geld-fuer-eauto.de
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
Social
Registration
- Updated
- 2021-04-11
- Name servers
-
- iris.ns.cloudflare.com.
- josh.ns.cloudflare.com.
DNS records live
- NS
-
- iris.ns.cloudflare.com
- josh.ns.cloudflare.com
- MX
-
Show 6 MX records
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 15 sxkxqlhazu3kdlm4ghkaku4u5bxc2uvbx4l5xgoviptlmzx7nlva.mx-verification.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
hibp-verify=dweb_vpyo29nnys548561jb7zic57klaviyo-site-verification=Ycd5Ha
- Verified for
-
- Anthropic
- Mailgun
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:116737df0efe474dbc4024391fe6305e@dmarc-reports.cloudflare.netpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 23 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' *; style-src 'self' 'unsafe-inline' *; frame-src 'self' *; img-src 'self' data: blob: *; connect-src 'self' *; object-src 'none'; base-uri 'self'; form-action 'self' https://www.googletagmanager.com https://www.facebook.com; frame-ancestors 'self' *.geld-fuer-eauto.de *.zusammenstromen.de; upgrade-insecure-requests;- strict-transport-security
max-age=63072000; includeSubDomains; preload