datev.it
HTML metadata
Technology
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×3
- gmpg.org×1
- www.google.com×1
Contact
DNS records live
- NS
-
- ns01.datev.de
- ns02.datev.com
- MX
-
- 0 immail01.prod.datev.de
- 0 immail02.prod.datev.eu
Email authentication partial
- SPF
-
v=spf1 ip4:93.62.234.96/29 ip4:93.62.234.105/29 ip4:37.186.225.200/29 ip4:151.0.184.56/29 ip4:93.47.135.0/25 ip4:89.96.88.176/28 ip4:37.186.235.144/29 ip4:93.62.132.144/28 ip4:93.51.247.80/28 ip4:93.41.189.0/25 ip4:93.47.209.0/24 ip4:93.47.210.0/24 ip4:85.18.95.0/24 include:turbo-smtp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:dmarc-a@reports.datev.depolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 100 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.jsdelivr.net *.googleapis.com *.gstatic.com *.gravatar.com *.googletagmanager.com *.google-analytics.com *.zoom.us zoom.us *.cookiebot.com *.google.com *.jquery.com 'unsafe-inline' 'unsafe-eval' ws:; worker-src blob:; frame-src *.google.com blob: data:; img-src *.w.org *.jquery.com *.gravatar.com *.zoom.us api.prestashop-project.org 'self' data:; font-src *.jquery.com *.googleapis.com *.gstatic.com *.zoom.us 'self' data:;- strict-transport-security
max-age=31536000; includeSubDomains