exigo.ch
HTML metadata
Technology
- Server
- generic
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- unpkg.com×2
- fonts.googleapis.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.exigo.ch
- dns2.exigo.ch
- MX
-
- 10 avas-in1.exigo.ch
- 10 avas-in2.exigo.ch
- TXT
-
_173vdxo4zz7g6nm00a63j6duf79jtb8
Email authentication partial
- SPF
-
v=spf1 ip4:193.93.20.0/26 ip4:193.93.21.15 ip4:193.93.21.238 ip4:193.93.21.236 ip4:213.174.45.67/24 ip4:109.234.108.151 ip4:109.234.108.152 include:_spf.mailrelay.rrpproxy.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:ops@exigo.ch; aspf=s; f0=s;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 103 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(), gyroscope=(), keyboard-map=(self), magnetometer=(), microphone=(), midi=(), navigation-override=(self), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(self), clipboard-write=(self), gamepad=(), speaker-selection=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' data:; script-src 'self' matomo.exigo.ch piwik.exigo.ch 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com data:; script-src-elem 'self' https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js https://unpkg.com/swiper@8/swiper-bundle.min.js https://snap.licdn.com https://px.ads.linkedin.com https://www.googletagmanager.com matomo.exigo.ch piwik.exigo.ch 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; style-src-elem 'self' https://unpkg.com/swiper@8/swiper-bundle.min.css https://fonts.googleapis.com/css 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; img-src 'self' https://www.linkedin.com/px https://px.ads.linkedin.com https://www.google.ch data: www.wc3.org; connect-src 'self' https://www.google.ch/ads/ga-audiences https://px.ads.linkedin.com https://region1.analytics.google.com https://stats.g.doubleclick.net matomo.exigo.ch piwik.exigo.ch; media-src 'self' youtube; object-src 'self'; prefetch-src- strict-transport-security
max-age=31536000; includeSubDomains