurewebsites.net https://cms.fsv.projuventute.ch https://app.usercentrics.eu https://api.usercentrics.eu https://graphql.usercentrics.eu https://privacy.usercentrics.eu https://*.service.usercentrics.eu https://*.service.consent.usercentrics.eu https://beob