lehmanns.ch
HTML metadata
Technology
- Server
- asc
- Stack
- PHP
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- schema.org×52
- www.lehmanns.de×4
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- dns.lehmanns.de
- dns2.lehmanns.de
- MX
-
- 10 m2.lehmanns.de
- 10 mx1.lehmanns.de
- TXT
-
tfcfc10c262b64fmlj2wpbmt2wdstnbf
Email authentication weak
- SPF
-
v=spf1 a a:darwin.lehmanns.de a:mail.lehmanns.de a:mailer.lehmanns.de a:mail.lob.de a:smtp.lob.de a:m2.lehmanns.de a:smtp.lehmanns.de ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 95 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' lob.de *.lehmanns.de *.lehmanns.ch lehmannspro.de lehmannsbib.de *.socialnet.de; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' *.lehmanns.de *.lehmanns.ch *.googleapis.com *.google-analytics.com *.vr-pay-ecommerce.de vr-pay-ecommerce.de oppwa.com widgets.trustedshops.com- strict-transport-security
max-age=31536000;