grassau.com
HTML metadata
Registration
- Registrar
- Vautron Rechenzentrum AG
- Created
- 1998-12-04
- Expires
- 2026-12-03 197 days left
- Updated
- 2025-12-04
- Name servers
-
- ns1.nameservercade.de
- ns2.nameservercade.de
DNS records live
- NS
-
- ns1.nameservercade.de
- ns2.nameservercade.de
- MX
-
- 100 fortimail.cadeprovider.de
- TXT
-
abuseipdb-verification=vUZ17BeDatlassian-sending-domain-verification=ed720657-bebd-4adf-a5c2-48452cc6bf73MS=827C1039426C4F3D773240B5DDBCE5B9F4F86380
Email authentication weak
- SPF
-
v=spf1 a:system245.newslettersystem.eu include:solutionshosted.de include:spf.protection.outlook.com include:_spf.atlassian.net -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCW2l2nmlc7A9/3nE+uSOWsqeF3tMQPQQh39Isyloax3QOzS2c/a1VxCS1oHZMiowAXcNH9bBrmMAFtbQeTV1… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3J+afgOz2jQy6CItyuf7oy4zX2RvF+477TVyRWnPiahd4RWjsuaEaifrq6uyxG7D9QAlOpqRgYKaiH…
selectors probed - selector1:
Certificate (current)
E7
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' grassau.com *.grassau.com ; script-src 'self' 'nonce-avrge3i5dPvJNf9UBzMt' ; img-src 'self' data: grassau.com *.grassau.com https://webcam.solutionshosted.de https://schiffswiki.de https://*.tile.openstreetmap.de *.amazonaws.com ; style-src 'self' 'nonce-avrge3i5dPvJNf9UBzMt'; form-action 'none'; manifest-src 'self' data: ; frame-src https://webcam.solutionshosted.de https://www.schiffswiki.de https://cm.livespotting.com https://cam.grassau.com https://tiles.openfreemap.org ; connect-src https://api2.grassau.com https://tiles.openfreemap.org ; worker-src blob:- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-resource-policy
cross-origin