hochschule-bundesbank.de
HTML metadata
Technology
- CMS
- Gatsby
Contact
- Phone
Registration
- Updated
- 2022-02-28
- Name servers
-
- ns1-any.123ns.eu.
- ns3-any.123ns.eu.
- ns4-any.123ns.de.
DNS records live
- NS
-
- ns1-any.123ns.eu
- ns3-any.123ns.eu
- ns4-any.123ns.de
- MX
-
- 10 cluster4.eu.messagelabs.com
- 20 cluster4a.eu.messagelabs.com
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; pct=100; rua=mailto:dmarc-reports@bundesbank.de; ruf=mailto:dmarc-reports@bundesbank.de; fo=1; ri=86400; adkim=s; aspf=s; rf=afrf;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Telekom Security ServerID OV Class 2 CA
Expires in 139 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
document-domain=(), usb=(), oversized-images=(), execution-while-out-of-viewport=(), battery=(), xr-spatial-tracking=(), midi=(), display-capture=(), wake-lock=(), accelerometer=(), legacy-image-formats=(), payment=(), camera=(), microphone=(), publickey-credentials-get=(), navigation-override=(), magnetometer=(), sync-xhr=*, layout-animations=(), execution-while-not-rendered=(), autoplay=*, gyroscope=(), screen-wake-lock=(), ambient-light-sensor=(), fullscreen=*, picture-in-picture=(), encrypted-media=(), vr=(), web-share=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
connect-src 'self' data: https://usage-stats.bundesbank.de https://api.statistiken.bundesbank.de https://code.highcharts.com https://bundesbank-http.mescdn.com https://*.slidesync.com https://api.friendlycaptcha.com https://eu-api.friendlycaptcha.eu https://api.stage.bio/; style-src 'self' blob: 'unsafe-inline' https://usage-stats.bundesbank.de/ https://assets.slidesync.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://usage-stats.bundesbank.de https://assets.slidesync.com https://d3js.org https://dashboard.stage.bio; frame-src 'self' https://slidesync.com https://www.youtube-nocookie.com https://www.podcaster.de https://usage-stats.bundesbank.de/ https://login.bundesbank.de/ https://allplayces.de/ https://chatthing.ai https://eu.frcapi.com/; media-src 'self' https://*.slidesync.com https://bundesbank-http.mescdn.com https://cdn.stage.bio blob: data:; frame-ancestors 'self' https://usage-stats.bundesbank.de/ https://intranet.inet.bundesbank.de/ https://intranet-a.inet.- strict-transport-security
max-age=31536000