clickstorm.de
HTML metadata
Technology
- Server
- Apache
Social
Contact
- Phone
- Address
- Altenburger Straße 13, 04275, DE
Registration
- Updated
- 2016-10-19
- Name servers
-
- ns1.csname.net.
- ns2.csname.net.
- ns3.csname.net.
DNS records live
- NS
-
- ns1.csname.net
- ns2.csname.net
- ns3.csname.net
- MX
-
- 10 dedi3224.your-server.de
- TXT
-
google-site-verification=vxxsehERL9l04vm5XhU5_SeKpBiMaU_GSED9lZfWWqoMS=69CD187DF68A677101635884A97BDAAF1812B687
Email authentication strong
- SPF
-
v=spf1 a mx include:spf.mailjet.com include:spf.nl2go.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;sp=none;pct=50;adkim=r;aspf=r;policy: quarantine · pct=50 · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 170 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin- x-frame-options
ALLOW-FROM cstorm.atlassian.net- permissions-policy
accelerometer=(), autoplay=(self), camera=(), encrypted-media=(), fullscreen=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' fonts.googleapis.com fonts.gstatic.com cstorm.atlassian.net;style-src 'self' 'unsafe-inline' fonts.googleapis.com cstorm.atlassian.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com ssl.google-analytics.com www.gstatic.com maps.google.com maps.googleapis.com *.googletagmanager.com;connect-src 'self' stats.g.doubleclick.net www.google-analytics.com *.google-analytics.com *.analytics.google.com maps.googleapis.com *.googletagmanager.com;img-src 'self' 'unsafe-inline' 'unsafe-eval' data: www.doctolib.de maps.googleapis.com *.google-analytics.com maps.gstatic.com *.googletagmanager.com;frame-src www.youtube-nocookie.com;frame-ancestors 'self' cstorm.atlassian.net;form-action 'self';base-uri 'self';worker-src 'self' blob:;- strict-transport-security
max-age=31536000; includeSubDomains; preload