kronimus.de
HTML metadata
Technology
- Server
- HTTP
- CMS
- WordPress
Third-party hosts loaded (1)
- www.kronimus.fr×1
Social
Contact
- Phone
Registration
- Updated
- 2025-11-20
- Name servers
-
- ns1.namesecure.de.
- ns2.namesecure.de.
DNS records live
- NS
-
- ns1.namesecure.de
- ns2.namesecure.de
- MX
-
- 10 mx-01-eu-central-1.prod.hydra.sophos.com
- 20 mx-02-eu-central-1.prod.hydra.sophos.com
- TXT
-
MS=CA03138F5DE5515B00915D6FBFDB34DE08F4A7BB9a4ea02e000e4140b3c27d26a571b144sophos-domain-verification=b51aceb8b6bc31f21c356080d044ce383efbb4af
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 a mx ip4:195.243.143.54 ip4:78.47.254.46 include:spf.protection.outlook.com include:spf.cloud.ci-solution.com include:_spf_eucentral1.prod.hydra.sophos.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Encryption Everywhere DV TLS CA - G2
Expires in 175 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=self- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.googletagmanager.com https://www.googleapis.com https://maps.googleapis.com https://cdn.weglot.com/weglot.min.js https://trinketsofcody.com; object-src 'self' https://maps.googleapis.com; img-src 'self' data: *.gravatar.com https://*.googletagmanager.com https://maps.googleapis.com https://maps.gstatic.com https://*.google-analytics.com https://*.kronimus.fr https://res.cloudinary.com; media-src 'self' data: https://*.kronimus.fr; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://fonts.googleapis.com https://cdn.weglot.com; child-src 'self' https: blob:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://*.doubleclick.net https://maps.googleapis.com https://www.googleapis.com https://*.google-analytics.com https://getcody.ai https://cdn.weglot.com https://cdn-api-weglot.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload