mdcc.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (3)
- cdn.brevo.com×1
- cloud.ccm19.de×1
- www.facebook.com×1
Social
Contact
- Phone
Registration
- Updated
- 2012-04-16
- Name servers
-
- ns1.mdlink.de.
- ns2.mdlink.de.
- ns3.mdlink.de.
- ns4.mdlink.de.
DNS records live
- NS
-
- ns1.mdlink.de
- ns2.mdlink.de
- ns3.mdlink.de
- ns4.mdlink.de
- MX
-
- 10 svmailgw01.sw-magdeburg.de
- 10 svmailgw02.sw-magdeburg.de
- TXT
-
cisco-ci-domain-verification=705a0e1b29194d751bd37de90a8fced954c355dba6382a2b2d3f70a6f8dd9054MS=ms47664679brevo-code:04b3b211ad873a29039aac7cd55a69ee
Email authentication partial
- SPF
-
v=spf1 a mx ip4:213.211.240.70/32 ip4:213.211.240.71/32 ip4:213.211.240.86/32 ip4:213.211.192.139/32 include:spf.nl2go.com include:spf.protection.outlook.com include:_spf.netigate.se -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),ambient-light-sensor=(),autoplay=(self),battery=(),camera=(),display-capture=(),document-domain=(self),encrypted-media=(self),execution-while-not-rendered=(),execution-while-out-of-viewport=(),fullscreen=(self),geolocation=(),gyroscope=(),layout-animations=(),legacy-image-formats=(),magnetometer=(),microphone=(),midi=(),navigation-override=(),oversized-images=(),payment=(),picture-in-picture=(),publickey-credentials-get=(self),screen-wake-lock=(),sync-xhr=(self),usb=(),wake-lock=(),web-share=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' cloud.ccm19.de; script-src 'self' 'unsafe-inline' *.gstatic.com *.brevo.com *.sibforms.com *.sibautomation.com cloud.ccm19.de app.cockpit.legal *.matomo.cloud *.google-analytics.com *.google.com *.googletagmanager.com *.doubleclick.net connect.facebook.net snap.licdn.com *.lacmp.net; script-src-elem 'self' 'unsafe-inline' *.gstatic.com *.brevo.com sibforms.com sibautomation.com cloud.ccm19.de app.cockpit.legal *.matomo.cloud *.google-analytics.com *.google.com *.googletagmanager.com *.doubleclick.net connect.facebook.net snap.licdn.com *.lacmp.net; connect-src 'self' cloud.ccm19.de *.sibforms.com sibforms.com *.brevo.com mdcc.matomo.cloud *.google.com www.google-analytics.com *.lacmp.net; font-src 'self' data:; style-src 'self' 'unsafe-inline' sibforms.com cloud.ccm19.de; img-src 'self' cloud.ccm19.de *.googletagmanager.com www.facebook.com mdcc.matomo.cloud *.doubleclick.net *.google.com www.google.de www.google-analytics.com *.linkedin.com *.lacmp.net *.lead-allian- strict-transport-security
max-age=31536000; includeSubDomains; preload