campus-nes.de
HTML metadata
Technology
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (1)
- consent.cookiebot.com×1
Social
Contact
- Phone
Registration
- Updated
- 2024-04-23
- Name servers
-
- ns1.telekom-domains.de.
- ns2.telekom-domains.de.
DNS records live
- NS
-
- ns1.telekom-domains.de
- ns2.telekom-domains.de
- MX
-
- 10 mail2.rhoen-klinikum-ag.com
- 20 mail.rhoen-klinikum-ag.com
- TXT
-
Show 6 TXT records
_telesec-domain-validation=343808_2025-11-17_6dEvfCMViejKcioOFGaM0rAIZ0At3eap1XoENjTBlsna2pIXTpMS=ms51475288apple-domain-verification=DPv7DhbPW3g3b05rgoogle-site-verification=RdlVt_YGaUgy4JVlEsYwBLIR_bxMo6HhhqmdxDIH-e0_telesec-domain-validation=328385_2024-02-06_AAKmoRbg0AiNARw0rXwUDjyDJJdPyYizDHTaegQsw8Qe60eSwbatlassian-domain-verification=OuzPma5BnLThijneY9wCrdx0ZODfyV0O7hobPpGquBGLTa5cWZkmQ2hUPyvezRDG
Email authentication weak
- SPF
-
v=spf1 mx ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Telekom Security ServerID OV Class 2 CA
Expires in 186 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' securemessage.rhoen-klinikum-ag.com matomo.int.insignio.com *.moin.ai *.cookiebot.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com blob: securemessage.rhoen-klinikum-ag.com www.campus-nes.de *.rhoen-klinikum-ag.com matomo.int.insignio.com *.moin.ai *.cookiebot.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com securemessage.rhoen-klinikum-ag.com charts3.equitystory.com app.guide3d.com https://media.video.taxi matomo.int.insignio.com *.moin.ai *.cookiebot.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' securemessage.rhoen-klinikum-ag.com matomo.int.insignio.com *.moin.ai *.cookiebot.com 'report-sample'; style-src 'self' 'unsafe-inline' securemessage.rhoen-klinikum-ag.com matomo.int.insignio.com *.moin.ai *.cookiebot.com 'report-sample'; font-src 'self' data: securemessage.rhoen-klinikum-ag.com matomo.int.in