castenow.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Drupal
Social
Contact
- Phone
Registration
- Updated
- 2019-10-15
- Name servers
-
- ns1a.dodns.net.
- ns2a.dodns.net.
DNS records live
- NS
-
- ns1a.dodns.net
- ns2a.dodns.net
- MX
-
- 10 mx01.hornetsecurity.com
- 20 mx02.hornetsecurity.com
- 30 mx03.hornetsecurity.com
- 40 mx04.hornetsecurity.com
- TXT
-
Show 6 TXT records
google-site-verification=XBMADx3NY1tExujZ9wMWrLySGlgOvQgLzY9GCqoZPuUfigma-domain-verification=19b71f481aafb134e8ed9bd600215c34bb42437da103fd52a181e5bad1e1bb68-1764258816google-site-verification=L_Oh5-0tFBr8ohEjHCMpvTifSSntqnZuaqO7YIkz9k0bw=IvQUPm2zFtKput9AGaPDkeydl9MUGXifbBV2gIyL6naZmiro-verification=5669550664b38c8dd8adbf7ec194fef871f22989MS=ms46197635
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.hornetsecurity.com include:spf.protection.outlook.com include:spf-de.emailsignatures365.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@castenow.depolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; connect-src 'self' wss: data: https://matomo.pw6.de/; font-src 'self' data:; frame-src 'self' www.youtube.com https://auth.pw6.de; img-src 'self' data: i.ytimg.com; media-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' matomo.pw6.de https://www.instagram.com https://matomo.pw6.de/; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' matomo.pw6.de https://www.instagram.com; style-src 'self' 'unsafe-inline'- strict-transport-security
max-age=31536000