muench-energie.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- cdn-jmjej.nitrocdn.com×8
- ajax.googleapis.com×1
- cdn.jsdelivr.net×1
- cdn.plyr.io×1
- cdnjs.cloudflare.com×1
- use.typekit.net×1
Social
Contact
Registration
- Updated
- 2020-12-16
- Name servers
-
- ns01.agenturserver.co.
- ns01.agenturserver.de.
- ns01.agenturserver.it.
DNS records live
- NS
-
- ns01.agenturserver.co
- ns01.agenturserver.de
- ns01.agenturserver.it
- MX
-
- 10 mx01.hornetsecurity.com
- 20 mx02.hornetsecurity.com
- 30 mx03.hornetsecurity.com
- 40 mx04.hornetsecurity.com
- TXT
-
2mks8vj2q9djxgppgx7xl8cqlpj73nw3lmc=6dcd8094-4cd5-4248-ac61-4eba79e290c8
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.exclaimer.net include:agenturserver.de include:spf.hornetsecurity.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:a.ko63pcgb@reports.hornetdmarc.compolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 161 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://ritrag.com https://www.googleadservices.com https://www.clarity.ms https://player.vimeo.com/ https://script.hotjar.com https://googleads.g.doubleclick.net https://connect.facebook.net https://snap.licdn.com https://static.hotjar.com https://www.google-analytics.com https://consentcdn.cookiebot.com https://nitroscripts.com https://cdn-jmjej.nitrocdn.com https://unpkg.com/ https://www.googletagmanager.com https://consent.cookiebot.com http://cdn.matomo.cloud https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://ajax.googleapis.com https://cdn.plyr.io https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://cdn-jmjej.nitrocdn.com https://unpkg.com/ https://fonts.googleapis.com https://use.typekit.net https://cdn.plyr.io https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://p.typekit.net blob: 'unsafe-eval'; font-src 'self' https://cdn-jmjej.nitrocdn.com https://fonts.gstatic.com- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (8)
- br.de×1
- facebook.com×1
- grueueuen.de×1
- instagram.com×1
- linkedin.com×1
- n-tv.de×1
- spiegel.de×1
- wiwo.de×1