leona.ch

.ch crawl

First seen 2026-06-01 · Last seen 2026-06-02 · ok HTTP/1.1 200 2496 ms crawled 2026-06-02

US · 158.177.90.237 · AS36351 IBM Cloud

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Apleona - Login

DNS records live

NS
  • ns1.ip-plus.net
  • ns2.ip-plus.net
MX
  • 0 mta-gw.infomaniak.ch
Verified for
  • Google

Email authentication weak

SPF
v=spf1 include:spf.infomaniak.ch -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2025-12-08 to 2026-12-09
Expires in 189 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://login.leona.ch/Account/Login?ReturnUrl=%2Fconnect%2Fauthorize%2Fcallback%3Fclient_id%3Dapleona-portal%26redirect_uri%3Dhttps%253A%252F%252Fwww.leona.ch%26response_type%3Dcode%2520id_token%26scope%3Dopenid%2520profile%2520email%2520phone%2520rem_profile%2520apleona_is_api%2520offline_access%26state%3DOpenIdConnect.AuthenticationProperties%253Do43kPEmx07TAmBDKfCoYYhMIDhfXbFBZuYnQSV5vVjVS27wE7FIdSdjraxWJet5KXP8hUsg5a6uxu5fQxlLgMlJMaU8VAIY-7Cu9Ph1mAVFjn1UylRj7QbLsrMMFLqd9yDzhW8F8lVasRb4cQT9imIuYSxfh4gJ6dxvQ1n6pvjGZvRbUPcfj3U3BGC9fVtB-s1ad409nxS5ELo5ZvcA5Y-fGIJor1NuM0krYfDVmSEK36c1N-fQZvrd0RMC_v2QDOL6hKk9gFcBFBwxabwB0hlRwtfW8eWsNJG-YDLLa-SrkXVUPGI0K8dXUJuwE9ah5hXLX5t-1zHvK9WTXKMgbFdhLdqFMq2hXWlNrOk9KNunQz9g9jBmwgvS7VN3bF7LspkJ0BUJrwEbgefEk5PTHAbyktfZeA-vSnnXcu77P3Xo1GXUAKCoxRPrlKCPD4cinmSp5wuGPQANsO_buTc7-CZ1TyXmneaNauj7Qbt_MuzbIiWkbU9N8asBX-e-25g66CGMKN81FMTMoQS8B4ZsBTcHkQbQlIfEk6D4kqGZDzUUYUlR5hWmP4x8e2fxGAXeacB3eWz6zTdsCKvavvFDSsXFSDQshJbmld-b68xB18O1pBST50xCqkPxWg2BypeLttLGxIv7eXNB-CMDqN6EFTOuDl5fOekzjYTYxcVd6O-rYeJ6OFG8_cNgS-Z1cNiMmljBsE0XR0AV4nA2H2oPJOVI2SDAoNYGMqTynVBC-abdgUrMhOaBuhglZjzEZ5VheEXSpHBrGKoqVz7UI5XpAYPFFmlb9CtUHuktZBIQA6tJtwUn9czQDvyZzJjOL1fYo%26response_mode%3Dform_post%26nonce%3D639159673866705287.ZGY2MGRjYTItZTI1Ny00ZWExLWE5NjgtNjIxOTE1NDI2M2NlMWQzMzFiY2MtYjQ3Yy00NjRmLTgzY2UtYzVlZjZiZjg5MWQ2%26ui_locales%3Dde-CH%26x-client-SKU%3DID_NET461%26x-client-ver%3D5.3.0.0

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing Permissions Policy
Header values
referrer-policy
no-referrer
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self'; upgrade-insecure-requests;
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (1)

Linked from (1)