heraeus-precious-metals.com
HTML metadata
Technology
- Server
- hide
- CMS
- Nuxt
Third-party hosts loaded (1)
- www.heraeus-precious-metals.cn×1
Social
Registration
- Registrar
- InterNetX GmbH
- Created
- 2009-11-11
- Expires
- 2026-11-11 174 days left
- Updated
- 2025-11-12
- Name servers
-
- ns.global.adacor.net
- ns5.adacor.net
DNS records live
- NS
-
- ns.global.adacor.net
- ns5.adacor.net
- MX
-
- 10 mxa-00125a01.gslb.pphosted.com
- 10 mxb-00125a01.gslb.pphosted.com
- Verified for
-
- Dynamics 365
Email authentication strong
- SPF
-
v=spf1 mx -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 149 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- missing Content Security Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), display-capture=(), fullscreen=(*), geolocation=(), microphone=(), bluetooth=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=(), picture-in-picture=(*), autoplay=(*), encrypted-media=(*)- x-content-type-options
nosniff- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
unsafe-none- cross-origin-resource-policy
cross-origin- content-security-policy-report-only
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.youtube.com *.ytimg.com *.wistia.com *.wistia.net *.qq.com *.gtimg.cn *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com snap.licdn.com *.facebook.com *.facebook.net connect.facebook.net *.dynamics.com *.microsoftonline.com *.friendlycaptcha.com friendlycaptcha.com *.heraeus-web.com *.cookiefirst.com; script-src-elem 'self' 'unsafe-inline' *.youtube.com *.wistia.com *.wistia.net *.qq.com *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.friendlycaptcha.com *.sociablekit.com localtesting.com *.azureedge.net *.maptiler.com *.licdn.com *.heraeus-web.com; style-src 'self' 'unsafe-inline' *.wistia.com *.wistia.net *.friendlycaptcha.com *.sociablekit.com *.cookiefirst.com *.heraeus-web.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com *.heraeus