fitundvitalplus.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- cloud.ccm19.de×1
Social
Contact
- Phone
Registration
- Updated
- 2024-03-08
- Name servers
-
- ns-cloud-a1.googledomains.com.
- ns-cloud-a2.googledomains.com.
- ns-cloud-a3.googledomains.com.
- ns-cloud-a4.googledomains.com.
DNS records live
- NS
-
- ns-cloud-a1.googledomains.com
- ns-cloud-a2.googledomains.com
- ns-cloud-a3.googledomains.com
- ns-cloud-a4.googledomains.com
- TXT
-
google-site-verification=4784lZ3zgHhX44Htt_2aHvRlpifCI4uap-9wsC02Txk
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' https://cloud.ccm19.de; script-src 'self' 'sha256-aMplebCurQOTdM044Bsy5BvHHxigUo2xiCUd3lCmYec=' blob: https://sanoa.net https://tagmanager.google.com https://*.ccm19.de https://*.youtube.com https://*.googletagmanager.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.ccm19.de https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://sanoa.net; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://sanoa.net https://www.polyshop.com https://*.youtube.com; style-src-elem 'self' https://fonts.bunny.net/css 'unsafe-inline' https://fonts.bunny.net https://fonts.googleapis.com https://www.googletagmanager.com https://sanoa.net https://*.ccm19.de 'report-sample'; script-src-elem 'self' 'sha256-aMplebCurQOTdM044Bsy5BvHHxigUo2xiCUd3lCmYec=' blob: https://sanoa.net https://tagmanager.google.com https://*.ccm19.de https://*.youtube.c- strict-transport-security
max-age=31536000; includeSubDomains; preload- content-security-policy-report-only
default-src 'self' https://cloud.ccm19.de; script-src 'self' 'sha256-aMplebCurQOTdM044Bsy5BvHHxigUo2xiCUd3lCmYec=' blob: https://sanoa.net https://tagmanager.google.com https://*.ccm19.de https://*.youtube.com https://*.googletagmanager.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.ccm19.de https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://sanoa.net; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://sanoa.net https://www.polyshop.com https://*.youtube.com; style-src-elem 'self' https://fonts.bunny.net/css 'unsafe-inline' https://fonts.bunny.net https://fonts.googleapis.com https://www.googletagmanager.com https://sanoa.net https://*.ccm19.de 'report-sample'; script-src-elem 'self' 'sha256-aMplebCurQOTdM044Bsy5BvHHxigUo2xiCUd3lCmYec=' blob: https://sanoa.net https://tagmanager.google.com https://*.ccm19.de https://*.youtube.c