mennekes.com
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Nuxt
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- mennekes-prod.directus.app×24
- cdn.jsdelivr.net×2
- fast.wistia.net×1
- fonts.googleapis.com×1
Social
Contact
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1996-08-23
- Expires
- 2031-08-22 1920 days left
- Updated
- 2021-08-22
- Name servers
-
- seth.ns.cloudflare.com
- tani.ns.cloudflare.com
DNS records live
- NS
-
- seth.ns.cloudflare.com
- tani.ns.cloudflare.com
- MX
-
- 10 mennekes-com.mail.protection.outlook.com
- TXT
-
JA6V71AGVFQTR8LS8CB674GJFDdfslpkf1b6nd8em2r971v0gcs7sophos-domain-verification=7fc30f800a790f3307b4f1a2c45cd3f48a3020ccb2b98aed4bff54c4aee14639
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 mx ip4:70.89.31.177 ip4:173.63.134.235 ip4:18.235.230.108 include:_spf.salesforce.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:admin@mymennekes.onmicrosoft.com; ruf=mailto:admin@mymennekes.onmicrosoft.com;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwFoGgfSLKpFXPSokhyfWsbLFhM8sXfcGNwYK8lC/fWnX2L1hFHBu2eypgaHD072FlQIOzziTA3RM7yKX1ye…
selectors probed - selector1:
Certificate (current)
E7
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=*, ambient-light-sensor=*, autoplay=*, battery=*, camera=*, cross-origin-isolated=*, display-capture=*, document-domain=*, encrypted-media=*, execution-while-not-rendered=*, execution-while-out-of-viewport=*, fullscreen=*, geolocation=*, gyroscope=*, keyboard-map=*, magnetometer=*, microphone=*, midi=*, navigation-override=*, payment=*, picture-in-picture=*, publickey-credentials-get=*, screen-wake-lock=*, sync-xhr=*, usb=*, web-share=*, xr-spatial-tracking=*- x-content-type-options
nosniff- content-security-policy
default-src 'self' use.typekit.net www.googletagmanager.com fast.wistia.com *.netlify.app; style-src 'self' 'unsafe-inline' maxcdn.bootstrapcdn.com www.googletagmanager.com fonts.googleapis.com *.typekit.net cdn.jsdelivr.net *.cloudflare.com; form-action 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com *.licdn.com *.googleadservices.com code.jquery.com fast.wistia.com fast.wistia.net www.google-analytics.com www.googletagmanager.com *.netlify.app stackpath.bootstrapcdn.com static.cloudflareinsights.com kit.fontawesome.com diffuser-cdn.app-us1.com prism.app-us1.com code.jquery.com cdn.jsdelivr.net ajax.googleapis.com; connect-src 'self' cdn.jsdelivr.net *.google.com *.googleadservices.com *.linkedin.com *.directus.app *.litix.io distillery.wistia.com embed-fastly.wistia.com pipedream.wistia.com www.google-analytics.com ka-f.fontawesome.com *.algolianet.com *.algolia.net; img-src 'self' blob: data: *.googletagmanager.com *.wistia.com *.doubleclick.net *.linked- strict-transport-security
max-age=31622400; includeSubDomains; preload