die-hochrheinbahn.com
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Registration
- Registrar
- EuroDNS S.A.
- Created
- 2020-05-28
- Expires
- 2026-05-28 8 days left
- Updated
- 2025-05-22
- Name servers
-
- ns-c.eurodns.eu
- ns-d.eurodns.biz
DNS records live
- NS
-
- ns-c.eurodns.eu
- ns-d.eurodns.biz
- MX
-
- 10 mail.die-hochrheinbahn.com
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Encryption Everywhere DV TLS CA - G2
Expires in 195 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- permissions-policy
geolocation=(), microphone=(), camera=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://dbwas.service.deutschebahn.com https://graphql.usercentrics.eu https://v1.api.service.cmp.usercentrics.eu; script-src 'self' https://app.usercentrics.eu https://dbwas.service.deutschebahn.com https://static.deutschebahn.com https://uct.service.usercentrics.eu https://v1.api.service.cmp.usercentrics.eu https://web.cmp.usercentrics.eu 'sha256-aBEXUauJIhP4+usMjK1U/zEWxwwVvi6u4/rTH/jgaBw=' 'nonce-d07a11e2c9f4884c364db6db3fe4333d'; img-src 'self' blob: data: https://app.usercentrics.eu https://uct.service.usercentrics.eu; media-src 'self'; font-src 'self' data:; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com https://*.newsletter.deutschebahn.com; frame-ancestors 'self'; form-action 'self' https://432512.newsletter.deutschebahn.com; worker-src 'self' blob:- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin