gesundheitsbad.de
HTML metadata
Technology
- Server
- LEIBOLD
- CMS
- Gatsby
Third-party hosts loaded (1)
- gesundheitszentrum-federsee.de×3
Social
Contact
- Phone
Registration
- Updated
- 2022-10-31
- Name servers
-
- ns2.dnsresolve.net.
- ns.indas.de.
DNS records live
- NS
-
- ns.indas.de
- ns2.dnsresolve.net
- MX
-
- 10 smtp.gesundheitszentrum-federsee.de
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.indas.de include:spfserver.auctores.de -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuM0/RyUN8ctxBOvUwIFey815AJa4G+IlBDF6icCEroGNKBSroSpIe6d+/ohJ4WT0cnMK/kPNpye6LjpAj/… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC0/pMCWcZpIWbUOgn2atofIAUC9+nn34tOgC4otjrNWgfKYiiPbUB1RpRPilizxXK9NIm3Z9BEFgCK4HZFxQ05Ys…
selectors probed - s1:
Certificate (current)
E8
Expires in 25 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
deny- permissions-policy
camera=self, microphone=(), geolocation=(), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' ;base-uri 'none';object-src 'none';form-action 'self' ;frame-ancestors 'self' ;connect-src 'self' www.google-analytics.com *.google-analytics.com *.analytics.google.com *.dirs21.de https://js-sdk.dirs21.de;img-src 'self' gesundheitsbad.de *.google-analytics.com *.analytics.google.com www.google-analytics.com *.google-analytics.com *.analytics.google.com data: connect.protel.net cloud02-7c83ec0.prod.1000grad.de gesundheitszentrum-federsee.de badstube-badbuchau.de gesundheitsbad.de schlossklinik-badbuchau.de federseeklinik.de adelindistherme.de *.holidaycheck.de;media-src 'self' ;script-src 'self' 'strict-dynamic' 'nonce-aor5g4kdjre9g3b7nq4a73v7l6t' www.google-analytics.com *.google-analytics.com *.analytics.google.com connect.protel.net cloud02-7c83ec0.prod.1000grad.de https://js-sdk.dirs21.de *.dirs21.de *.holidaycheck.de 'unsafe-inline' 'unsafe-eval';style-src 'self' 'unsafe-inline' connect.protel.net cloud02-7c83ec0.prod.1000grad.de *.dirs21.de https://v- strict-transport-security
max-age=31536000