burotippspiel.de
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Hugo
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- cdn.jsdelivr.net×6
- www.googletagmanager.com×3
- assets.getkoppa.com×2
- cdnjs.cloudflare.com×2
- js.sentry-cdn.com×1
- sdk.gleap.io×1
Social
Contact
- Phone
Registration
- Updated
- 2026-04-22
- Name servers
-
- alexis.ns.cloudflare.com.
- heather.ns.cloudflare.com.
DNS records live
- NS
-
- alexis.ns.cloudflare.com
- heather.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=7vHrQeha2qpMi2j2VrPitgEgQnGFibGuUFolCSxaQKohosted-email-verify=ha7xsrtd
Email authentication strong
- SPF
-
v=spf1 include:spf.migadu.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarcreports@gokoppa.compolicy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx6p9TQgQteZrZ28fxowhIrMNWG2qFrIC7A6lTj/GLPCSV0mXDaYO0IffaxjU9HqycsyWDKHU2gDtOV…
selectors probed - google:
Certificate (current)
E7
Expires in 26 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(self "https://*.gleap.io"), geolocation=(), payment=(), fullscreen=(self "https://*.gleap.io" "https://tally.so" "https://forms.gokoppa.com"), clipboard-write=(self "https://*.gleap.io" "https://tally.so" "https://forms.gokoppa.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://www.googletagmanager.com https://sdk.gleap.io https://cdnjs.cloudflare.com https://www.google.com https://www.gstatic.com https://sc.lfeeder.com https://snap.licdn.com https://assets.calendly.com https://tally.so https://browser.sentry.io https://js.sentry-cdn.com https://browser.sentry-cdn.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; img-src 'self' data: https:; font-src 'self' https:; connect-src 'self' https: wss://ws.gleap.io; frame-src 'self' https://calendly.com https://*.calendly.com https://tally.so https://forms.gokoppa.com https://*.gleap.io https://www.googletagmanager.com https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com; frame-ancestors 'none'; media-src 'self' https://js.gleap.io;- strict-transport-security
max-age=31536000; includeSubDomains; preload