prospekt-edeka.de
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
Third-party hosts loaded (3)
- scripts.publitas.com×3
- view.publitas.com×2
- cdn.jsdelivr.net×1
DNS records live
- NS
-
- a.ns14.net
- b.ns14.net
- c.ns14.net
- d.ns14.net
- ns01.w-commerce.de
- MX
-
- 10 mx02.w-commerce.de
Email authentication weak
- SPF
-
v=spf1 include:spf-edith.haake.com mx ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'nonce-8I3d2nGmH1YGfZ02M4kwHg==' https: http:; object-src 'none'; base-uri 'self'; report-uri https://o23229.ingest.sentry.io/api/5518230/security/?sentry_key=42c084127e7f448dbf2996950d578de0- strict-transport-security
max-age=63113904