moebel-portmann.ch
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- webcache-eu.datareporter.eu×2
Social
Contact
DNS records live
- NS
-
- ns1.4webspace.ch
- ns2.4webspace.ch
- MX
-
- 10 moebelportmann-ch01e.mail.protection.outlook.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.protection.outlook.com include:spf.hostpoint.ch include:hostpoint.ch include:mxout013.mail.hostpoint.ch ip4:80.74.145.65 ip4:80.74.145.67 ip4:80.74.145.0/24 ip4:46.14.204.82 ip4:46.140.115.86 include:spf.mva.instride.ch -allstrict (-all) - DMARC
-
v=DMARC1;p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSdoFmDhyRC/rOubWYV9lgDTyhXJ/VDjq7uhTbIhOHCKqYEp7QnifbLIMdGc6NpTrjztQtqh0LMbAqd/7m9j… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8aVgAFhurupcXSBF4VVG0VpZwS8E0+tXT/0THCKP/i9BLUUjZVJU8GvR2TqJTfkBWujq247DRHBV0CclPgn…
selectors probed - selector1:
Certificate (current)
R13
Expires in 63 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; connect-src 'self' api.friendlycaptcha.com www.youtube-nocookie.com swarmcrawler.datareporter.eu www.googletagmanager.com *.google-analytics.com *.analytics.google.com stats.g.doubleclick.net www.google.com googleads.g.doubleclick.net www.googleadservices.com www.facebook.com capig.stape.cc; font-src 'self' data:; form-action 'self' *.payrexx.com *.list-manage.com www.facebook.com; frame-ancestors 'self'; frame-src 'self' www.youtube-nocookie.com www.facebook.com; img-src 'self' data: i.ytimg.com www.googletagmanager.com www.google.ch www.google.com googleads.g.doubleclick.net www.googleadservices.com www.facebook.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' webcache-eu.datareporter.eu www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com connect.facebook.net; style-src 'self' 'unsafe-inline' webcache-eu.datareporter.eu; worker-src 'self' blob: