mobiliare.ch
HTML metadata
Technology
- CDN
- Fastly
- CMS
- Drupal
- JS framework
- Angular 21.2.6
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google Ads (DoubleClick)
Third-party hosts loaded (7)
- mobiliar.rokka.io×22
- adservice.google.com×1
- analytics.google.com×1
- doubleclick.net×1
- tags.tiqcdn.com×1
- www.google-analytics.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.ip-plus.net
- ns1.mobi-net.ch
- ns2.mobi-net.ch
- MX
-
- 10 mail.swisscom.com
- 20 mail10.swisscom.com
- 20 mail20.swisscom.com
- TXT
-
Show 8 TXT records
swisssign-check=H_myPKG467SxesOvzDEzh6DSMFYswisssign-check=47-cFyjvYZKQsOWFg4lZKtRv6Nwz1nm848tbz412t5q7wfw0wp2ntxlxsmkswisssign-check=sktv42W3uwkkPY2Zpq_Wvol3goU_99lpo2sfhzkyhdeulo6u62mrbmmsei8_rsdszf4ym7sqfevn0nuh60dedwjczkzSFMC-VbXoSjfxnxGf_hsO1qLMSzlrABi6Rr75keAjhm_G6dBsomUHj+/CBbMqxGYpAQP0Eb0wBRLjOHd8BhqKrF4zJRcpMBeMBwYi7bkrO5D//gkWYcK5HrJWSJKBcx/1fA==
- Verified for
-
- Apple
- Meta
- Microsoft 365
- Miro
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
SwissSign RSA TLS EV ICA 2022 - 1
Expires in 117 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: *.rokka.io *.jquery.com *.cloudflare.com jquery.com doubleclick.net *.doubleclick.net google.com *.google.com google.nl *.google.nl google.at *.google.at google.co.uk *.google.co.uk google.ch *.google.ch google.de *.google.de google.fr *.google.fr google.it *.google.it google.li *.google.li *.googleapis.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.tealiumiq.com *.tiqcdn.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: ajax.aspnetcdn.com *.algolia.net *.algolianet.com bam.eu01.nr-data.net *.cloudflare.com *.cookielaw.org *.dynatrace.com doubleclick.net *.doubleclick.net *.evenito.com evenito.com *.facebook.com *.facebook.net google.com *.google.com google.nl *.google.nl google.at *.google.at google.co.uk *.google.co.uk google.ch *.google.ch google.de *.google.de google.fr *.google.fr google.it *.google.it google.li *.google.li *.google-analytics.com *.googleadservices.com *.googleapis.com *.googleoptimize.com *.goog- strict-transport-security
max-age=31536000; includeSubDomains; preload