gaissmayer.de
HTML metadata
Technology
- CDN
- Cloudflare
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (1)
- consent.cookiebot.com×1
Social
Contact
- Phone
Registration
- Updated
- 2019-12-16
- Name servers
-
- chip.ns.cloudflare.com.
- venus.ns.cloudflare.com.
DNS records live
- NS
-
- chip.ns.cloudflare.com
- venus.ns.cloudflare.com
- MX
-
- 10 mx10.continum.net
- 20 mx10.continum.net
- TXT
-
Show 5 TXT records
facebook-domain-verification=lr8ugxepcbobgzvz6inruw59gokce6mistral-domain-verification=da3d7e47fd2c0a85d9da152432877517e9dccec4zone-ownership-verification-c2e1316a9371c4d50e2a6dfaca1996e810f6d27660fbee462fb8db6cd8386d13MS=911A3633FB2A8C57BE7E6CAD8B23F8B95088B05Efacebook-domain-verification=f490z1bdd2zvjn584h00dolnrsghie
Email authentication weak
- SPF
-
v=spf1 a mx a:mail.continum.net a:out.gaissmayer.de ip4:80.72.131.24/29 ip4:24.134.170.81 ip4:93.90.204.190 ip4:87.106.17.114 include:_spf.perfora.net include:_spf.kundenserver.de include:spf.crsend.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https://* 'self' 'unsafe-eval' 'unsafe-inline' https://*.cookiebot.com https://*.regiondo.net https://*.stripe.com https://*.stripe.network; object-src 'none'; img-src 'self' https://*.gaissmayer.de https://*.datafarm.de https://*.cookiebot.com https://*.regiondo.net https://*.stripe.com data:;- strict-transport-security
max-age=15768000