luchs.at
HTML metadata
Technology
- Server
- nginx
DNS records live
- NS
-
- gilean.luchs.at
- ns6.gandi.net
- seth.luchs.at
- MX
-
- 23 seth.luchs.at
- 42 gilean.luchs.at
- 65 gilean.luchs.at
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 ip4:95.129.205.85 ip6:2a02:b18:c13b:4::85 ip4:95.129.205.86 ip6:2a02:b18:c13b:4::86 ip4:95.129.205.94 ip4:77.244.242.189 ip4:212.232.31.242 ip4:62.99.132.30 ip6:2a02:1b8:10:13::aa ip6:2a02:1b8:10:13::89 ip4:77.244.253.227 a mx -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; aspf=r; fo=1:d:s; rua=mailto:dmarc@luchs.at; ruf=mailto:dmarc@luchs.at;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current) wrong cert
Gandi Standard SSL CA 2
Expired 812 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
sameorigin- permissions-policy
interest-cohort=() geolocation=() microphone=() camera=() usb=() notifications=() push=() sync-xhr=() magnetometer=() vibrate=() payment=()- x-content-type-options
nosniff- content-security-policy
connect-src https://bonjour.luchs.at/matomo.php https://calendly.com/ https://assets.calendly.com/; script-src https://calendly.com/ https://assets.calendly.com/ 'self' 'unsafe-inline' https://bonjour.luchs.at/matomo.js- strict-transport-security
max-age=31536000
Links to (5)
- agentex.at×1
- attingo.com×1
- crowes.eu×1
- foo.at×1
- nets.at×1