all-for-one.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Next.js
Third-party hosts loaded (2)
- images.ctfassets.net×14
- cookie-cdn.cookiepro.com×1
Social
Contact
Registration
- Registrar
- Key-Systems GmbH
- Created
- 1997-10-25
- Expires
- 2026-10-24 157 days left
- Updated
- 2025-11-27
- Name servers
-
- ns1.nic53.net
- ns2.nic53.de
DNS records live
- NS
-
- ns1.nic53.net
- ns2.nic53.de
- MX
-
- 10 allforone-com0ii.mail.protection.outlook.com
- TXT
-
Show 14 TXT records
google-site-verification=Lv62NPsyQy6XX7Ld0cLSXyvSNGW0zSkZ763IxSljxN8atlassian-domain-verification=Tgfo4AfsN1QGmRtJaHvK/ba89uyvwY8j/LVvxhWzfR6hrYzh0gaFWgPdzSQB584Aatlassian-domain-verification=7aYHF71aw7hsKJ0Q8FGDo8OhDfQqtNOoF//Ka1QNM7WfGkAPp/a1PS/pFaoBYjC9atlassian-sending-domain-verification=99cf108e-1011-4c99-a9ac-df4bdd0b1bf8atlassian-domain-verification=dKfQY/X0rMAbtUMca2wzVX1WZbB78FAfVO2Dud6tUDCjC5XGdj7nsi1pa8g9XtQ8google-site-verification=Q6zAowcBRHV_JN9rjxxwxZ7ExmNoTatPkgaKft7uK_smiro-verification=c425c3e3592d26bc3c4c4d44a904aa4edc55ef29docusign=2eb088f4-568e-42f8-8aa1-2a6e9f60f159apple-domain-verification=BWkPeVdute3LMwQwatlassian-domain-verification=9oiaURtJ31pP3/677vStKLGZxML6ddCrZVpyrnJ4ZBEw/MwKQw6N01QdFooOphnwteamviewer-sso-verification=30f9e2388ca24282a3fb54dc81986720v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3BYI6oKWpFrvmIcPBFTBgW5tbWac3+cB8LyzO76j2gqdQzvFCecTNz2HrR1jjWZp+jY50lFNlTn/wennyJvhcqn43qdsaEw7BKnenNSDczrsLTRcRk4i5Pg/8UnU8XuQ1zInn+Sa7bndYb+SijhEvuuzNwTCRREfsAbePuyXMqbjOMl3aYGSOGM5caQNbUXykh6ydC6yE5xKFgK0V13I/3h9EwsT1wxVtFeScL/m6sO1oDfBw+hmvVhzuOj4D2lsEo2bMpolFSLKSApGS63dLPX1KX/4jiXBTsD/N4U6Z0J0YUuGzTLMpqPR1Ek9RXDqshAKbabdQ+JQN4eAqBhmQwIDAQABfacebook-domain-verification=tj8bgd0hd1opkcpo2zijm57iz5kllpmgverify=a038c2b9138c62f688544424b27058df2bd693c876ef38c1e2eadfbccb184f23
Email authentication strong
- SPF
-
v=spf1 include:spf.hornetsecurity.com include:spf.protection.outlook.com include:_spfeu.qmarkets-dns.org include:2849983.spf07.hubspotemail.net include:amazonses.com include:_spf.eegw.corp365online.com include:mailgun.org ip4:91.229.169.9 ip4:195.243.206.130 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@all-for-one.com; ruf=mailto:dmarc@all-for-one.com; fo=1policy: none (monitoring only) - DKIM
-
- s1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdjztsVhlmSSRvT/1qgtnaKklirRfmZM8A6i2bqDS/Na392Nlz8UzaPI0flZRruk7uxIKy5MPRYbp/JTm6nPF0kCPbbsA… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - s1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 230 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.all-for-one.com *.e-spirit.hosting *.blue-zone.io *.all-for-one-test.monday.com *.all-for-one.monday.com embedder.app; frame-ancestors 'self' https://*.e-spirit.hosting https://all-for-one-test.monday.com https://all-for-one.monday.com https://embedder.app; media-src 'self' https://cdn.blue-zone.io https://media.blue-zone.io https://cdn.all-for-one.com https://media.all-for-one.com https://open.spotify.com https://itunes.apple.com https://allforonegroup.podcaster.de https://www.brn-ag.de https://images.ctfassets.net https://videos.ctfassets.net blob: https://prelive.all-for-one.com https://d2l5frpsmiqn.cloudfront.net; img-src 'self' data: https:; font-src *; frame-src *; connect-src *; script-src * 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' blob:; style-src * 'unsafe-inline';- strict-transport-security
max-age=31536000; includeSubDomains; preload