mitgas.de
HTML metadata
Technology
- CDN
- Azure Front Door
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (7)
- app.usercentrics.eu×3
- cdn.enviam.de×3
- privacy-proxy.usercentrics.eu×3
- integrations.etrusted.com×2
- api.usercentrics.eu×1
- cdn.insight.sitefinity.com×1
- widgets.trustedshops.com×1
Registration
- Updated
- 2023-12-13
- Name servers
-
- dns2.envia-tel.net.
- dns3.envia-tel.net.
DNS records live
- NS
-
- dns2.envia-tel.net
- dns3.envia-tel.net
- MX
-
- 10 mitgas-de.mail.protection.outlook.com
- TXT
-
Show 9 TXT records
D-TRUST=R83RC6V4XBFK77AIJ25PB5G_sytm7w5zg0yc1zynavvnfl9jydvb3uu654f3615f3ab26ba7fe945ef6155d309efdaea3d80c3aeb1c3f6532f2d21177batlassian-domain-verification=khDfe2tNb4a3IlrXDB0Os7RNtf4vlHI9RTRXBXnvIOzJPt0/J5yOrlAbhy1mhUb3_sy4n5we1j9pr90xuw142eipouos8gwnMS=ms86116975_yglaqwflq1ogvg44xopk8e4q53rnwvr9lh4scwvfgd9k1xsr1wz5f2lghx7607l_xnosesgtu0bx8ubz6onnod4sfdlrvhh
Email authentication partial
- SPF
-
v=spf1 ip4:194.113.76.0/24 ip4:199.102.176.221/30 ip4:199.102.176.223/32 ip4:199.102.176.224/29 ip4:199.102.178.112/32 ip4:155.56.221.13 ip4:155.56.221.14 ip4:94.100.245.28 ip4:94.100.245.29 ip4:153.100.8.31 ip4:153.100.8.32 include:spf.protection.outlook.com include:spf.u2d.de ip4:130.214.193.83 ip4:130.214.193.93 ip4:130.214.193.78 ip4:130.214.193.85 include:spf.gisa.de include:spfa.myconvento.com include:_spf.pluspol-networks.de -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@enviam.de; ruf=mailto:dmarc@enviam.de;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6ig+yvUFDisQAu/ItRAkH+LRaD9CA6jgmMEObkTx+VzMtMH+TAQ+nhY6UXdd3aHet1BN1WTvOuG1gH…
selectors probed - selector1:
Certificate (current)
R13
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.enviam.de https://*.mitgas.de https://srm.ba.contentsquare.net *.contentsquare.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.enviam.de https://*.mitgas.de https://*.myaccount.private.enviam.de https://*.myaccount.private.mitgas.de https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.googletagmanager.com https://www.google-analytics.com https://static.hotjar.com https://script.hotjar.com https://*.vo.msecnd.net https://app.easy-feedback.de https://app.easy-feedback.com https://easy-feedback.de https://easy-feedback.com https://connect.facebook.net https://bat.bing.com https://js.adsrvr.org https://api.eu-1.smooch.io https://app.usercentrics.eu https://privacy-proxy.usercentrics.eu https://aggregator.service.usercentrics.eu https://www.cdn.botfriendsx.com https://cdn.insight.sitefinity.com https://dec.azureedge.net/ https://iona-counter-ocr.sdacehub.de https://mvp.sdacehub.de https://cdn.jsdelivr.net/npm/@elbwalker- strict-transport-security
max-age=31536000; includeSubDomains