ewh.ch
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 3.5.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- hubspot.etrex.dev×11
- ik.imagekit.io×11
- hubspot-no-cache-eu1-prod.s3.amazonaws.com×3
- www.googletagmanager.com×2
- 7052064.fs1.hubspotusercontent-na1.net×1
Social
DNS records live
- NS
-
- ns-1451.awsdns-53.org
- ns-1775.awsdns-29.co.uk
- ns-341.awsdns-42.com
- ns-570.awsdns-07.net
- MX
-
- 0 ewh-ch.mail.protection.outlook.com
- TXT
-
hibp-verify=dweb_z9tfj4myr04ezjecj1dmua8x
- Verified for
-
- Apple
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf-eu.emailsignatures365.com include:spf.voipgateway.org ip4:104.40.243.199 include:_spf.psm.knowbe4.com include:4594078.spf06.hubspotemail.net include:fdspfus.freshemail.io include:fl1.li -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@swissitsecurity.uriports.com; ruf=mailto:dmarc@swissitsecurity.uriports.com; fo=1:d:spolicy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCS4Zg4MsdPqa/bEgsv4kQiav4nogt4GXdccp+YcxIHJRsg2J6pNr4ZWnWS4ZzR0Y3ALncQuG8NE9AmedDYTW… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvYCuSZxbS+keiYSpM8WHQeFhWOnF1KtSQvV+t1EUTmCwDk9KCtTHZIDQbJ6S1xWl4TatM3evur/3u6JzAL… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq1NR0q0DlNcke+Cm1Enx/pungVv4R2KEvUJIZl7IBJMkhV8tqfOtW/tLWvpqNRhELXr3mV9cq6BC7GP3S/… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
R13
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing content type protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=self, geolocation=self, microphone=self, payment=self- content-security-policy
default-src https: 'unsafe-inline'; script-src https: 'unsafe-inline'; style-src-elem https: 'unsafe-inline'; img-src https: data:;; upgrade-insecure-requests- strict-transport-security
max-age=31536000
Links to (5)
Linked from (3)
- vdn.ch×1
- nis.ch×1
- lokalerstrom.ch×1