schaumann.cz
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (14)
- www.schaumann.de×2
- app.usercentrics.eu×1
- code.etracker.com×1
- www.schaumann.at×1
- www.schaumann.ch×1
- www.schaumann.fi×1
- www.schaumann.fr×1
- www.schaumann.hr×1
- www.schaumann.hu×1
- www.schaumann.it×1
- www.schaumann.pl×1
- www.schaumann.ro×1
- www.schaumann.sk×1
- www.schaumann.vn×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns.nts.cz
- ns2.nts.cz
- MX
-
- 0 schaumann-cz.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf01.hh-group.info include:_spf.eshop-rychle.cz -allstrict (-all) - DMARC
- not published
- DKIM
-
- mail:
v=DKIM1; k=rsa; n=2048; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA/skyocQWKukFnv/iASqLiuevmQASV7Y6wFgs9eKbAMKxdr7Hr/RO1T0MEKNZMUBVR3kzOu…
selectors probed - mail:
Certificate (current)
R13
Expires in 85 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'none'; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.etracker.de https://*.etracker.com https://www.googletagmanager.com https://*.usercentrics.eu; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.etracker.de https://*.etracker.com https://www.googletagmanager.com https://*.usercentrics.eu https://huelsenberg.coremedia.cloud https://*.huelsenberg.coremedia.cloud; font-src 'self' data:; style-src 'self' 'unsafe-inline' https://*.etracker.com https://*.usercentrics.eu; img-src 'self' data: https://*.etracker.de https://*.etracker.com https://*.usercentrics.eu; connect-src 'self' https://*.etracker.de https://*.etracker.com https://www.googletagmanager.com https://*.usercentrics.eu https://*.huelsenberg.coremedia.cloud; frame-src 'self' https://formcycle.hh-group.info https://www.youtube.com https://player.vimeo.com https://www.google.com; frame-ancestors 'self' https://*.etracker.com https://*.huelsenberg.coremedia.cloud; upgrade-- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin
Links to (12)
Linked from (2)
- holstein.cz×1
- zscr.cz×1