carinthia.eu
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- eu-library.klarnaservices.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- nsa5.schlundtech.de
- nsb5.schlundtech.de
- nsc5.schlundtech.de
- nsd5.schlundtech.de
- MX
-
- 10 d328873.a.ess.de.barracudanetworks.com
- 100 d328873.b.ess.de.barracudanetworks.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.ess.barracudanetworks.com include:spf.protection.outlook.com include:_senderspf.copernica.com ip4:80.120.254.164 include:spf.dc-cluster.de include:spf.ess.de.barracudanetworks.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc@smtpeter.compolicy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1;k=rsa;g=*;s=email;h=sha256;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDaSAJjBC443wG2/25c3yn9c6khkst1T1W0lmBijpuWRMcnvPgC8zeARGkubGs2uhR…
selectors probed - dkim:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self' payments-de-sandbox.amazon.com payments-de.amazon.com payments.amazon.de ws://127.0.0.1:35729 www.carinthia.eu b2b.carinthia.eu *.facebook.com *.juicer.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' use.typekit.net www.googletagmanager.com www.google.com www.google-analytics.com www.gstatic.com maps.google.com maps.googleapis.com connect.facebook.net *.payments-amazon.com payments-de-sandbox.amazon.com tagmanager.google.com *.clarity.ms www.carinthia.eu b2b.carinthia.eu *.vimeo.com *.vimeocdn.com *.litix.io *.juicer.io https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js https://bat.bing.com https://www.googleadservices.com https://googleads.g.doubleclick.net *.klarnaservices.com *.clarity.ms *.youtube.com *.google.de *.google.com *.google.at *.google.de *.google.li *.google.lu *.google.co.in *.google.co.id *.google.co.kr *.google.com.tw *.google.co.jp *.google.cn *.google.com.tr *.google.gr *.google.hr *.google.si *.google.bg *.google.ro *.google.- strict-transport-security
max-age=31536000; includeSubDomains; preload