rollingpinconvention.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.facebook.com×2
- js.hs-scripts.com×1
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2020-06-03
- Name servers
-
- dns1.sysup.at.
- dns2.sysup.at.
- dns3.sysup.at.
- dns4.sysup.at.
- dns5.sysup.at.
DNS records live
- NS
-
- dns1.sysup.at
- dns2.sysup.at
- dns3.sysup.at
- dns4.sysup.at
- dns5.sysup.at
- MX
-
- 10 rollingpinconvention-de.mail.protection.outlook.com
- TXT
-
MS=ms20801582
Email authentication weak
- SPF
-
v=spf1 a mx ip4:77.75.20.200/29 ip4:91.220.179.12 ip4:91.220.179.17 ip4:77.75.21.128/29 ip4:77.75.22.56/29 ip4:81.223.79.128/28 include:sysup.email include:amazonses.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 79 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing content type protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- content-security-policy
default-src 'self' http://*.bugherd.com https://*.bugherd.com https://bugherd-attachments.s3.amazonaws.com wss://ws.pusherapp.com http://*.addthis.com https://*.addthis.com http://*.fontawesome.com https://*.fontawesome.com http://*.rollingpin.at https://*.rollingpin.at http://*.rollingpin.eu https://*.rollingpin.eu http://*.hotjar.com https://*.hotjar.com ws://*.hotjar.com http://*.hotjar.com:12080 http://*.userlike.com https://*.userlike.com ws://*.userlike.com wss://*.userlike.com https://js.hs-scripts.com https://*.hs-scripts.com https://hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hscollectedforms.net https://*.hscollectedforms.net https://*.hubspot.com http://*.googleadservices.com https://*.googleadservices.com http://*.google-analytics.com https://*.google-analytics.com http://*.facebook.com https://*.facebook.com https://*.zapier.com https://*.tiktok.com https://*.mapbox.com https://*.gleap.io wss://ws.gleap.io; font-src 'self' data: http://th