az-direct.ch
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- ns-anycast1.hostpoint.ch
- ns-anycast2.hostpoint.ch
- ns-ch.hostpoint.ch
- MX
-
- 5 azdirect-ch0e.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
knowbe4-site-verification=c0444f93b83f0ee0554a067b668b8782MS=8179D751CD02C86DC722B02409B77DCBA82E9C51linkedin-site-verification=bdc300ad-965a-491e-b879-dcd6b554ba0dswisssign-check=se2gu62I7Ago23d356pYPMmfpb5XeapQLztTHZKUWzhes=0985c8a7140254e448b25806dbdf66c2ec06e397-54ff-4b47-aa48-ddfbf87e2911
- Verified for
-
- Adobe
- Apple
- OpenAI
Email authentication strong
- SPF
-
v=spf1 include:_spf.atlassian.net include:spf.protection.outlook.com include:spf2.azavista.com include:spf.servicemail24.de -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:bpg-rua@dmarc.servicemail24.de; pct=100; ri=86400policy: quarantine · sp=quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5BYUQM235VzxCXitxNcViCKt9tei97zKGV+obn1l9tkBwqUoKY4YDImz90EN9qIC83BS7dh6dqf8Pq…
selectors probed - selector1:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 276 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.cookiebot.com *.cookiebot.eu *.facebook.com *.youtube-nocookie.com *.admin.ch *.xing-events.com *.google-analytics.com *.doubleclick.net *.oribi.io *.google.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.az-direct.com *.doubleclick.net *.ytimg.com *.linkedin.com *.youtube.com *.bizographics.com *.cookiebot.eu *.cookiebot.com *.xing-events.com *.f24.org *.googleapis.com *.googletagmanager.com *.google-analytics.com *.adform.net *.licdn.com *.facebook.net *.facebook.com *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.hs-analytics.net *.oribi.io google.de; script-src-attr * 'self' data: *.az-direct.ch; style-src 'self' 'unsafe-inline' *.googleapis.com; style-src-elem * 'self' data: 'unsafe-inline'; img-src 'self' data: *.cloudfront.net *.google.de *.googletagmanager.com *.gstatic.com *.usercentrics.eu *.googleapis.com *.google-analytics.com *.facebook.com *.linkedin.com *.adform.net *.licdn.com *.facebook.net *.f24.org *.google.com *.doubleclic