erftverband.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (3)
- cdn.jsdelivr.net×4
- code.jquery.com×2
- cdnjs.cloudflare.com×1
Social
Contact
- Phone
Registration
- Updated
- 2014-02-07
- Name servers
-
- ns1.first-ns.de.
- robotns2.second-ns.de.
- robotns3.second-ns.com.
DNS records live
- NS
-
- ns1.first-ns.de
- robotns2.second-ns.de
- robotns3.second-ns.com
- MX
-
- 10 server.erftverband.de
- TXT
-
Show 4 TXT records
MS=326700D2B03C2A5FE0BB273FF11C494D5EF94859MS=ms64356514apple-domain-verification=beDQn38V175Me5Uqcisco-ci-domain-verification=2c59256f18d34fed8357d3d29d2cb50481ca8051c67daf965666bb6f1588c867
Email authentication partial
- SPF
-
v=spf1 a mx ip4:49.12.126.224 ip4:144.76.110.195 -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:postmaster@erftverband.de;ruf=mailto:postmaster@erftverband.de;ri=86400;aspf=r;adkim=r;fo=0policy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Sectigo RSA Domain Validation Secure Server CA
Expires in 4 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src *; img-src 'self' data: https://webgis.erftverband.de https://www.dwd.de https://secure.gravatar.com https://ps.w.org; font-src 'self' data:; connect-src 'self' https://cdn.jsdelivr.net https://webgis.erftverband.de; style-src 'self' 'unsafe-inline' https://webgis.erftverband.de; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://webgis.erftverband.de ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://webgis.erftverband.de; script-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://webgis.erftverband.de https://www.vmp-rheinland.de; object-src 'none'; worker-src 'self' blob: https://webgis.erftverband.de; frame-src 'self' https://webgis.erftverband.de https://www.youtube.com; frame-ancestors 'self'; form-action 'self' ; base-uri 'self';- strict-transport-security
max-age=31536000; includeSubDomains; preload