dwbf.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- sibforms.com×2
- a9.com×1
Social
Contact
Registration
- Updated
- 2007-06-20
- Name servers
-
- docks14.rzone.de.
- shades18.rzone.de.
DNS records live
- NS
-
- docks14.rzone.de
- shades18.rzone.de
- MX
-
- 10 mail2016.dwbf.de
- TXT
-
Show 6 TXT records
brevo-code:74328fab6c2b9ce2c4c6327c9734d10agoogle-site-verification=7-6kOG4U4JzEMqc0ZeLSpmdwohD4IMNri3c1UbeRo6gfacebook-domain-verification=45lsj2w4thm6q5rqi7d9pss86u8j6ugavv1kd296qdktrripk8puaumf_globalsign-domain-verification=7_Qbfetuu2njxK4JjCyUhoHWvO-v3G3UdyRA1mVezF_globalsign-domain-verification=nmonk0080ptvh7d4p15houimg5
Email authentication partial
- SPF
-
v=spf1 include:_spf.strato.com include:_spf.efm.de include:hostels.assd.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificates
Loading certificate
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src https://sibforms.com 'unsafe-inline' 'self' https://diakbb-dwbf-12.ddev.site:5173 https://jobs-diakonie.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com; base-uri 'self'; frame-src *.google.com *.google.de *.openstreetmap.org *.vimeo.com *.youtube.com *.youtube-nocookie.com https://www.google.com/maps/embed; object-src 'none'; connect-src 'self' https://sibforms.com https://jobs-diakonie.de; style-src 'self' https://sibforms.com 'report-sample'; style-src-elem 'self' https://sibforms.com 'unsafe-inline' 'report-sample'; font-src 'self' data: https://assets.sendinblue.com; worker-src blob:; report-uri https://www.dwbf.de/@http-reporting?csp=report&requestTime=1778680419996232&requestHash=75d41cf35a5440241b0b5d8df0aeb15676e3443b