joseph-stiftung.de
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Updated
- 2021-08-02
- Name servers
-
- ns1.telekom.net.
- pns.dtag.de.
DNS records live
- NS
-
- ns1.telekom.net
- pns.dtag.de
- MX
-
- 0 josephstiftung-de01e.mail.protection.outlook.com
- TXT
-
MS=ms2789250687K2foyilAhOftEKmYgMPJ1COL8Dhi4i7shksWiiIr6sYWn5qspA4Jdj0ALzO0NDqgRJLTdthQ5C0bTM/u6sBQ==
Email authentication weak
- SPF
-
v=spf1 mx a:gw01.joseph-stiftung.de ip4:62.55.182.68/32 include:spf.protection.outlook.com include:_spf.aareon.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCblbck/U3vACV/EOo6iG3H1b9a1plF+3FCmO4/60ZYGguZYxVkbDozsnkmEh4aqVjNDWQcO+gfVittlJQSEd… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxzC2cPrTvmAu2nZI0SUdeeFsie0gSRVdPSj3YesMcRaGYY/qNx9uD+/90PNQW7wqZwvUV+agSaLIl9…
selectors probed - selector1:
Certificate (current)
R12
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
Header values
- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://cdn.jsdelivr.net https://iframe-chatplugin.asw.aareon.com https://ssl.google-analytics.com;style-src 'self' 'unsafe-inline' https://www.joseph-stiftung.de https://fonts.googleapis.com https://cdn.jsdelivr.net https://iframe-chatplugin.asw.aareon.com 'unsafe-hashes';img-src 'self' data: https:;font-src 'self' data: https://fonts.gstatic.com;media-src 'self';connect-src 'self' https://fonts.googleapis.com https://iframe-chatplugin.asw.aareon.com;frame-src 'self' https://iframe-chatplugin.asw.aareon.com;object-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'self';upgrade-insecure-requests;worker-src blob:;- strict-transport-security
max-age=63072000; includeSubDomains; preload