ingram-braun.net
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (9)
- www.paypal.com×3
- i.ytimg.com×2
- schach-goettingen.de×2
- ssl-vg03.met.vgwort.de×2
- ssl-vg09.met.vgwort.de×2
- www.paypalobjects.com×2
- youtube-nocookie.com×2
- gmpg.org×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Key-Systems GmbH
- Created
- 2012-01-18
- Expires
- 2027-01-18 242 days left
- Updated
- 2026-01-19
- Name servers
-
- ns01.1blu.de
- ns02.1blu.de
DNS records live
- NS
-
- ns01.1blu.de
- ns02.1blu.de
- MX
-
- 10 mail.ingram-braun.net
Email authentication weak
- SPF
-
v=spf1 a mx ip4:178.254.4.101 ip4:178.254.0.201 ip4:178.254.0.202 ip4:178.254.0.203 ip4:178.254.0.204 ip4:178.254.0.205 ip4:178.254.0.206 ip4:178.254.0.207 ip4:178.254.0.208 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 26 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' blob: 'unsafe-eval' data: 'unsafe-inline' https://*.ingram-braun.net https://*.chessbase.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://*.ingram-braun.net https://*.chessbase.com; img-src blob: data: * ; media-src 'self' https://*.chessbase.com; frame-src 'self' blob: https://*.youtube-nocookie.com; font-src 'self' data: https://*.ingram-braun.net https://*.chessbase.com https://*.gstatic.com; manifest-src 'self' https://*.ingram-braun.com; object-src 'self' https://*.ingram-braun.net; form-action 'self' https://*.ingram-braun.net https://www.paypal.com; base-uri 'self'; connect-src 'self' https://*.ingram-braun.net;- strict-transport-security
max-age=63072000; includeSubDomains; preload