rauch.de
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- cdn.consentmanager.net×1
Social
Contact
- Phone
- Address
- Boulevard E 20077836
Registration
- Updated
- 2013-03-22
- Name servers
-
- ns1.inline.de.
- ns2.inline.de.
DNS records live
- NS
-
- ns1.inline.de
- ns2.inline.de
- MX
-
- 10 mx01.badencloud.de
- 20 mx02.badencloud.de
- TXT
-
duo_sso_verification=BamfORj89Lane2x1iR85HzaBxxHeZSIjvipmBLhqtFsbyyhlvcYo4g5AiWoANRbYMS=ms30655675cisco-ci-domain-verification=564ae8e00f663aef678bea1f25f024387627f065ec6708938df9e60b7ba8fb6a
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.mailjet.com include:inline.de include:_spf-ipa.badencloud.de ip4:93.186.160.0/20 include:spf.crsend.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 22 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=*, autoplay=*, picture-in-picture=*, accelerometer=(), attribution-reporting=(), bluetooth=(), browsing-topics=(), camera=(), compute-pressure=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), geolocation=(), gyroscope=(), hid=(), identity-credentials-get=(), idle-detection=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), otp-credentials=(), payment=(), publickey-credentials-create=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), storage-access=(), usb=(), web-share=(), window-management=(), xr-spatial-tracking=(), accelerometer=()- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; default-src 'self'; base-uri 'none'; connect-src 'self' https://a.delivery.consentmanager.net https://rauch.matomo.cloud https://www.google.com https://maps.googleapis.com; font-src 'self' data: ; form-action 'self' https://eu.cleverreach.com/f/27099-41626/wcs/ ; frame-ancestors 'self'; frame-src 'self' https:; img-src 'self' data: 'unsafe-inline' https://maps.gstatic.com https://maps.google.com https://cdn.consentmanager.net https://a.delivery.consentmanager.net ; manifest-src 'self'; media-src 'self' https://a.delivery.consentmanager.net/delivery/info/ https://cdn.consentmanager.net/delivery/; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net/npm/friendly-challenge@0.9.8/widget.min.js https://maps.googleapis.com/maps/api/js https://www.google.com/recaptcha/api.js https://cdn.consentmanager.net/delivery/autoblocking/4561707688f5.js https://cdn.consentmanager.net/delivery/ https://a.delivery.consentmanager.net/- strict-transport-security
max-age=31536000; preload