planetarymapping.eu
HTML metadata
Technology
- Server
- Apache
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- analytics.neamedia.it×1
- fonts.googleapis.com×1
Social
Contact
DNS records live
- NS
-
- ns.abdns.biz
- ns.abdns.eu
- ns.abdns.info
- MX
-
- 10 posta1.neamedia.it
- TXT
-
google-site-verification=XabzuSW5WOn588McUi_05nWMTG8_zA87oGpRrF_xqxo
Email authentication partial
- SPF
-
v=spf1 ip4:77.81.228.5 ip4:95.110.135.166 ip4:95.110.135.168 ip4:95.110.135.169 ip4:95.110.135.170 ip4:95.110.135.171 ip4:95.110.135.172 ip4:145.238.0.0/16 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=none; adkim=r; aspf=rpolicy: none (monitoring only) · sp=none - DKIM
-
- dkim:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8X4OSR7PsSL9nFwM/39qd8dkPzm6BINu31RseUl4Y9Cbs+iaT+bCjPhW7cthajHDTDssNVKlHDh41RQ70suKRyM3Gp…
selectors probed - dkim:
Certificate (current) wrong cert
E7
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=(), payment=(), usb=(), accelerometer=(), gyroscope=(), magnetometer=(), fullscreen=(self), display-capture=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://app.streavent.de https://*.streavent.de; default-src 'self' *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; img-src 'self' data: blob: *; font-src 'self' data: *; connect-src 'self' *; frame-src 'self' *; object-src 'none'; base-uri 'self'- strict-transport-security
max-age=31536000; includeSubDomains; preload
planetarymapping.eu