3on-it.de
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (3)
- consent.cookiebot.com×1
- js-eu1.hs-scripts.com×1
- script.crazyegg.com×1
Social
Registration
- Updated
- 2023-10-23
- Name servers
-
- dns.dns1.de.
- dns.dns2.de.
- dns.dns3.de.
- dns.dns4.de.
DNS records live
- NS
-
- dns.dns1.de
- dns.dns2.de
- dns.dns3.de
- dns.dns4.de
- MX
-
- 0 3onit-de0i.mail.protection.outlook.com
- TXT
-
apple-domain-verification=tzqooQIvH16OqsmYopenai-domain-verification=dv-95gJUwsJRDuZKwYSQ1Wveds2MS=ms40618775
Email authentication partial
- SPF
-
v=spf1 a include:spf.protection.outlook.com include:spf.crsend.com include:26766888.spf04.hubspotemail.net include:spf-de.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:dmarc@3on-it.de; ruf=mailto:dmarc@3on-it.de; fo=1policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApi6BYQAYgHeMzdboQ7BHPyBBG0V35gGEhYe2g6QwSMJI8o+bh2/e1KtV3+gGaFw8QJFFV+97ogMngR…
selectors probed - selector1:
Certificate (current)
R12
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), vr=(), speaker=(), ambient-light-sensor=(), gyroscope=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src-elem 'self' 'unsafe-inline' *.leadinfo.net *.cookiebot.com *.crazyegg.com *.googletagmanager.com *.hubspot.com *.hsappstatic.net *.hsforms.net *.hs-scripts.com *.multipage.online *.hs-analytics.net *.hs-banner.com *.usemessages.com *.hscollectedforms.net; style-src-elem 'self' 'unsafe-inline' *.multipage.online *.hs-analytics.net *.hs-banner.com *.usemessages.com *.hscollectedforms.net; style-src-attr 'self' 'unsafe-inline'; img-src 'self' data: *.cookiebot.com *.hsforms.com *.multipage.online *.hubspot.com *.googletagmanager.com; connect-src 'self' data: *.crazyegg.com *.leadinfo.net *.leadinfo.com *.cookiebot.com *.multipage.online *.google-analytics.com *.hubspot.com *.hscollectedforms.net *.3on-it.de; frame-src 'self' *.cookiebot.com *.hubspot.com *.hsforms.net; worker-src 'self' blob:;- strict-transport-security
max-age=31536000; includeSubdomains, max-age=15768000; includeSubDomains