aov.de
HTML metadata
Registration
- Updated
- 2019-04-23
- Name servers
-
- ns1.aov.de.
- ns2.aov.de.
- ns3.aov.de.
DNS records live
- NS
-
- ns1.aov.de
- ns2.aov.de
- ns3.aov.de
- MX
-
- 100 mailserv1.aov.de
- 100 mailserv2.aov.de
- 200 mailserv3.aov.de
- TXT
-
MS=980C1D7C59F812B5CBCC484D09B96669F5272515atlassian-domain-verification=SQlE1KOK9UDW5vN2KttGacB2QLSCdxmZ3YdmrB/yVAfwUWJ/zYnXfWI7azXZS/tZapple-domain-verification=KIfPmzTu3rFSLgUq
Email authentication strong
- SPF
-
v=spf1 include:_spf.aov.de mx a:smtp1.continue.de a:smtp2.continue.de ip4:84.44.160.21 ip4:84.44.160.20 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=none; pct=100; rua=mailto:dmarc-aggregate@aov.de; ruf=mailto:dmarc-forensic@aov.de; fo=1policy: reject (enforced) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' www.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' wwwdev.aov.de *.aov.de cdn.aov.de *.b-ite.com; connect-src 'self' jobs.b-ite.com *.aov.de; img-src * 'self' data: https:; style-src 'self' 'unsafe-inline' cdn.aov.de *.aov.de;- strict-transport-security
max-age=31536000; includeSubDomains
Linked from (2)
- swn.de×2
- sw-verl.de×1