hef-rof.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- sdp-knowledge.cluster02.viind.io×1
Social
Contact
- Phone
Registration
- Updated
- 2020-09-30
- Name servers
-
- dns10.nethinks.com.
- dns9.nethinks.com.
DNS records live
- NS
-
- dns10.nethinks.com
- dns9.nethinks.com
- MX
-
- 10 smail.hef-rof.de
- TXT
-
apple-domain-verification=shA90I33gpRuDc3Rgoogle-site-verification=RQynzejnAHfW7VwALgiv-GfsAcLO9OxiK4X3nVroUIUgoogle-site-verification=NWrMo4bs1ulUfF0L3MYiQaXSF4kjkyO9H5YmejZcERI
Email authentication partial
- SPF
-
v=spf1 +a +mx +ip4:212.218.193.6 +ip4:195.226.81.0/24 +ip4:62.156.249.0/24 +ip4:80.69.206.32/27 +ip4:80.69.206.64/27 +ip4:80.69.206.96/27 +ip4:80.69.202.112/28 +ip4:80.69.201.0/24 +a:smail.hef-rof.de +include:ekom21.de -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;adkim=s;aspf=s;pct=100;fo=1;rf=afrf;ri=604800;ruf=mailto:dmarc@hef-rof.depolicy: none (monitoring only) · sp=none - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqsuxbpZpOjqj0zUbXfMklZI4DdGv0rDYJ7uWQ6KsaVYFPQXixbbUHOrnBeeLlSmuwCToi4clFWf8Ou…
selectors probed - default:
Certificate (current)
Sectigo RSA Domain Validation Secure Server CA
Expires in 2 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; child-src 'self' blob: https://kb.ionas.de/; connect-src 'self' https: *.cluster02.viind.io *.viind.io https://*.egovernor.de/ https://api.service-digitale-verwaltung.de https://matomo.hef-rof.de wss:; font-src 'self' data: *.viind.com *.viind.io; frame-ancestors 'self' https://matomo.hef-rof.de https://www.hef-rof.de; frame-src 'self' https://beteiligungsportal.hessen.de https://iam.chamaeleon.de/ https://matomo.hef-rof.de; form-action 'self'; img-src 'self' data: https://*.egovernor.de/ https://api.service-digitale-verwaltung.de https://bewerber-pro5.ekom21.de https://matomo.hef-rof.de https://tiles.chamaeleon.de https://www.hef-rof.de; manifest-src 'self'; media-src 'self'; object-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.viind.com *.viind.io https://api.service-digitale-verwaltung.de https://matomo.hef-rof.de statistik.cms21.de; script-src-elem 'self' https: 'unsafe-inline' https://matomo.hef-rof.de; script-src-attr 'self' https: 'unsafe-inli- strict-transport-security
max-age=31536000