refresco.de
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdn.ravenjs.com×1
- cookie-cdn.cookiepro.com×1
- fonts.googleapis.com×1
- js.hsforms.net×1
- www.googletagmanager.com×1
Registration
- Updated
- 2025-06-18
- Name servers
-
- ns1.openprovider.nl.
- ns2.openprovider.be.
- ns3.openprovider.eu.
DNS records live
- NS
-
- ns1.openprovider.nl
- ns2.openprovider.be
- ns3.openprovider.eu
- MX
-
- 10 refresco-de.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:94.199.88.0/22 ip4:82.135.18.0/23 ip4:62.245.148.0/26 ip4:62.134.45.32/28 ip4:217.111.120.0/27 ip4:94.199.89.34/32 ip4:94.199.92.185/32 ip4:212.117.77.134/32 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 19 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'nonce-RnPVlfCxlEubGS5azdeJUttD8uSBeTSE7l/5xnaZwiQ=' 'strict-dynamic' https: http:; style-src 'self' fonts.googleapis.com 'unsafe-inline'; style-src-attr 'unsafe-inline'; font-src 'self' data: fonts.gstatic.com static2.sharepointonline.com *.cloudfront.net res.cdn.office.net; img-src 'self' data: https://*.paradox.ai www.googletagmanager.com px.ads.linkedin.com cookie-cdn.cookiepro.com *.amazonaws.com img.youtube.com *.google-analytics.com www.facebook.com https://ml-eu.globenewswire.com *.cloudfront.net i.ytimg.com; frame-ancestors 'self' www.googletagmanager.com www.youtube.com refresco.com fizz.refresco.com staffbase.com capacitor://refresco.com capacitor://refresco.com; connect-src 'self' https://*.cloudfront.net *.google-analytics.com region1.google-analytics.com www.googletagmanager.com svrdntfctn.com cdn.ravenjs.com cdn.jsdelivr.net cdn.plyr.io geolocation.onetrust.com cookie-cdn.cookiepro.com https://paradox.ai wss://paradox.ai https://*.paradox.ai wss://*.par- strict-transport-security
max-age=31536000; includeSubDomains; preload