au-schein.de
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (1)
- cdn.builder.io×42
Registration
- Updated
- 2022-04-08
- Name servers
-
- brianna.ns.cloudflare.com.
- patryk.ns.cloudflare.com.
DNS records live
- NS
-
- brianna.ns.cloudflare.com
- patryk.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
MS=B87DAD90F0590D49A52F04709AFFCCC0375CE33Batlassian-domain-verification=bvbZd4KENLpwcdFm/FhfxxR/P2BouTxGgD2qd8Et7FFrcXMcua/vN8GZqznLKSvCgoogle-site-verification=2Y4sIfxOPmajwPn6Ea-Ld85I2816ydk9PuW4Kczsgt0sendinblue-code:304882ea0efcf9f01771b8e6d9b58e03wiz-domain-verification=a112083cf60e535135d4ae921e2f35c7c5b718dece758569bf638cb789142abc
Email authentication partial
- SPF
-
v=spf1 include:spf.sendinblue.com include:_spf.google.com mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCs2ZHwkURlwuVkDOfrpjF7p3QPUS5JG5tdkx0e7wZsbIe0LWm+zigwsK9kqI5C+9H1HXWT6zP2UXVfSuanBT… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0aD2DZucJFfTXtyV2lmPHQa0ioEsXj/9J43LBraoAw7dkzH5HAWMdUL9tPATzMG/IXz+0wkzlYuLWwBPZm… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDtVFSmbuDKRb1tTSbUta3y3fS1UkxJTRC7I9JoZsLKE1Qcf2MZnPTybuTa+n+wjpLJOKo2jKCQRtDsJpcz5ElxtG…
selectors probed - google:
Certificate (current)
WE1
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
camera=(), microphone=(), geolocation=(self), payment=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://builder.io https://*.builder.io; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.api.here.com https://cdn.builder.io https://*.builder.io https://www.googletagmanager.com https://js.stripe.com https://*.crisp.chat https://sdk.frontnow.app https://*.frontnow.app https://sg.dransay.com https://analytics.ahrefs.com https://*.usercentrics.eu https://*.posthog.com https://*.i.posthog.com https://analytics.cnd-motionmedia.de https://cdn.rudderlabs.com https://www.youtube.com https://*.hotjar.com https://t.adcell.com https://p.gsitrix.com https://o.gsitrix.com https://s.adroll.com https://d.adroll.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.redditstatic.com https://*.optimeleon.com; style-src 'self' 'unsafe-inline' https://js.api.here.com https://cdn.builder.io https://fonts.googleapis.com https://*.crisp.chat https://*.frontnow.app https://*.posthog.com https://*.usercentrics.eu https://*.h- strict-transport-security
max-age=63072000; includeSubDomains; preload