dkrz.de
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Updated
- 2023-04-12
- Name servers
-
- dns-2.dfn.de.
- ns1.dkrz.de.
- ns2.dkrz.de.
DNS records live
- NS
-
- dns-2.dfn.de
- ns1.dkrz.de
- ns2.dkrz.de
- MX
-
- 10 mailin3.dkrz.de
- 10 mailin4.dkrz.de
- TXT
-
MS=D2B141813E6964B6E56B6DA955395FAB30A90E0Fgoogle-site-verification=jhhv8KwxuYH97tJUAzbUyoOGe6F7wJO3UpZ07gwkpdI
Email authentication weak
- SPF
-
v=spf1 +a:mailhost.dkrz.de +a:mailext-ha.dkrz.de -allstrict (-all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtYTOAXnBG0UBwUUAdozxZkcAAAL+lDd4V7iOMRZyrJxAdhSkImEChl0Xe1gU4LbqCVSqWqIPvaHjMeNFO3+…
selectors probed - default:
Certificate (current)
GEANT TLS RSA 1
Expires in 121 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src data: 'self' https://www.youtube-nocookie.com/ https://www.youtube.com/ https://matomo.dkrz.de https://mms.dkrz.de; img-src data: 'self' https://wdcc-status.dkrz.de/ https://matomo.dkrz.de https://mms.dkrz.de/; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://matomo.dkrz.de; connect-src 'self' https://matomo.dkrz.de; frame-ancestors 'self';- strict-transport-security
max-age=63072000