mvz-cracau.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- cloud.ccm19.de×1
Registration
- Updated
- 2025-07-21
- Name servers
-
- dfnserv1.urz.uni-magdeburg.de.
- dfnserv2.urz.uni-magdeburg.de.
- dns-2.dfn.de.
- dns-3.dfn.de.
DNS records live
- NS
-
- dfnserv1.urz.uni-magdeburg.de
- dfnserv2.urz.uni-magdeburg.de
- dns-2.dfn.de
- dns-3.dfn.de
- MX
-
- 10 mvzcracau-de0i.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1aM7ZjHBBsmXOZf3+jFkJQ5YuKKKwa7VjikLf3pP3vWWMTUbRdbLCA0KJyuCaGE1qu9L3foVPQyy+i… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAujQ8cPU5qGZkK2IldEqRXhfFjIIxL8jPx20YE0rW5o7iIoAExA+eY8ODCbteutkAJLAYt3GArFZkL3…
selectors probed - selector1:
Certificate (current)
R12
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(self), geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), vr=(), speaker=(), ambient-light-sensor=(), gyroscope=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'nonce-p3HZC6P660hLyUSoAV6X4DkU4ajEAgI6PR7qD322aXwHWW-AvWOVEQ' data: https://*.openstreetmap.org 'unsafe-eval' https://cloud.ccm19.de https://cdn-eu.readspeaker.com https://maps.google.com https://maps.googleapis.com https://matomo.med.uni-magdeburg.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://cloud.ccm19.de https://maps.google.com https://maps.googleapis.com https://maps.gstatic.com https://matomo.med.uni-magdeburg.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://cloud.ccm19.de *.cloud.ccm19.de; connect-src 'self' https://cloud.ccm19.de https://*.readspeaker.com https://maps.google.com https://maps.googleapis.com https://matomo.med.uni-magdeburg.de; style-src-elem 'self' 'nonce-p3HZC6P660hLyUSoAV6X4DkU4ajEAgI6PR7qD322aXwHWW-AvWOVEQ' https://cloud.ccm19.de https://mato- strict-transport-security
max-age=63072000; includeSubdomains