bastei-luebbe.de
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
Third-party hosts loaded (1)
- images.ctfassets.net×24
Social
Contact
- Address
- Schanzenstraße 6-20, 51063, Köln, DE
Registration
- Updated
- 2022-08-10
- Name servers
-
- ns1.kiagdomain.de.
- ns2.kiagdomain.de.
DNS records live
- NS
-
- ns1.kiagdomain.de
- ns2.kiagdomain.de
- MX
-
- 10 relay.mail.sec-provider.de
- TXT
-
Show 4 TXT records
hvopdamjk8ql1kqueiu96ppi1c00D68000004DIKt=1TBTy00000000Kzesh0n24ajdve50pqb6ockvjif4pardot1024131=8ed30f6873cc5922e9341d5de9ff98df8e57b27b5e14e04c8ae99e58290bf2ce
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:46.20.39.153 ip4:212.18.11.33/27 ip4:80.251.80.0/28 ip4:78.35.13.19 include:spf.mailjet.com include:_spf.rexx-suite.com include:spf.pallas-security.com include:spf.sec-provider.de include:spf.protection.outlook.com include:spf.eu.exclaimer.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:it-dienste@luebbe.depolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5NIAV1ANzoH890Vae2PgR6kDA+qLmQOx+6CwksPxykXh45CgX7J2AF9FADvKYn0CFn5Re5AsEdFaVF…
selectors probed - selector1:
Certificate (current)
R13
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' *.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.ccm19.de *.googletagmanager.com *.facebook.net *.tiktok.com *.youtube.com *.vimeo.com vercel.live charts3.equitystory.com *.pinimg.com *.pinterest.com ir-api.eqs.com https://googleads.g.doubleclick.net https://platform.contentfry.com/sdk/embed.js *.involve.me; frame-src 'self' 'unsafe-eval' 'unsafe-inline' *.ccm19.de *.googletagmanager.com *.facebook.net *.tiktok.com *.youtube.com *.vimeo.com vercel.live *.bic-media.com charts3.equitystory.com *.pinterest.com *.doubleclick.net ir-api.eqs.com https://www.facebook.com https://tracking.bastei-luebbe.de https://gtm-747961606695.europe-west3.run.app https://display.contentfry.com/ *.involve.me; style-src 'self' 'unsafe-inline' *.ccm19.de ir-api.eqs.com https://fonts.googleapis.com; img-src 'self' blob: data: https:; font-src 'self' https:; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'self' *.contentful.com https://app.contentfu- strict-transport-security
max-age=63072000