km2.de
HTML metadata
Technology
- Server
- Apache
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (2)
- app.usercentrics.eu×2
- api.usercentrics.eu×1
Contact
- Phone
Registration
- Updated
- 2017-10-30
- Name servers
-
- nick.ns.cloudflare.com.
- reza.ns.cloudflare.com.
DNS records live
- NS
-
- nick.ns.cloudflare.com
- reza.ns.cloudflare.com
- MX
-
- 20 aspmx.l.google.com
- 50 alt1.aspmx.l.google.com
- 50 alt2.aspmx.l.google.com
- 80 aspmx2.googlemail.com
- 80 aspmx3.googlemail.com
- TXT
-
ca3-f194969cffbc42f3ab31d4bd72c0f89av=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkbhoKiqwiS3ZzjVHW9RG+i5tMP08Z3B5xoqASXRgwih3O1dxfKn9Mv6ETc6m3wDn0i9Z2M4W0QLg5rC0aGAF+JBgfORPbXhHvNU7k4K6UQBLA5efM1h9XZrYqlPEvlISq0CF3sqdu96fQYjZLKurHeEibcEV8c9LkP6jU1jNQWaJBU+u2CNgeKc/rbMhyznnIpESAbll7yISSz2VXYT3fSYvWqIntRZja+kQfcCfL/y4sFgjCE+B1L0nw6irWzbTTADpVtStq9sRo+qsuHDz3qVydS8m+cKu7G0v7mK14wP0AscV4dTc+cYH/Esgjts/b3f3UUvxr19RODc+QxW2HwIDAQABatlassian-sending-domain-verification=e88ad292-1923-4e6f-928e-caae39b354f7
- Verified for
-
- Apple
- Atlassian
Email authentication weak
- SPF
-
v=spf1 a include:_spf.atlassian.net include:_spf.google.com include:agenturserver.de include:dedi7081.your-server.de ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw1gU64wM331J2x42nJ5l0VWV9mz2yyXOQwlgqvQ5eOkANWTV43m7GSCUU9MBBKHDpm6+8o9nY+5vm506tZ… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8tvSmzHnj/KkHIVAuonmai05ZFiat3Js8GETYTxg0Pfb3773i53A56TIx89vrodwSgVPFTQFqQ1Tg/KOpQM6YlC…
selectors probed - s1:
Certificate (current)
R12
Expires in 39 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
deny- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; base-uri 'none'; style-src 'self' 'unsafe-inline' https://cdn.leadinfo.net 'report-sample'; style-src-elem 'self' https://*.usercentrics.eu 'unsafe-inline' 'report-sample'; script-src 'self' 'unsafe-inline' https://app.usercentrics.eu 'unsafe-eval' https://sst.km2.de https://www.googleadservices.com https://www.google.com https://www.google.de https://cdn.leadinfo.net https://*.ldnfrpl.com 'report-sample'; img-src 'self' data: https://*.usercentrics.eu https://sst.km2.de https://www.googletagmanager.com https://*.analytics.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.de https://collector.leadinfo.net https://cdn.leadinfo.net; font-src 'self' https://cdn.leadinfo.net; frame-src 'self' https://date.km2.de https://sst.km2.de; script-src-elem 'self' 'unsafe-inline' https://app.usercentrics.eu https://sst.km2.de https://www.googleadservices.com https://www.google.com https://www.google.de https: