bdk.de
HTML metadata
Technology
- Server
- nginx
Registration
- Updated
- 2019-05-14
- Name servers
-
- ns2.iacd.net.
- ns.iacd.net.
DNS records live
- NS
-
- ns.iacd.net
- ns2.iacd.net
- MX
-
- 10 mail.bdk.de
Email authentication strong
- SPF
-
v=spf1 a mx ip4:217.113.41.29/32 ip4:217.113.45.228/32 ip4:217.113.43.137 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject; rua=mailto:admin@bdk.de; ruf=mailto:postmaster@bdk.depolicy: reject (enforced) - DKIM
-
- default:
v=DKIM1; h=sha256; k=rsa;p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAqAUSgy40g0Xs2tg3edBnC2CHREOasDttb5BJ88y9UIQp8sbBMuoOFzRXAL1U39PCzpi1T…
selectors probed - default:
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, DENY- permissions-policy
geolocation=(self), microphone=(), camera=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src 'self' https://bbbank-content-tool.de data:; connect-src 'self' https://bbbank-content-tool.de; frame-src 'self' https://player.vimeo.com https://www.youtube.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://bbbank-content-tool.de; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; frame-ancestors 'none';- cross-origin-opener-policy
same-origin