remeha.de
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (3)
- edge.sitecorecloud.io×18
- cdn.cookielaw.org×1
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2021-05-04
- Name servers
-
- dns1.safenames.com.
- dns2.safenames.net.
- dns3.safenames.org.
DNS records live
- NS
-
- dns1.safenames.com
- dns2.safenames.net
- dns3.safenames.org
- MX
-
- 10 mxa-001e2d01.gslb.pphosted.com
- 10 mxb-001e2d01.gslb.pphosted.com
- TXT
-
box-domain-verification=f9ba229e62e2d2c9d72472992af9c4eb33717f2f6159824b31a6f35f3d7c338arovag_verification_token=2B3221C42F254C1A92F54C9220C10B3E_9pcamt1hhqmdphmnfo4i78uc6fin9z1
- Verified for
-
- 1Password
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://cdn.cookielaw.org https://privacyportalde-cdn.onetrust.com https://*.youtube.com https://api-engage-eu.sitecorecloud.io https://edge.sitecorecloud.io https://ka-p.fontawesome.com https://kit.fontawesome.com https://xmc-bdrthermea1-platform-production.sitecorecloud.io/ https://xmf.remeha.co.uk https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://www.gstatic.com bdr-prd-platform-remehade-lupyy2rmj-bdr-thermea-group.vercel.app; script-src 'self' 'unsafe-inline' 'unsafe-eval' bdr-prd-platform-remehade-lupyy2rmj-bdr-thermea-group.vercel.app https://cdn.cookielaw.org https://privacyportalde-cdn.onetrust.com https://api-engage-eu.sitecorecloud.io https://*.googletagmanager.com https://*.google-analytics.com https://kit.fontawesome.com https://*.youtube.com https://vitals.vercel-insights.com https://edge-platform.sitecorecloud.io https://*.google.com https://www.gstatic.c- strict-transport-security
max-age=63072000; includeSubDomains; preload;