peterstaler.de
HTML metadata
Technology
- Server
- Apache
Social
Registration
- Updated
- 2024-11-29
- Name servers
-
- a.ns14.net.
- b.ns14.net.
- c.ns14.net.
- d.ns14.net.
DNS records live
- NS
-
- a.ns14.net
- b.ns14.net
- c.ns14.net
- d.ns14.net
- MX
-
- 10 de-smtp-inbound-1.mimecast.com
- 10 de-smtp-inbound-2.mimecast.com
- TXT
-
MS=ms819967600ed1fe018aec2d05bc8cb5400e9dee9970aacc7469apple-domain-verification=6lQ1yaWXaXi5EIUI
Email authentication weak
- SPF
-
v=spf1 a mx a:mail.peterstaler.de include:spf.protection.outlook.com include:spf.hornetsecurity.com include:spf-de.emailsignatures365.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbd0wsvS0el2QVr233KE6mZBH2kQtGeUmc4nXmVGdlJVcb6IZ4fXPm6jXlBbAw6RocItAlaI9gmK8ozP6ZRg… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLb4giy/M7fUgKb8cvJ564T8jJlF27rcBqstHqlIGgHZAXioe6KDUG7aFgzPPHzRJU4sp3n9ReXjYp75CILm…
selectors probed - selector1:
Certificate (current)
R12
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src data: blob: 'self' 'unsafe-inline' 'unsafe-eval' service.mtcaptcha.com service2.mtcaptcha.com www.peterstaler.de www.blackforest-still.de www.youtube.com developers.google.com maps.googleapis.com; style-src 'self' 'unsafe-inline' fast.fonts.net fonts.googleapis.com; img-src data: 'self' www.peterstaler.de www.blackforest-still.de maps.gstatic.com maps.googleapis.com i.ytimg.com; frame-src 'self' service.mtcaptcha.com service2.mtcaptcha.com www.youtube-nocookie.com; frame-ancestors 'self' www.peterstaler.de www.blackforest-still.de; connect-src 'self' www.peterstaler.de www.blackforest-still.de maps.googleapis.com; font-src 'self' fonts.gstatic.com data: fast.fonts.net; media-src 'self' t3:- strict-transport-security
max-age=31536000; includeSubDomains; preload