operamrhein.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- code.etracker.com×1
Social
Registration
- Updated
- 2022-07-07
- Name servers
-
- ns21.domaincontrol.com.
- ns22.domaincontrol.com.
DNS records live
- NS
-
- ns21.domaincontrol.com
- ns22.domaincontrol.com
- MX
-
- 10 mail.operamrhein.de
- TXT
-
apple-domain-verification=2nGokdHlvXQjAsy9google-site-verification=cDU1Y7ZyRfPalJjRkCMrYZV7CVD2e14WlYRgo47hXoo
Email authentication partial
- SPF
-
v=spf1 mx a a:mx4.eventim.de ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 Ip4:185.250.236.0/22 a:mx4.eventim.de ip4:212.202.155.167 ip4:212.202.155.168 ip4:116.203.171.184 ip4:194.49.92.240 ip4:217.113.45.225 include:spf.protection.outlook.com include:_spf.spiritec-server.deno all qualifier - DMARC
-
v=DMARC1; p=none; rua=mailto:it-dor@operamrhein.de; fo=1; fr=afrf; ri=86400; aspf=s; adkim=s;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 274 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'none'; frame-src https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; img-src 'self' https: data:; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; manifest-src 'self' https:; media-src 'self' https:; connect-src 'self' https:- strict-transport-security
max-age=31536000; includeSubDomains; preload- content-security-policy-report-only
default-src 'none'; frame-src https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; img-src 'self' https: data:; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; manifest-src 'self' https:; media-src 'self' https:; connect-src 'self' https: