hetsl.ch
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- kit.fontawesome.com×2
- maps.googleapis.com×2
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- nsany1.infomaniak.com
- nsany2.infomaniak.com
- MX
-
- 0 hetsl-ch.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
have-i-been-pwned-verification=566bf9385a68448faa7df687edee99d3atlassian-sending-domain-verification=08dd3b63-ab02-4e03-96b2-2397561631dbhubspot-developer-verification=ODU2YzkzNzctY2U3Zi00NGMyLTg0MWItNGJjNzkzYmFmNTQ15V7vfcYN0HM7j+MSXjCknEDxt4vsOh58HE8fe+Qc4rM=
- Verified for
-
- Adobe
- Apple
- Atlassian
- Meta
- Microsoft 365
- Stripe
Email authentication strong
- SPF
-
v=spf1 a mx ip4:193.134.222.11 inclv=spf1 a mx ip4:193.134.222.11 include:spf.mtasv.net include:spf.protection.outlook.com include:spf.hefr.ch include:servers.mcsv.net include:spf.mandrillapp.com include:49000560.spf07.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=quarantine;sp=quarantine;adkim=s;aspf=r;pct=100;rua=mailto:hetsl-d@dmarc.report-uri.com,mailto:re+ae23889f5968@inbound.dmarcdigests.com,mailto:jfj4mh75ae@rua.powerdmarc.com;ruf=mailto:hetsl-d@dmarc.report-uri.com,mailto:jfj4mh75ae@ruf.powerdmarc.com;fo=0:1:d:spolicy: quarantine · sp=quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6iAgi9EOjQIe/7hB6BkfjyaBoUGhiqiHLFJm9QAytntVgE5PJlXGqIIJ4k+Xc86JyimBq09P1rL/bn… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
GlobalSign GCC R3 DV TLS CA 2020
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; connect-src 'self' https://www.facebook.com https://ka-p.fontawesome.com https://pagead2.googlesyndication.com https://www.googleadservices.com https://analytics.google.com https://region1.analytics.google.com https://www.google-analytics.com https://form-assets.mailchimp.com https://stats.g.doubleclick.net https://www.google.be https://www.google.ch https://www.google.com https://www.google.fr https://www.google.nl https://www.google.pt https://www.google.com https://*.intuit.com https://*.googleapis.com https://*.axept.io https://cdn.datatables.net; default-src 'self'; font-src 'self' data: https://use.fontawesome.com https://fonts.gstatic.com https://fonts.axept.io https://cdn.smassets.net; frame-src 'self' https://www.dailymotion.com https://geo.dailymotion.com https://e.issuu.com https://hetsl.wufoo.com https://player.vimeo.com https://www.googletagmanager.com https://www.youtube-nocookie.com https://td.doubleclick.net https://outlook.office365.com https://tube.sw- strict-transport-security
max-age=63072000; includeSubDomains; preload