classicseller.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- www.classicseller.com×1
Registration
- Updated
- 2020-09-22
- Name servers
-
- ns1.first-ns.de.
- robotns2.second-ns.de.
- robotns3.second-ns.com.
DNS records live
- NS
-
- ns1.first-ns.de
- robotns2.second-ns.de
- robotns3.second-ns.com
- MX
-
- 10 mail.classicseller.de
Email authentication strong
- SPF
-
v=spf1 +a +mx +a:www.classicseller.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; adkim=s; aspf=spolicy: quarantine - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJ4zrIKwqj3fLqhi1rUZlwMecbLCGic5xTBvnUIvexGCzpnxIu7ePMaI7XPCEZ1KDSW0ufHakAdK5EP9psZtT5XeBym…
selectors probed - default:
Certificate (current)
R13
Expires in 76 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
publickey-credentials-get=(self "https://js.stripe.com" "https://*.js.stripe.com"), payment=(self "https://js.stripe.com" "https://*.js.stripe.com"), web-share=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; connect-src 'self' https://*.paypal.com https://www.paypalobjects.com https://*.classicseller.de https://api.stripe.com; form-action 'self'; frame-ancestors 'self' https://*.etracker.com; frame-src 'self' https://*.paypal.com https://www.paypalobjects.com https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com; img-src 'self' data: https://*.paypal.com https://www.paypalobjects.com https://media.classicseller.de https://*.classicseller.de; script-src 'self' https://*.paypal.com https://www.paypalobjects.com https://*.classicseller.de https://*.js.stripe.com https://js.stripe.com 'unsafe-inline' 'nonce-jjEjmZ8lt3Esovt9IdDAZg=='; style-src 'self' https://*.paypal.com https://*.classicseller.de 'unsafe-inline'; report-uri https://www.classicseller.de//nelmio/csp/report