gambach.ch
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Contact
- Phone
- Address
- Avenue Louis-Weck-Reynold 9, 1700, Fribourg, FR, Suisse
DNS records live
- NS
-
- dns1.bluehemmer.ch
- dns2.bluehemmer.ch
- MX
-
- 10 mx2.spamvor.com
- 5 mx1.spamvor.com
Email authentication strong
- SPF
-
v=spf1 include:_spf.ch-dns.net include:spf.infomaniak.ch +mx +a -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
-
- default:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmQB04Ki1nAna+leJcOosx5LkW/JgjeehdoBzUPO89dDbmEwGWXLucrAy5E8i2i5/kTVEgZZs+UgI6IaHEtaKx…
selectors probed - default:
Certificate (current)
R13
Expires in 86 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' swapi.dev *.g.doubleclick.net *.google-analytics.com *.gstatic.com *.googletagmanager.com; script-src 'self' 'unsafe-inline' *.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gstatic.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gstatic.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.theodia.org; style-src 'self' swapi.dev *.g.doubleclick.net *.google-analytics.com *.gstatic.com *.googletagmanager.com 'unsafe-inline' data: *.googleapis.com *.theodia.org 'report-sample'; report-uri https://gambach.ch/@http-reporting?csp=report&requestTime=1780216100128096&requestHash=0aef67b26210afc2b9a2019643c9876172011af5