dw-connect.org
HTML metadata
DNS records live
- NS
-
- dns.mahamudra.de
- dns.mahamudra.info
- MX
-
- 10 mx.mahamudra.de
- 20 mail.mahamudra.de
- 30 mail2.mahamudra.de
Email authentication strong
- SPF
-
v=spf1 mx a:registration.dwbn.org a:gitlab.dwbn.org a:checkmk.dwbn.org a:dw-connect.org a:www.diamondway-buddhism.org a:mila.mahamudra.de -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- permissions-policy
microphone=(self "https://*.dwbn.org" "https://*.dw-connect.org" "https://dw-connect.org"), geolocation=(self "https://*.dwbn.org" "https://*.dw-connect.org" "https://dw-connect.org"), camera=(self "https://*.dwbn.org" "https://*.dw-connect.org" "https://dw-connect.org"), usb=(), web-share=(self "https://*.dwbn.org" "https://*.dw-connect.org" "https://dw-connect.org")- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.dwbn.org https://*.mahamudra-holders.org https://*.budismo-malaga.org https://*.dw-connect.org https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com https://js.stripe.com https://*.google.com https://jwpsrv.com https://ssl.p.jwpcdn.com https://*.mapbox.com https://stamen-tiles.a.ssl.fastly.net https://tazman.co.il https://*.buddhism.org.il https://*.diamondway.org https://outlook.office365.com https://forms.office.com https://cdn.jsdelivr.net/npm/world-atlas@2/countries-110m.json https://*.hereapi.com https://vote.easypolls.net https://*.genially.com blob: ; style-src 'self' 'unsafe-inline' ; img-src data: blob: 'self' https: ; frame-ancestors 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload