diesaat.at
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- JS framework
- Next.js
Third-party hosts loaded (2)
- media.diesaat.hendriks.cloud×21
- media.diesaat-test.hendriks.cloud×2
Social
Contact
DNS records live
- NS
-
- ns1.ri-solution.com
- ns2.ri-solution.com
- ns5.ri-solution.com
- MX
-
- 0 diesaat-at.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.protection.outlook.com a:dedi5228.your-server.de include:amazonses.com ip4:194.76.176.9 ip4:194.76.180.116 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_rua@baywa.de; ruf=mailto:dmarc_ruf@baywa.de; fo=1policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApyQcXsrV6GDF5h4d47mmQkQtYwZ+9/7zxa4iSfbQhR9Mbq4gbOBYbYHsLI7ne/y/BGPzxDXZy5jLYx…
selectors probed - selector1:
Certificate (current)
E8
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'nonce-cms-script' 'nonce-lottie-player' 'nonce-gtm-script' 'nonce-webcare' 'nonce-curator-script' https://*.google.com https://www.googletagmanager.com https://*.datareporter.eu https://www.google.com/recaptcha https://*.hotjar.com https://*.hotjar.io https://cdn.curator.io https://connect.facebook.net https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; style-src 'self' 'unsafe-inline' https://*.datareporter.eu https://cdn.curator.io; img-src 'self' https://*.hendriks.cloud https://*.ovl.cloud https://ad.doubleclick.net data: https://curator-assets.b-cdn.net www.googletagmanager.com https://*.tile.openstreetmap.org https://i.ytimg.com; media-src 'self' https://*.hendriks.cloud https://*.ovl.cloud https://curator-assets.b-cdn.net; connect-src 'self' https://*.hendriks.cloud https://*.datareporter.eu https://*.algolia.net https://*.execute-api.eu-west-1.amazonaws.com https://*.google-analytics.com https://*.hotja- strict-transport-security
max-age=600000