gv-bayern.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Social
Registration
- Updated
- 2021-11-17
- Name servers
-
- ns.gv-bayern.de.
- pns.dtag.de.
- secondary006.dtag.net.
DNS records live
- NS
-
- ns.gv-bayern.de
- pns.dtag.de
- secondary006.dtag.net
- MX
-
- 10 mail.gv-bayern.de
- TXT
-
v=spf1 mx ip4:80.155.1.6 ip4:62.55.182.68 ip4:80.150.188.169 include:spf.mailjet.com include:spf.nl2go.com ip4:78.46.1.116 ip6:2a01:4f8:d0a:26d7::2 -all_telesec-domain-validation=336798_2024-09-18_Lkji0HEpoxv68FCOVlaNWIgrr5HPyTgtwiOwcfHZdNlmr5H4SU
- Verified for
-
- Adobe
- Microsoft 365
Certificate (current)
Telekom Security ServerID OV Class 2 CA
Expires in 108 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://mika.gv-bayern.de; frame-src https://app.gv-bayern.de https://mika.gv-bayern.de https://www.gv-bayern.de https://log.gv-bayern.de https://www.youtube-nocookie.com https://player.vimeo.com https://slidesync.com; default-src 'self' blob: data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' slidesync.com cdn.plyr.io player.vimeo.com i.ytimg.com i.vimeocdn.com www.youtube.com www.youtube-nocookie.com cdn.cookiehub.eu cookiehub.net ds.cookiehub.net dash.cookiehub.com browser-update.org www.gv-bayern.de log.gv-bayern.de pbs.twimg.com; media-src 'self' googlevideo.com noembed.com; connect-src 'self' api.friendlycaptcha.com eu-api.friendlycaptcha.eu consent-eu.cookiehub.net cookiehub.net ds.cookiehub.net dash.cookiehub.com noembed.com cdn.plyr.io *.gv-bayern.de cdn.cookiehub.eu; script-src blob: 'self' 'unsafe-inline' 'unsafe-eval' player.vimeo.com www.youtube.com cdn.cookiehub.eu cookiehub.net syndication.twitter.com dash.cookiehub.com assets.slidesync.com www.gv- strict-transport-security
max-age=31536000; includeSubDomains