baby-walz.de
HTML metadata
Technology
- CDN
- Vercel
Third-party hosts loaded (4)
- a.storyblok.com×113
- www.baby-walz.ch×2
- production.neocomapp.com×1
- www.baby-walz.at×1
Social
Registration
- Updated
- 2014-12-23
- Name servers
-
- a.ns14.net.
- b.ns14.net.
- c.ns14.net.
- d.ns14.net.
DNS records live
- NS
-
- a.ns14.net
- b.ns14.net
- c.ns14.net
- d.ns14.net
- MX
-
- 10 mail1.net.walz.de
- 10 mail2.net.walz.de
- Verified for
-
- Brevo
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx ip4:129.41.76.100 ip4:129.41.76.113 ip4:208.73.7.87 ip4:129.41.167.226 include:inxserver.com include:spf.sendinblue.com include:spf.mailjet.com include:spf.protection.outlook.com include:spf-de.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8sNc0V66gBnr+z4Yi8yw+4YP3f5AhPgvPfKSZ3mDdr1HNfN1PZsZizSp1QZsfzu8ziqV7mysnZWXD4… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - selector1:
Certificate (current)
R13
Expires in 49 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(self https://videos.walz.de https://a.storyblok.com), geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self' https://*.exponea.com; font-src 'self' data: https://babywalz.omq.de https://*.paypalobjects.com https://*.abtasty.com https://*.reviews.io https://applepay.cdn-apple.com; form-action 'self' https://*.adyen.com https://*.facebook.com; frame-ancestors 'self' https://app.storyblok.com; img-src 'self' data: https://*; object-src 'none'; script-src-attr 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' data: 'unsafe-inline' https://*.aboutyou.cloud https://*.adyen.com https://*.omq.de https://*.googletagmanager.com https://fonts.googleapis.com https://*.reviews.io https://*.abtasty.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.baby-walz.de https://checkout.www.baby-walz.de https://*.scayle.cloud https://*.aboutyou.cloud https://*.adyen.com https://*.paypal.com https://*.paypalobjects.com https://babywalz.omq.de https://api.exponea.com https://*.googletagmanager.com https://www.dwin1.com https://www.awin1.com https://the.sciencebehindecommerce.com https- strict-transport-security
max-age=15552000; includeSubDomains;