roemerholz.ch
HTML metadata
Technology
- CMS
- Nuxt
Third-party hosts loaded (1)
- prod-roemerholzch-hcms-sdweb.imgix.net×8
Social
Contact
- Phone
DNS records live
- NS
-
- ins1.admin.ch
- ins2.admin.ch
- ins3.admin.ch
- ins4.admin.ch
- ins5.admin.ch
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
SwissSign RSA TLS OV ICA 2022 - 1
Expires in 247 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' http://*.ws-old.parlament.ch https://*.admin.ch https://*.alexandria.ch https://*.baspomedia.ch https://*.cloudflare.com https://*.codepen.io https://*.dwcdn.net https://*.everviz.com https://*.fliphtml5.com https://*.googleapis.com https://*.infogram.com https://*.issuu.com https://*.media.dma.swiss https://*.media.zem.ch/ https://*.raceresult.com https://*.polyfill.io https://*.youtube.com https://api.mailxpert.ch https://cdn.syndication.twimg.com https://connect.facebook.net https://embed-cdn.surveyhero.com https://embed.ticketpark.ch https://embed.typeform.com https://fliphtml5.com https://issuu.com https://livingdocs-assets.s3-eu-west-1.amazonaws.com https://media.dma.swiss https://platform.twitter.com https://player.vimeo.com https://snap.licdn.com https://webstats.ch.ch https://webstat.2edaadmin.ch https://siteimproveanalytics.com https://plugin.passolution.eu ; style-src-elem 'self' 'unsafe-inline' *.dwcdn.net- strict-transport-security
max-age=16070400; includeSubDomains