mdd.ch
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 1.11.2 known XSS (<3.5)
Third-party hosts loaded (5)
- hubspot.etrex.dev×13
- data.my.permaleads.ch×1
- ik.imagekit.io×1
- js.hs-scripts.com×1
- static.hsappstatic.net×1
Social
Contact
- Phone
DNS records live
- NS
-
- matt.ns.cloudflare.com
- monika.ns.cloudflare.com
- MX
-
- 10 mdd-ch.mail.protection.outlook.com
- TXT
-
atlassian-sending-domain-verification=ff0f14e2-9fd4-4a06-b272-5e6a5206a00eswisssign-check=IkDQvk_Duv_ijsNIdjqQZgOzPV0
- Verified for
-
- Atlassian
- Canva
- OpenAI
Email authentication partial
- SPF
-
v=spf1 a mx ip4:74.161.122.51 ip4:212.243.144.184 ip4:195.65.163.33 ip4:37.128.180.86 ip4:141.195.94.178 include:spf.protection.outlook.com include:5610142.spf06.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:18854ad6169742849b668a5a45198b9a@dmarc-reports.cloudflare.net; ruf=mailto:18854ad6169742849b668a5a45198b9a@dmarc-reports.cloudflare.net; sp=none; fo=0; aspf=r; adkim=r;policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5KAkIOUWpED5WhDzev/1AHRKIM71GYNCZAVbsu6o95qGCsD23zkFe76rCepwH3pzIn2Jn1QNXNFXCKl2W6i… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
E8
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(self), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=()- x-content-type-options
nosniff- content-security-policy
connect-src hubspot-forms-static-embed.s3.amazonaws.com hubspot.etrex.dev maps.googleapis.com *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hsforms.com *.hubapi.com js.hscta.net *.hubspot.com *.hsappstatic.net *.hsforms.com *.hsforms.net px.ads.linkedin.com cdn.matomo.cloud mdd.matomo.cloud www.mdd.ch data.my.permaleads.ch; script-src 'unsafe-inline' cdn.matomo.cloud maps.googleapis.com hubspot.etrex.dev feedback.hubapi.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hsadspixel.net *.hscollectedforms.net *.hscta.net *.hsforms.com *.hsforms.net *.hsleadflows.net *.hubspot.com *.hubspot.net *.hubspotfeedback.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspotusercontent-eu1.net static.hsappstatic.net www.mdd.ch data.my.permaleads.ch *.usemessages.com; script-src-elem 'unsafe-inline' connect.facebook.net maps.googleapis.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.- strict-transport-security
max-age=3628800