invia.ch
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.5.1
- Stack
- PHP
Third-party hosts loaded (2)
- cdn.weglot.com×1
- s3.amazonaws.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns.hostpoint.ch
- ns2.hostpoint.ch
- ns3.hostpoint.ch
- MX
-
- 0 invia-ch.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:5.148.183.98/32 ip4:5.148.183.72/32 ip4:5.148.188.19/32 include:spf.protection.outlook.com include:spf.mail.hostpoint.ch a:mnc-mail.smsbox.ch -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
R12
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-YMm2wqGWzqqQoaDF3IvLPw==' 'unsafe-eval' 'sha256-hSrxDOhQqsfSysSVjG6nWmmZAAEQTcdg7sWJuTeQUOU=' https://cdn-cookieyes.com https://*.cookieyes.com https://*.facebook.com https://templates.nextbike.net https://cdn.weglot.com https://s3.amazonaws.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://invia.us21.list-manage.com https://static.landbot.io https://tracking.invia.ch https://unpkg.com https://players.yumpu.com https://www.yumpu.com https://youtube.com; style-src 'self' 'unsafe-inline' https://templates.nextbike.net https://cdn.weglot.com https://cdn.landbot.io https://www.googletagmanager.com https://fonts.googleapis.com; img-src 'self' data: https://cdn-cookieyes.com https://www.facebook.com https://www.googletagmanager.com https://storage.googleapis.com https://gr-invia.ch https://invia.ch https://www.google.ch https://*.tile.openstreetmap.org https://static.nextbike.net https://fon- strict-transport-security
max-age=63072000; includeSubDomains
Links to (8)
- facebook.com×1
- gr-invia.ch×1
- gr.ch×1
- instagram.com×1
- linkedin.com×1
- sbb.ch×1
- swisspass.ch×1
- tiktok.com×1
Linked from (3)
- churbus.ch×1
- venda.ch×1
- rhb.ch×1