ibaw.ch
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- cdn.cookielaw.org×2
- miducabulalicdnprd.z1.web.core.windows.net×2
- www.googletagmanager.com×2
- maps.googleapis.com×1
Social
DNS records live
- NS
-
- migze100.migros.ch
- migze104.migros.ch
- ns3.migros.ch
- MX
-
- 10 ibaw-ch.mail.protection.outlook.com
- TXT
-
dtm-domain-verification=mE8LTcfaBT7Cw2nzUPoY5wzNto7iRICGUHMmF1qJGyA
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:194.126.200.0/24 ip4:149.126.0.0/21 include:spf.protection.outlook.com include:servers.mcsv.net include:mspf.migros.ch include:spf.umantis.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;rua=mailto:dmarc.report@migros.ch;ruf=mailto:dmarc.forensic@migros.ch;adkim=r;aspf=r;fo=1;rf=afrf;pct=100;ri=86400policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx1bY44rgpE02HdpvR3oHWWm1gHfhtiFrC8TQI4I9318F12+BJPs6hc7N60HowVAmM6AtnRIr6xSxWF… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - selector1:
Certificate (current)
R12
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src *.adform.net *.clarity.ms *.easy.education.ch *.ecole-club.ch *.facebook.com *.google.com *.gstatic.com *.hotjar.com *.ibaw.ch *.jsdelivr.net *.klubschule.ch *.klubschule-pro.ch *.licdn.com *.linkedin.com *.logrocket.com *.logrocket.io *.lrkt-in.com *.microsoft.com *.onetrust.com *.posthog.com *.qualtrics.com *.scuola-club.ch *.smartlook.com analytics.tiktok.com blob: data: https://*.service.migros.cloud https://ade.googlesyndication.com https://ajax.aspnetcdn.com https://cdn.cookielaw.org https://cdn.jsdelivr.net https://cdn.migros.ch https://chatbot-cdn-qa.migros.ch https://clarity.microsoft.com https://connect.facebook.net https://cp.klubschule.ch https://ct.pinterest.com https://dev.cp.klubschule.ch https://dev.klubschule.ch https://geolocation.onetrust.com https://googleads.g.doubleclick.net https://insights.hotjar.com https://int.cp.klubschule.ch https://js.monitor.azure.com https://maps.googleapis.com https://maps.gstatic.com https://mgbchatbotpublicprod.blob.core.win- strict-transport-security
max-age=31536000; includeSubDomains