konzerthaus-dortmund.de
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- portal.safe-port.cloud×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Updated
- 2011-04-12
- Name servers
-
- ns1.your-server.de.
- ns3.second-ns.de.
- ns.second-ns.com.
DNS records live
- NS
-
- ns.second-ns.com
- ns1.your-server.de
- ns3.second-ns.de
- MX
-
- 10 dedi1092.your-server.de
- TXT
-
MS=E5E5CEA905445F66E3EB21480F7CE73036822752
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 a mx ip4:62.72.73.155 ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=quarantine;sp=none;pct=50;adkim=r;aspf=r;policy: quarantine · pct=50 · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Encryption Everywhere DV TLS CA - G2
Expires in 174 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
STRICT-ORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'self';script-src *.konzerthaus-dortmund.de *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.sharethis.com portal.safe-port.cloud *.bing.com *.bing.net *.typekit.net *.friendlycaptcha.eu *.facebook.net *.gstatic.com *.issuu.com *.enuerto.net *.google-analytics.com *.google.com *.jquery.com 127.0.0.1:* 'unsafe-inline' 'unsafe-eval' blob: data: 'self';style-src data: blob: 'unsafe-inline' *;form-action 'self' https://konzerthaus-dortmund.com https://*.konzerthaus-dortmund.com https://*.inxmail.com https://www.facebook.com/tr/ https://*.ipg-online.com https://www.paypal.com/; connect-src *.konzerthaus-dortmund.com *.konzerthaus-dortmund.de portal.safe-port.cloud *.giraffentoast.net *.bing.net *.friendlycaptcha.eu *.facebook.net *.googlesyndication.com *.google-analytics.com *.google.com *.doubleclick.net *.sharethis.com *.bing.com updates.expressionengine.com- strict-transport-security
max-age=31536000; includeSubDomains; preload