holidaypirates.com
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (3)
- media.holidaypirates.group×46
- image.urlaubspiraten.de×33
- images.ctfassets.net×5
Social
Registration
- Registrar
- INWX GmbH
- Created
- 2011-05-31
- Expires
- 2027-05-31 377 days left
- Updated
- 2022-05-29
- Name servers
-
- bill.ns.cloudflare.com
- elaine.ns.cloudflare.com
DNS records live
- NS
-
- bill.ns.cloudflare.com
- elaine.ns.cloudflare.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 16 TXT records
apple-domain-verification=7QtVYu8xym8Ea9Aoapple-domain-verification=ZqgrWvOjOHrK0SeKjamf-site-verification=7whYt4hvb9yvYQy2oOC3Oghj-ownership=x7V86QuUjYV0facebook-domain-verification=0nl0weu4xptxsj3pz8gbls7v2i5pgdairalo-domain-verification=mWFe7qzBR7dL0v8ZOOM_verify_vZmSHAGZTdS9h_l4iislPQanthropic-domain-verification-5nm50z=s1EYO58SGIJ49J99SIZmKucd6apple-domain-verification=dFWhcDlmp2bFiVHAui4ECEbzJ3hDsD4cQy7u60BXl0oc9Ez9fubbLwPXuQg-86B57fAV80vu6v3QVGwCOx1DM8atlassian-domain-verification=eaCAVgjKsE63zLmd9fHhyJkB2qwkvtVCv5qLgcSLw457IepM7FsmjVb7QZA1OsIAgoogle-site-verification=GkrAGy9rNJtO2N-W1ty13KI9vDgt_rUeRF0er-0TQ00MS=ms48884166google-site-verification=f8KrGWU5JTTm6DLCfwQDuzKdUye-S0AzP4lKXtKfp3Agoogle-site-verification=PF8b-UX2EqL1cUSPCEuMkXgEG6H2mjYVu32TfZk_yhUpkYgkGn5yijoWZD4NUm0ibh2bMh7JLAI8wfaiMLdVCw
Email authentication strong
- SPF
-
v=spf1 a mx ip4:144.76.44.26 ip4:176.9.83.102 ip4:148.251.15.8 ip4:176.9.107.22 ip4:54.246.87.49 ip4:144.76.44.4 ip4:144.76.44.26 ip4:144.76.44.2 ip4:136.243.24.172 ip4:178.63.53.145 ip4:144.76.44.16 ip4:37.187.31.91 include:_spf.google.com include:spf.mandrillapp.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:58f25ec441814019af57a8f438b65e3a@dmarc-reports.cloudflare.net,mailto:dmarcreports@holidaypirates.com;policy: quarantine - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests;script-src * 'unsafe-eval' 'unsafe-inline';script-src-attr 'unsafe-inline';style-src * 'unsafe-inline';img-src * data:;font-src *;connect-src * ;manifest-src data:;frame-ancestors 'self';form-action *;base-uri 'self';object-src 'none'- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
unsafe-none- cross-origin-resource-policy
cross-origin