bad-endbach.de
HTML metadata
Technology
- Server
- nginx
Registration
- Updated
- 2018-07-26
- Name servers
-
- ns1019.ui-dns.biz.
- ns1019.ui-dns.com.
- ns1019.ui-dns.de.
- ns1019.ui-dns.org.
DNS records live
- NS
-
- ns1019.ui-dns.biz
- ns1019.ui-dns.com
- ns1019.ui-dns.de
- ns1019.ui-dns.org
- MX
-
- 10 mail.bad-endbach.info
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://*.forms.app https://cdn.forms.app; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: https://*.forms.app https://cdn.forms.app https://s3-media0.fl.yelpcdn.com https://s3-media1.fl.yelpcdn.com https://s3-media2.fl.yelpcdn.com https://s3-media3.fl.yelpcdn.com https://cdn.yelp.com https://www.yelp.com; frame-src 'self' https://*.forms.app https://www.paypal.com https://www.sandbox.paypal.com; connect-src 'self' https: https://*.forms.app https://api.forms.app https://www.yelp.com https://api.yelp.com; worker-src 'self' https://*.forms.app; child-src https:; font-src 'self' https: data: https://*.forms.app https://cdn.forms.app;, default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://*.forms.app https://cdn.forms.app; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: https://*.forms.app https://cdn.forms.app https://s3-media0.fl.yelpcdn.com h- strict-transport-security
max-age=31536000; includeSubDomains; preload, “max-age=31536000”, max-age=31536000; includeSubDomains; preload