ofac.ch
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (4)
- fonts.googleapis.com×2
- player.flipsnack.com×1
- player.vimeo.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- ns1.ip-plus.net
- ns2.ip-plus.net
- ns6.gandi.net
- MX
-
- 10 esg1.ofac.ch
- 10 esg2.ofac.ch
- TXT
-
Show 7 TXT records
have-i-been-pwned-verification=dweb_zdrgrgao1iyxvd5f8rf4qmfosite24x7-signals-domain-verification=97709eb0e831b11b881214f5547266b5Fpabqplz8jDoOTaPTBZnPGVX5MvBMdMlMS=8BD5FF6DF198D372A2ECC8BE994820DB1A223278swisssign-check=XgVo6jfCL7L4RFXcwo247VCVn8Ibsqttz3zxnt2xwb51c68f65dl8czhkvmx4sygrd2qz0vmb3s302b6tx58d2rml8m
- Verified for
-
- Atlassian
Email authentication weak
- SPF
-
v=spf1 a:ofac.ch mx:ofac.ch include:spf.ofac.ch a:ov-f0fcc3.infomaniak.ch include:servers.mcsv.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
SwissSign RSA TLS OV ICA 2022 - 1
Expires in 219 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, no-referrer- x-frame-options
ALLOW-FROM intranet.ofac.ch, SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'unsafe-inline' 'unsafe-eval' https://ofac.ch https://*.ofac.ch https://fonts.googleapis.com https://cdn.jsdelivr.net https://*.google-analytics.com https://*.hotjar.com/ https://*.hotjar.io/ wss://*.hotjar.com https://*.cloudflare.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ofac.ch https://*.ofac.ch https://www.google.com https://www.gstatic.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://*.hotjar.com https://*.google-analytics.com https://*.cloudflare.com/ https://unpkg.com/ https://cdn-cookieyes.com/ https://*.cdn-cookieyes.com/; object-src 'none'; img-src 'self' data: https://ofac.ch https://*.ofac.ch https://*.google-analytics.com https://*.cdn-cookieyes.com/ https://cdn-cookieyes.com/; media-src 'self'; frame-src 'self' https://*.ofac.ch https://*.google.com https://www.flipsnack.com/ https://player.vimeo.com https://*.youtube.com https://*.youtube.be https://*.youtube-nocookie.com https://*.pharmatic.ch https://*.hotjar.com ht- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains; preload
Links to (2)
- ovan.ch×1
- flipsnack.com×1