madicon.de
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Hugo
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- imagedelivery.net×4
- firebasestorage.googleapis.com×3
- templates.bullet.site×3
- app.consently.net×1
- app.visitortracking.com×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
Social
Registration
- Updated
- 2020-10-14
- Name servers
-
- ns5.kasserver.com.
- ns6.kasserver.com.
DNS records live
- NS
-
- ns5.kasserver.com
- ns6.kasserver.com
- MX
-
- 10 w01b1cda.kasserver.com
- TXT
-
google-site-verification=Lun-qsxeTlbCmMdRU2nlPYWoHfL-WDAPAe-oHLnICI0
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.kasserver.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- permissions-policy
geolocation=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: wss:; manifest-src 'self'; img-src https: data: 'self'; style-src https: 'unsafe-inline'; script-src 'unsafe-inline' https:; frame-ancestors http://localhost:3000/ https://app.bullet.so/ 'self'; object-src 'none'; worker-src https: blob: data: 'self'; base-uri 'self'- strict-transport-security
max-age=63072000; preload