bofrost.de
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (10)
- app.usercentrics.eu×3
- privacy-proxy.usercentrics.eu×2
- www.bofrost.be×2
- www.bofrost.lu×2
- api.usercentrics.eu×1
- bofrostchatwebapp.azurewebsites.net×1
- www.bofrost.at×1
- www.bofrost.com×1
- www.bofrost.fr×1
- www.googletagmanager.com×1
Social
Contact
Registration
- Updated
- 2021-02-24
- Name servers
-
- ns1a.dodns.net.
- ns2a.dodns.net.
DNS records live
- NS
-
- ns1a.dodns.net
- ns2a.dodns.net
- MX
-
- 10 mx01.hornetsecurity.com
- 20 mx02.hornetsecurity.com
- 30 mx03.hornetsecurity.com
- 40 mx04.hornetsecurity.com
- TXT
-
Show 10 TXT records
google-site-verification=zq5nEzInOIS4a9tZ67d9z_VVZ7q5DJNH0jUaPg4ohKMapple-domain-verification=fDaeeUL9hvfjlILgmongodb-site-verification=IGH9ESfxlxsOeTu4XMDMlTjObR0S8EWifacebook-domain-verification=qh068dbauls6c2lxoqrp3kpsrj3m8mMS=ms53820495_x2s1fpq98a2i9zb3up93gm2xxy8t9sgcisco-ci-domain-verification=6e173b6619f08ffda414083610e5a3ea207cbef535b1d130cd3ae031afade153q140vz3z1smdx123n0y1vspwwcqbgpfxmiro-verification=649d7f0becea46bc12427f41f34667b79c22c055MS=ms71561146
Email authentication partial
- SPF
-
v=spf1 a mx ip4:213.128.132.136/30 ip4:78.46.2.57 ip6:2a01:4f8:d0a:301f::2 include:spf.hornetsecurity.com include:spf.mailjet.com include:spf.mailingress.de include:spf.protection.outlook.com include:spf-de.emailsignatures365.com include:_spf.salesforce.com ip4:85.10.204.79 ip4:85.10.204.71 ip4:85.10.204.77 ip4:85.10.204.36 ip4:85.10.204.42 ip4:85.10.204.43 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:mailsec@bofrost.de; ruf=mailto:mailsec@bofrost.de; fo=1policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 18 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'unsafe-inline' 'unsafe-eval';frame-ancestors 'self';block-all-mixed-content;upgrade-insecure-requests- strict-transport-security
max-age=31536000 ; includeSubDomains- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin
Links to (6)
- apple.com×2
- facebook.com×2
- google.com×2
- instagram.com×2
- pinterest.de×2
- tinyurl.com×1