highfield.de
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Updated
- 2025-11-04
- Name servers
-
- ns1.wavedns.de.
- ns2.wavedns.de.
- ns6.wavedns.com.
- ns7.wavedns.org.
DNS records live
- NS
-
- ns1.wavedns.de
- ns2.wavedns.de
- ns6.wavedns.com
- ns7.wavedns.org
- MX
-
- 0 highfield-de.mail.protection.outlook.com
- TXT
-
google-site-verification=ezFL8Jo9zt3SnKFpnwP_yI1WKnye2hmL6ta9Ld-3lmI_9hx3r1uzvok0bukmckdhsbfb89786zec42ntb8vqzqf7btmzxvbmjpl4pyvyq94cvrnss24b
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:mail.zendesk.com ip4:185.22.221.21 ip4:213.61.103.243 ip4:31.172.112.72 ip4:31.172.113.110 ip4:31.172.113.109 a:mx4.eventim.de -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=5 ; rua=mailto:dmarc@highfield.depolicy: quarantine · pct=5 - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwQu2kQHqNt2k/RjcAJsSFLRV1sgWtN+FcwNNR/KKqKP7zQ/ELP/ks+D09jp8uFTS3VZ+B+QU7Jemt2… - mail:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4kw3YBGJeaRFb606NJobeNzH+new8HRbH2A4ZqDfIgu5K2c8HAhYnFsG+/923Q1RxxJQgoVZp4JiEvh50fIWg…
selectors probed - selector1:
Certificate (current)
GeoTrust EV RSA CA G2
Expires in 213 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' https://*.highfield.de https://media-api.flockler.com https://*.cloudflarestream.com; script-src 'self' 'nonce-rays3mmkiY2teFfJF3EViYtoCBr0ZbxH1zgiEMxpbx34DAGyG9aoXQ' http: https: https://*.highfield.de https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleadservices.com https://*.googlesyndication.com https://*.doubleclick.net https://stats.g.doubleclick.net https://*.google.com https://*.consentmanager.net https://*.delivery.consentmanager.net https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://ads.tiktok.com https://*.facebook.net https://*.adform.net https://i18n https://s.pinimg.com https://ct.pinterest.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src blob: 'self' https://*.highfield.de data: https://*.google-analytics.com https://*.gstatic.com https://*.analytics.google.com https://*.googlesyndication.com https://*.doubleclick.net https://stats.g.doubleclick.ne- strict-transport-security
max-age=31536000