bachmannkarten.ch
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Contact
- Phone
- Address
- Dammstrasse 2CH-6383 DallenwilTel.+41 41 629 70 80info@bachmannkarten.ch
DNS records live
- NS
-
- ns1.trendhosting-net.ch
- tux13.trendhosting-net.ch
- MX
-
- 0 bachmannkarten-ch.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a:spf.trendhosting-net.ch include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email;policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
YE1
Expires in 88 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), payment=(self)- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; frame-ancestors *;- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains;- cross-origin-opener-policy
same-origin-allow-popups;- cross-origin-embedder-policy
unsafe-none;- cross-origin-resource-policy
same-origin;- content-security-policy-report-only
default-src 'self'; script-src 'self' https: 'sha256-MzK5TtoxGStCBsjQ73v3AiJDm4Djnn59ODWXebPMK3E=' 'sha256-ez2NesdJiz2JtSXPbJ0KPBkYizPifHkgJRbSceMnoLQ=' 'sha256-3hP87bSroOnU+wlhA7wEIVpYTD1GnDLLU0nqRwSH0YM=' 'sha256-fMH1eeBIo7IIb7/ib1fbilK1/owvkU78z4FJVjZhbz0=' 'sha256-6/Y5bLK7dYojIeRPkjO5EU6szR8mScmTyGu7E7eQ2e8=' 'sha256-hRZNQcLrghE3AQTI1IHvlH7ICsHj4jrQGcn18MvNkSM=' 'sha256-d0PDBMb89ACG+fGfWyEzOQu16LUeEQSPWFaaREunq44=' 'sha256-HaPHu1RTk9ENsl4i8ca2PgwrqmOqd7iaV8vNfGkJkEU=' 'sha256-VOBs7IF0ljUtd7oAW8OTlAf0reLe2V1ITwcBtbI4GlI=' 'sha256-uYz/LeJ53PSyjwtskacOeXcJBgXWkXcHmR8VyZZvK1c=' 'sha256-mRbdKfgY2uDykn1DfW9saYRH5Tho0v9AHR5gXOmIJIg=' 'sha256-WTos5IdFeNHz2AIy4TuOiPx+Pf/MWt3n6qpr42PlRI4=' 'sha256-ftWatFLf8bvcuRNWhA419QHxNbYk+PBPlBqR5Cl7Ujc='; style-src 'self' https: 'unsafe-hashes' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-60lRWTc9D4esA70Rc17srTC48ar/4QtxUK+Zv/3oucY=' 'sha256-lBwNe0qpKGbgdaFgVTCb5PG6X8cSM3EEoJ341WR4ptc='; img-src 'self' https: data:; font-src 'self' http