noser-bulgaria.com
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress 6.9.4
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Ascio Technologies, Inc. Danmark - Filial af Ascio technologies, Inc. USA
- Created
- 2017-10-27
- Expires
- 2026-10-27 158 days left
- Updated
- 2025-10-28
- Name servers
-
- ns.hostpoint.ch
- ns2.hostpoint.ch
- ns3.hostpoint.ch
DNS records live
- NS
-
- ns.hostpoint.ch
- ns2.hostpoint.ch
- ns3.hostpoint.ch
- MX
-
- 10 esa.nosergroup.com
- 10 esa1.nosergroup.com
- 10 esa2.nosergroup.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com mx:noser-bulgaria.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyAGf1MdBfZ4BCXANxYel3abb5G3OQ/Kzc2iHbDjLS//2k5y0+n2pPqNurPbxz52BBGUWJyD/txXf33…
selectors probed - selector1:
Certificate (current)
R13
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
same-origin- permissions-policy
geolocation=(),midi=(),notifications=(),push=(),sync-xhr=(),accelerometer=(),gyroscope=(),magnetometer=(),payment=(),camera=(),microphone=(),usb=(),xr=(),speaker=(self),vibrate=(),fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; object-src 'none'; worker-src blob: 'self'; connect-src 'self' *.hsforms.com *.hsforms.net *.youtube.com https://www.googletagmanager.com https://www.gstatic.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google-analytics.com https://www.google.com https://code.jquery.com *.onetrust.com *.linkedin.com *.googleapis.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.doubleclick.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.hsforms.com *.hsforms.net *.youtube.com https://www.googletagmanager.com https://www.gstatic.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google-analytics.com https://www.google.com https://code.jquery.com *.onetrust.com *.linkedin.com *.googleapis.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.doubleclick.net;- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (11)
- akros.ch×1
- bucher-suter.com×1
- danexis.com×1
- facebook.com×1
- frox.ch×1
- google.ch×1
- instagram.com×1
- linkedin.com×1
- noser-group.ch×1
- noser.com×1
- noseryoung.ch×1