gedaechtniskirche-berlin.de
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Updated
- 2018-09-07
- Name servers
-
- ns1063.ui-dns.biz.
- ns1063.ui-dns.com.
- ns1063.ui-dns.de.
- ns1063.ui-dns.org.
DNS records live
- NS
-
- ns1063.ui-dns.biz
- ns1063.ui-dns.com
- ns1063.ui-dns.de
- ns1063.ui-dns.org
- MX
-
- 0 gedaechtniskircheberlin-de04c.mail.protection.outlook.com
- TXT
-
v=verifydomain MS=1455460
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.easybill-mail.de include:spf.protection.outlook.com include:spf.crsend.com include:_spf.e-pixler.network -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAypIdlQQBV5quqsgClqH4Lflms3LXAahsogdPWA40nKbmwzxUn/MwmC1HNj2VecldIH9cb1o5STEnSH… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxYnaLh2t64tN5lz+rBGmJafZf9Hdjw7V5XN1iH29NP3aomVeiPH5Qzf5xGOwrJRr6Q80lOgjTu8RjU…
selectors probed - selector1:
Certificate (current)
E8
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'none' ; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://ajax.googleapis.com https://www.google.com/ https://www.google-analytics.com https://www.googletagmanager.com https://secure.fundraisingbox.com https://widget.churchdesk.com/; img-src 'self' https://d388us03v35p3m.cloudfront.net/ https://i.ytimg.com/ https://edge.churchdesk.com/ https://i.vimeocdn.com/ https://www.google-analytics.com https://www.google.com https://www.google.de https://secure.fundraisingbox.com https://widget.churchdesk.com/; form-action 'self' https://seu2.cleverreach.com; frame-ancestors 'none'; frame-src 'self' https://secure.fundraisingbox.com https://widget.churchdesk.com/ https://www.google.com https://www.youtube-nocookie.com/ https://www.youtube.com/ https://player.vimeo.com/ https://vimeo.com/ https://my.sendinblue.com https://*.sibforms.com/ https://my.brevo.com/; font-src 'self' ; connect-src 'self' https://www.google-analyt- strict-transport-security
max-age=31536000