merck-bkk.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- consent.cookiebot.com×1
- www.bitv-widget.de×1
Registration
- Updated
- 2018-03-27
- Name servers
-
- ns1.dsg1.de.
- ns2.dsg1.de.
DNS records live
- NS
-
- ns1.dsg1.de
- ns2.dsg1.de
- MX
-
- 10 mail.merck-bkk.de
- TXT
-
swisssign-check=_pU2FE5Orz4RxqIXRHcLHpz7s2k
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.itscnet.de -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Encryption Everywhere DV TLS CA - G2
Expires in 249 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), camera=(self), microphone=(self), fullscreen=(self), autoplay=(self), accelerometer=(self), gyroscope=(self), magnetometer=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' *.bkk-dachverband.de *.google.com *.google.de 'sha256-59eVUTOUNLWnRzEwsrxWQhdUcZEYmgytww4u9hyDNoY=' stats.merck-bkk.de *.dsg1.de https://www.bitv-widget.de/ *.ip-gkv.de *.gwq-serviceplus.de https://snap.licdn.com/li.lms-analytics/ https://px.ads.linkedin.com/ https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://f1-eu.readspeaker.com/ https://www.instagram.com/ https://platform.instagram.com/ https://platform.twitter.com/ https://siteimproveanalytics.com/ https://www.eye-able-cdn.com/ https://platform.linkedin.com *.bkk-lichtbildservice.de; style-src 'report-sample' 'self' data: *.dsg1.de https://www.bitv-widget.de/ *.bkk-lichtbildservice.de *.ip-gkv.de *.gwq-serviceplus.de 'unsafe-hashes' 'unsafe-inline' https://px.ads.linkedin.com/ https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://f1-eu.readspeaker.com/ https://platform.instagram.com/ https://platform.twitter.com/ https://s- strict-transport-security
max-age=31536000