kaya-shisha.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Third-party hosts loaded (2)
- kaya-shisha.alterspruefung365.de×1
- www.kaya-shisha.com×1
Social
Contact
- Phone
- Address
- Herenholz 14a, 288832, Bremen, Bremen, DE
Registration
- Updated
- 2010-01-28
- Name servers
-
- ns01.vege.net.
- ns02.vege.net.
- ns03.vege.net.
DNS records live
- NS
-
- ns01.vege.net
- ns02.vege.net
- ns03.vege.net
- MX
-
- 5 mx3.vege.net
- 50 mx2.vege.net
Email authentication weak
- SPF
-
v=spf1 mx a include:spf.nl2go.com include:vege.net -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
*, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.paypalobjects.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.fonts.googleapis.com data: *.cloudflare.com https://widgets.trustedshops.com https://static.unzer.com https://applepay.cdn-apple.com static.unzer.com *.googleadservices.com *.google-analytics.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.vdcprojects.xyz https://b2b-smoking-com.vdcprojects.xyz/stores/store/redirect/ *.de *.com *.shop 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcom- strict-transport-security
max-age=31536000; includeSubDomains