lsbt.me
HTML metadata
Technology
- Server
- nginx
DNS records live
- NS
-
- ns07.domaincontrol.com
- ns08.domaincontrol.com
- MX
-
- 10 mxext1.mailbox.org
- 10 mxext2.mailbox.org
- 20 mxext3.mailbox.org
Email authentication strong
- SPF
-
v=spf1 mx include:mailbox.org a ip4:46.4.116.108 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s; rua=mailto:postmaster@lsbt.mepolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 44 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; default-src 'none'; frame-ancestors 'none'; font-src 'self' https://lsbt.me; img-src 'self' data: blob: https://*.ytimg.com https://lsbt.me https://www.christin-loehner.de; style-src 'self' https://lsbt.me 'nonce-ntexs4zyH8v8H6mZO+bRtQ=='; media-src 'self' data: https://lsbt.me; manifest-src 'self' https://lsbt.me; form-action 'self' https://lsbt.me; child-src 'self' blob: https://lsbt.me; worker-src 'self' blob: https://lsbt.me; connect-src 'self' data: blob: https://lsbt.me wss://lsbt.me; script-src 'self' https://lsbt.me 'wasm-unsafe-eval'; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://lsbt.me;- strict-transport-security
max-age=63072000; includeSubDomains