loga.ch
HTML metadata
Technology
- Server
- Apache
- CMS
- Ghost
- Analytics
-
- Google Tag Manager
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (2)
- player.vimeo.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Via San Gian 42a, 7500, St. Moritz, Graubünden, CH
DNS records live
- NS
-
- ns.second-ns.com
- ns1.your-server.de
- ns3.second-ns.de
- MX
-
- 30 mx001.ticinocom.xion.oxcs.net
- 30 mx002.ticinocom.xion.oxcs.net
- 30 mx003.ticinocom.xion.oxcs.net
- 30 mx004.ticinocom.xion.oxcs.net
- Verified for
-
- Brevo
- GlobalSign
Email authentication weak
- SPF
-
v=spf1 ip4:195.190.166.213 +a +mx +ip4:157.97.79.0/24 +ip4:157.97.78.0/24 +ip4:185.27.183.128/25 +ip4:153.92.124.128/25 +ip4:185.74.64.0/24 +ip4:185.74.65.0/24 +include:spf.mailjet.com +include:ticino.com +include:spf.mandrillapp.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 73 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/; script-src 'self' 'unsafe-inline' https://googleads.g.doubleclick.net https://www.googletagmanager.com/ https://pagead2.googlesyndication.com/ https://*.stripe.com/ https://facebook.com/ https://www.googleadservices.com/ https://*.doubleclick.net/ https://*.googletagmanager.com/ https://*.google-analytics.com https://consent.cookiebot.com/ https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://connect.facebook.net/; frame-src 'self' https://*.vimeo.com https://pagead2.googlesyndication.com/ https://www.googletagmanager.com/ https://*.stripe.com/ *.privacybee.ch https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://*.doubleclick.net/ https://*.matterport.com/;style-src 'self' 'unsafe-inline' https://*.myfonts.net; object-src 'none'; frame-ancestors 'self'; f
Links to (9)
- chiccodoro.ch×1
- facebook.com×1
- instagram.com×1
- linkedin.com×1
- mobimex.ch×1
- nanea.ch×1
- twitter.com×1
- wittmann.ch×1
- youtube.com×1