hochtief.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (3)
- charts3.equitystory.com×1
- static.etracker.com×1
- www.hochtief.com×1
Social
Contact
- Phone
Registration
- Updated
- 2022-01-12
- Name servers
-
- x.ns.joker.com.
- y.ns.joker.com.
- z.ns.joker.com.
DNS records live
- NS
-
- x.ns.joker.com
- y.ns.joker.com
- z.ns.joker.com
- MX
-
- 0 hochtief-de.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
atlassian-domain-verification=TbN7MenUyVeSGTqrtGPC89GlD2XA5fKatT8GZsNe6vNCxaHxrjfvpmynIfBl9I3ReID/Xz17/S8HL4lzc02LnR6KnKRzqzaZTPPap4pXYldNskv5JwykOSRNsa4BJLnvmkYlQUH1zER/Kvyi1Nk7Lw==apple-domain-verification=ElVBm8Y36Riqw16kknowbe4-site-verification=31e048ee3866263191cb829f1ee3a099autodesk-domain-verification=zbxfclmqju-kYoUkuoii
Email authentication strong
- SPF
-
v=spf1 include:spf1.hochtief.de include:spf2.hochtief.de -allstrict (-all) - DMARC
-
v=DMARC1; p=reject;policy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC/FmXe4dz4t98Fe5ubN2TqerqjYdWenbeEEf7dFz5F1DMww/QXyk1QgrcAx2cDCZ5JjZFIIxIhIVb3NhjJlI… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvCIBXiYj8pjGHHqCm7zEiGnG9JuyITFcv353ydanNTPkpjoXijBDH9D6R37sUUCrMzOJbL1f49Z/A3… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8tifNscJXN4sLFuxbsx7tEeFu8047gu+MWVYqL6xbFTKocbQeB/Eq1AruEZ0iLquskbTb2hseD+H/K5lqP… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxXW9SWi7wzB8VqVcv1ycGaTgzbMF6T1Ll1qhNaexiKxct3iyou+esQdsaB5QeFQtSi8e57RDvH5ADTqUPW…
selectors probed - selector1:
Certificate (current)
TeleSec Business TLS-CA 2022
Expires in 295 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: http://app.flipbase.com http://apply.indeed.com http://cdn-ui.lumessetalentlink.com http://charts3.equitystory.com code.etracker.com http://code.jquery.com emea3.recruitmentplatform.com gateway.zscaler.net gateway.zscalertwo.net gateway.zscloud.net http://github.com playout.3qsdn.com http://p.typekit.net static.etracker.com static.lumessetalentlink.com http://use.typekit.net http://www.etracker.de http://www.hochtief.de http://www.take-it-media.com; connect-src 'self' https://www.hochtief.de https://charts3.equitystory.com https://www.etracker.de https://emea3.recruitmentplatform.com; frame-ancestors 'self' https://*.etracker.com;- strict-transport-security
max-age=31536000