esf-bw.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- t53ddb402.emailsys1a.net×1
Registration
- Updated
- 2024-07-24
- Name servers
-
- ns1.your-server.de.
- ns3.second-ns.de.
- ns.second-ns.com.
DNS records live
- NS
-
- ns.second-ns.com
- ns1.your-server.de
- ns3.second-ns.de
- MX
-
- 10 mail.your-server.de
- TXT
-
v=spf1 a mx ip4:162.55.254.103 ip6:2a01:4f8:1061:134e::2 ip4:78.46.155.226 ~all
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-Ulaa-0cG9N8lynGN83ghmb7HBsCYV4oM5dbCwUtB9A9N0sDPePaFiw' https://stats.esf-bw.de/ 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://stats.esf-bw.de/; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com; style-src-elem 'self' 'nonce-Ulaa-0cG9N8lynGN83ghmb7HBsCYV4oM5dbCwUtB9A9N0sDPePaFiw' 'report-sample'; connect-src 'self' https://t53ddb402.emailsys1a.net/ https://stats.esf-bw.de/; script-src-elem 'self' 'nonce-Ulaa-0cG9N8lynGN83ghmb7HBsCYV4oM5dbCwUtB9A9N0sDPePaFiw' https://t53ddb402.emailsys1a.net/ https://stats.esf-bw.de/ 'report-sample'; report-uri https://www.esf-bw.de/@http-reporting?csp=report&requestTime=1777978770517778&requestHash=428f2dd8285748d3cce4e7a83da3e7983a4fc089