bonuscard.ch
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.6.0
- Stack
- Java
- Cookie consent
-
- OneTrust
Third-party hosts loaded (3)
- assets.adobedtm.com×1
- cdn.cookielaw.org×1
- www.google.com×1
DNS records live
- NS
-
- drns-bp.itsrv.plus
- drns-bp.itsrv.tech
- drns-sp.itsrv.plus
- drns-sp.itsrv.tech
- ns-bp.itsrv.plus
- ns-bp.itsrv.tech
- ns-sp.itsrv.plus
- ns-sp.itsrv.tech
- MX
-
- 20 mail-relay01.itsrv.plus
- 20 mail-relay01.itsrv.tech
- 20 mail-relay02.itsrv.plus
- 20 mail-relay02.itsrv.tech
- TXT
-
Show 13 TXT records
swisssign-check=On9aS3D6sw4uVHp4B2Lo7LcbUTssF6Ko4yykoSz4QDSTIqB7YTn0xznWMREC3Fq3XIrGhTy2JbxYbTy/3uOBzNZ3ZvFzIJ38ZmtJRwWBBifZlM/rw==swisssign-check=tfJn-FPIgSS5MlwydcJ_PhgE6a8swisssign-check=MfONeOHlhi1xSzkzmRwB9dHvTEHHSLvebLGqHPSIujOn9aS3D6sw4uVHp4B2Lo7LcbUTs_lqv3ivbj9s5zgtk8xo3s2ifn80905sg_9icx8r0qlqgbk73zjk6jdnyc1p890eixcmlqp4gfvkhjf21p6rq3m4p3q91661vswisssign-check=qUHhObbckv9N4g7pBEgYx_oohL4z49gy46pv4vt4lkdb08s6kjn8wks8zd21kxzjwb83pv1slfzxjqvp73l80xj70l6_5wev4350brh2fg2te0hq0aul5wdk2vzswisssign-check=wruyDvn_tDGLlBFuQif6u4eYKFU
- Verified for
-
- OneTrust
Email authentication partial
- SPF
-
v=spf1 include:itsrv.tech include:spf.messagelabs.com include:_spfhard.aspectra.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; aspf=s; adkim=s; fo=0; pct=100; rua=mailto:dmarc-rua@itsrv.tech; ruf=mailto:dmarc-ruf@itsrv.techpolicy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires in 109 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
media-src 'self' blob: https://www.bonuscard.ch/ https://www-r1.prep.bonuscard.ch https://www-t1.ittest.bonuscard.ch https://platinum.cdn.cornercard.ch; default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' https://www.bonuscard.ch/ https://www-r1.prep.bonuscard.ch https://www-t1.ittest.bonuscard.ch https://www.googleadservices.com https://usercheck.tech.corner.group https://s.pinimg.com https://script.hotjar.com https://secure-ds.serving-sys.com https://tr.snapchat.com https://googleads.g.doubleclick.net https://www.redditstatic.com/ https://bat.bing.com https://snap.licdn.com https://sc-static.net https://www.googletagmanager.com https://analytics.tiktok.com https://static.hotjar.com https://connect.facebook.net https://static.ads-twitter.com https://assets.adobedtm.com https://cdn.cookielaw.org *.bonuscard.ch https://www.google.com https://www.gstatic.com/ ; style-src 'self' 'unsafe-inline' https://www.gstatic.com/ https://fonts.googleapis.com; img-src 'self' blob: data: htt- strict-transport-security
max-age=31536000; includeSubDomains