saal-digital.es
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (28)
- photoservice.cloud×79
- b-shop.saal-digital.net×3
- www.saal-digital.de×2
- img.youtube.com×1
- web.cmp.usercentrics.eu×1
- www.saal-digital.at×1
- www.saal-digital.bg×1
- www.saal-digital.ch×1
- www.saal-digital.co.uk×1
- www.saal-digital.com×1
- www.saal-digital.cz×1
- www.saal-digital.dk×1
- www.saal-digital.ee×1
- www.saal-digital.eu×1
- www.saal-digital.fi×1
- www.saal-digital.fr×1
- www.saal-digital.gr×1
- www.saal-digital.hu×1
- www.saal-digital.it×1
- www.saal-digital.lt×1
- www.saal-digital.lv×1
- www.saal-digital.nl×1
- www.saal-digital.pl×1
- www.saal-digital.pt×1
- www.saal-digital.ro×1
- www.saal-digital.se×1
- www.saal-digital.si×1
- www.saal-digital.sk×1
Social
DNS records live
- NS
-
- ns-1189.awsdns-20.org
- ns-1740.awsdns-25.co.uk
- ns-247.awsdns-30.com
- ns-891.awsdns-47.net
- MX
-
- 10 saaldigital-es01b.mail.protection.outlook.com
- TXT
-
MS=ms39867918google-site-verification=OwGbAYseHueDdrMazfif4Vf2cltrUA1nlpdqPyb6RQc
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:saal-digital.de -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:t3p0w5icc1@rua.powerdmarc.com; ruf=mailto:t3p0w5icc1@ruf.powerdmarc.com;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwVbyWHVFRitam/QGTJx6vMyk6BP4+GCdo5CURGPU+K9DQ5oY2VoKSCVdp9FU4TA2c9Zquac1/q8VTz…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 187 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: about:; frame-ancestors 'self'; img-src 'self' 'unsafe-eval' data: blob: about: *.awin1.com *.doubleclick.net *.trbo.com *.gstatic.com *.google.de *.google.com *.youtube.com *.amazonaws.com *.bing.com *.clarity.ms photoservice.cloud *.google-analytics.com *.cdninstagram.com *.saal-digital.net *.saal-digital.com *.saal-digital.de *.photo-portal.shop *.googleusercontent.com *.paypal.com *.paypalobjects.com *.hotjar.com *.facebook.com *.ytimg.com *.cookiepro.com *.bing.net *.usercentrics.eu; script-src 'self' 'unsafe-eval' 'unsafe-inline' about: *.awin1.com *.sciencebehindcommerce.com *.roeyecdn.com *.dwin1.com *.trbo.com *.saal-digital.net *.photo-portal.shop *.clarity.ms *.bing.com *.hotjar.com *.facebook.net blob: about: *.cookiepro.com *.amazonaws.com photoservice.cloud *.google-analytics.com *.googletagmanager.com *.cdninstagram.com *.google.com *.paypalobjects.com *.paypal.com *.sovendus.com *.googleapis.com *.usercentrics.eu; style-src 'self' 'unsafe-eval'- strict-transport-security
max-age=86400; includeSubDomains; preload