alterric.com
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Social
Contact
- Phone
Registration
- Registrar
- Key-Systems GmbH
- Created
- 2021-02-15
- Expires
- 2027-02-15 272 days left
- Updated
- 2026-02-16
- Name servers
-
- ans0.ewetel.de
- ans1.ewetel.net
- ans2.ewetel.de
- ans3.ewetel.net
DNS records live
- NS
-
- ans0.ewetel.de
- ans1.ewetel.net
- ans2.ewetel.de
- ans3.ewetel.net
- MX
-
- 10 alterric-com.mail.protection.outlook.com
- TXT
-
Show 11 TXT records
atlassian-domain-verification=scnMbzWgiHRKEbzvCVkiybCrO2tPrGIXRPBCVmIjU9nzgSiaBSAKTStz4rFMkrVHMS=ms235609628c0eaba8-0b84-4a45-bc08-ae434f4a6311apple-domain-verification=lZOvvGQYwzIZwgMOflexera-domain-verification-bvripgulvhhgbqftdocusign=2078b776-46fd-427d-8a4e-cce48fdb0d11autodesk-domain-verification=HX6WkrGMqV55E_YZh3pYmiro-verification=d5b819bd05f9a4c94a909b7fcbb6f9b8c720bfe8google-site-verification=E-165ID8jNoM2lHvnyz2w-Yg2t-4pumiqAXEPR8I_Bcatlassian-sending-domain-verification=7c7e5f29-d76b-4db7-bfae-ab845f839e5dv=DMARC1; p=none; rua=mailto:it-sec@alterric.com; ruf=mailto:it-sec@alterric.com
Email authentication weak
- SPF
-
v=spf1 a:email.prnewswire.com ip4:193.53.250.185 ip4:85.214.99.153 ip4:81.169.162.35 ip4:81.169.253.123 include:spf.protection.outlook.com include:_spf.ewetel.de include:spf.evalea.de include:spf.servicemail24.de -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt+cic8O6he9Dph11TUoannQMJ3FMBZQqNWmixlS5N8QMpZ2m9kfeia2fSmRt+wzjuCb3RW4sYsyWeE… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GhwOwjeGl7b54Kg2X9agYWf36v/rr09hNg0wgGyOu95qTqQbAdnGe9NHdpMvGHEHAATJYQylCpdq5…
selectors probed - selector1:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 255 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), accelerometer=(), gyroscope=(), magnetometer=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'nonce-uu+ChtixfHV56h4LP/hODA==' 'strict-dynamic';form-action 'self';connect-src 'self' *.googletagmanager.com *.google-analytics.com *.googleapis.com;media-src 'self' blob: data:; base-uri 'self'; object-src 'none'; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.googleapis.com; frame-ancestors 'self'; frame-src 'self'; font-src 'self' data: *.gstatic.com; img-src 'self' *.googletagmanager.com data: *.googleapis.com *.gstatic.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin; report-to="default"- cross-origin-embedder-policy
unsafe-none; report-to="default"- cross-origin-resource-policy
cross-origin