daa-nrw.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (3)
- cdn.eye-able.com×2
- cloud.ccm19.de×1
- daa-matomo.de×1
Social
Contact
- Phone
Registration
- Updated
- 2024-07-31
- Name servers
-
- nsa0.schlundtech.de.
- nsb0.schlundtech.de.
- nsc0.schlundtech.de.
- nsd0.schlundtech.de.
DNS records live
- NS
-
- nsa0.schlundtech.de
- nsb0.schlundtech.de
- nsc0.schlundtech.de
- nsd0.schlundtech.de
- TXT
-
google-site-verification=Bprxa8hFY7tgwz8KwQGT1jNa_QHTvImo9zbZOCu3t8Eseobility=152c7c216319d7baf3b722f2612be58e
Certificate (current)
R13
Expires in 21 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://cloud.ccm19.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://cloud.ccm19.de https://cdn.eye-able.com https://daa-matomo.de blob: 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://cloud.ccm19.de https://cdn.eye-able.com https://daa-matomo.de https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://cloud.ccm19.de https://daa-matomo.de *.google.com; font-src 'self' data: https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cloud.ccm19.de https://cdn.eye-able.com 'report-sample'; connect-src 'self' https://daa-matomo.de https://cloud.ccm19.de https://cdn.eye-able.com https://*.googleapis.com *.google.com https://*.gstati