lixt.ch

.ch crawl

First seen 2026-06-03 · Last seen 2026-06-03 · ok HTTP/1.1 200 365 ms crawled 2026-06-03

DE · 3.120.198.221 · AS16509 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Factoring, Inkasso und Monitoring für KMU, Gemeinden und Verbände.
Description
Über 3'000 Kunden setzen auf die cleveren Tools vom Schweizer Unternehmen Lixt für Inkasso, Factoring und Monitoring.
Translations
  • de
  • fr
  • it

Technology

Server
Microsoft-IIS
jQuery
3.7.1
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (5)

  • cdnjs.cloudflare.com×9
  • cdn.datatables.net×1
  • cdn.linearicons.com×1
  • fonts.googleapis.com×1
  • www.googletagmanager.com×1

DNS records live

NS
  • ns-1080.awsdns-07.org
  • ns-1805.awsdns-33.co.uk
  • ns-426.awsdns-53.com
  • ns-884.awsdns-46.net
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • amazonses:bMFpwTCTjF0f7amVx3WEB1BJ4lkUzTqg2cVLoKNSp8I=
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:amazonses.com include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarcreports@lixt.ch
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAi9FZpSd3KzM97v1RdegrAlJMiEloMHCBFucGKoKO06FTcbSm6fSDwgpC5mtOjXVTpE3s5LLq48rohv…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

Amazon RSA 2048 M01
from 2025-12-01 to 2026-12-31
Expires in 209 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.lixt.ch/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(), midi=(), sync-xhr=(), accelerometer=(), gyroscope=(), magnetometer=(), payment=(), camera=(), microphone=(), usb=(), fullscreen=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.datatables.net https://code.createjs.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.gstatic.com https://tagmanager.google.com https://snap.licdn.com https://px.ads.linkedin.com https://*.bexio.com https://sc.lfeeder.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.datatables.net https://cdn.linearicons.com https://fonts.googleapis.com https://tagmanager.google.com https://www.googletagmanager.com; img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.google.com https://www.google.ch https://www.google.mk https://www.gstatic.com https://font
strict-transport-security
max-age=2592000

Linked from (2)