sahco.com
HTML metadata
Technology
- Server
- Apache
Social
Registration
- Registrar
- EuroDNS S.A.
- Created
- 1997-06-19
- Expires
- 2026-06-18 13 days left
- Updated
- 2025-06-13
- Name servers
-
- ns1.eurodns.com
- ns2.eurodns.com
- ns3.eurodns.com
- ns4.eurodns.com
DNS records live
- NS
-
- ns1.eurodns.com
- ns2.eurodns.com
- ns3.eurodns.com
- ns4.eurodns.com
- MX
-
- 10 dk.mx1.mailanyone.net
- 20 dk.mx2.mx25.net
- TXT
-
ba1ul8hqrb9c2da2na4rn5m0mqipgmml4fnvoidf0dd3ad08tc30
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 a mx a:kvadrat.org include:spf.protection.outlook.com ip4:193.110.84.200 ip4:72.35.23.0/24 ip4:72.35.12.0/24 ip4:192.162.216.0/22 ip4:208.70.128.0/21 ip4:185.38.180.0/22 ip4:89.104.206.0/23 ip4:68.71.200.64/27 ip4:168.245.38.204 ip6:2a01:77c0:1180::/46 ip6:2a01:77c0:6::/47 ip6:2001:978:2a01::/48 ip6:2001:978:2a02::/48 ip4:103.28.42.0/24 ip4:27.126.146.0/24 ip4:146.88.28.0/24 ip4:163.47.180.0/22 ip4:203.55.21.0/24 ip4:204.75.142.0/24 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 64 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
ALLOW-FROM https://vimeo.com/- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googletagmanager.com *.google-analytics.com *.googleapis.com *.cookieinformation.com *.clarity.ms unpkg.com; connect-src 'self' *.craftcms.com *.presscloud.com *.google-analytics.com *.doubleclick.net *.cookieinformation.com *.clarity.ms data: blob:; media-src 'self' *.vimeo.com *.akamaized.net *.vimeocdn.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.typekit.net; img-src 'self' *.sahco.com *.imgix.net *.google-analytics.com *.googletagmanager.com *.azureedge.net *.craft-cdn.com *.clarity.ms *.bing.com *.digitaloceanspaces.com data: blob:; frame-src 'self' vimeo.com *.youtube.com *.cookieinformation.com; font-src 'self' *.googleapis.com *.gstatic.com *.typekit.net data:;