geschichtsboden.de
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
Social
Registration
- Updated
- 2020-05-27
- Name servers
-
- dns.dns1.de.
- dns.dns2.de.
- dns.dns3.de.
- dns.dns4.de.
DNS records live
- NS
-
- dns.dns1.de
- dns.dns2.de
- dns.dns3.de
- dns.dns4.de
- MX
-
- 0 mail.leipfinger-bader.de
- TXT
-
google-site-verification=nUh56pA_FxO3PWTLMavQfjhjXtKGfukV5CK6EogYLqg
Email authentication weak
- SPF
-
v=spf1 mx ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 49 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), gyroscope=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.google-analytics.com *.googletagmanager.com *.facebook.net *.cloudflare.com *.jsdelivr.net *.datatables.net leanbe.ai *.announcekit.app *.helpscout.net *.youtube.com *.vimeo.com *.googleapis.com *.hsforms.com *.hsadspixel.net *.hs-analytics.net *.hscollectedforms.net *.hsforms.net *.hs-scripts.com *.hs-banner.com https://unpkg.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.cloudflare.com leanbe.ai *.fonts.net *.myfonts.net *.datatables.net; img-src 'self' data: *.hubspotusercontent40.net *.facebook.com *.hsforms.net leanbe.ai *.w.org *.vimeocdn.com *.borlabs.io *.google-analytics.com *.ytimg.com *.hubspot.com *.gravatar.com *.google.de *.google.com *.hsforms.com; font-src 'self' data: *.gstatic.com; connect-src 'self' *.hubspot.com *.hubapi.com *.hsforms.com *.google-analytics.com *.cloudfront.net leanbe.ai *.hscollectedforms.net; media-src 'self'; object-src 'none'; frame-src 'self' *.hsforms- strict-transport-security
max-age=31536000; includeSubDomains; preload