deinehrenamt.de
HTML metadata
Technology
Third-party hosts loaded (3)
- img.hessen-agentur.de×12
- cdn.hessen-agentur.de×4
- matomo.hessen-agentur.de×1
Registration
- Updated
- 2018-03-13
- Name servers
-
- ns1.vistec.net.
- ns2.vistec.net.
DNS records live
- NS
-
- ns1.vistec.net
- ns2.vistec.net
- MX
-
Show 6 MX records
- 10 spamwall2-1.vistec.net
- 10 spamwall2-2.vistec.net
- 10 spamwall2-3.vistec.net
- 10 spamwall2-4.vistec.net
- 10 spamwall2-5.vistec.net
- 10 spamwall2-6.vistec.net
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a mx ip4:213.216.17.189/32 include:spf.mailjet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; sp=none; pct=100; ri=86400; aspf=r; adkim=r; fo=1policy: reject (enforced) · sp=none - DKIM
-
- dkim:
v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDld4BKJJaM4yMgRrK+yKXCUJMlnxBK7lRaU8BHdJh6ZAprl3JWVHn8PhEku0L/uh+xGex+7QldLsvYyiwP77a2p7…
selectors probed - dkim:
Certificate (current)
E7
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), camera=(), microphone=(), fullscreen=(self), payment=(), usb=(), accelerometer=(self), gyroscope=(self), magnetometer=()- x-content-type-options
nosniff- content-security-policy
style-src 'self' 'unsafe-inline' *.hessen-agentur.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hessen-agentur.de; object-src 'self' *.hessen-agentur.de blob:; connect-src 'self' 'unsafe-inline' nominatim.openstreetmap.org *.googleapis.com *.hessen-agentur.de; media-src 'self' blob: *.hessen-agentur.de ; default-src https: 'self' * blob: data: https:; img-src 'self' * blob: data: *.hessen-agentur.de; frame-ancestors 'self' https://dsx.hessen-agentur.de/- strict-transport-security
max-age=31536000