schmidtspiele-shop.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×2
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2013-07-18
- Name servers
-
- ns1.im-netz.de.
- ns2.im-netz.de.
- ns.im-netz.de.
DNS records live
- NS
-
- ns.im-netz.de
- ns1.im-netz.de
- ns2.im-netz.de
- MX
-
- 0 schmidtspieleshop-de03c.mail.protection.outlook.com
- Verified for
-
- Meta
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:194.6.209.69 ip4:194.6.209.70 ip4:185.60.20.2 ip6:2a00:f48:1008::209:69:10 ip6:2a00:f48:1008::209:70:10 ip4:185.60.20.0/24 ip4:54.246.203.105 -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtfxyY3rJ1l4ex0WIXfZse7GtiQswiYMYeOMbZY50dzSnedMHo9iUhdqnsrkKJxzwPSLVUFkHTV7fzO…
selectors probed - selector1:
Certificate (current)
E8
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=31536000- content-security-policy-report-only
font-src applepay.cdn-apple.com www.gstatic.com fonts.gstatic.com cfg.schmidtspiele-shop.de data: 'self' 'unsafe-inline'; form-action facebook.com www.facebook.com graph.facebook.com connect.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src payments.amazon.de applepay.cdn-apple.com challenges.cloudflare.com td.doubleclick.net facebook.com www.facebook.com graph.facebook.com connect.facebook.net *.google.com www.google.com/recaptcha/ www.googletagmanager.com googletagmanager.com jsctool.com www.jsctool.com js.playground.klarna.com secure.pay1.de player.vimeo.com *.youtube-nocookie.com *.youtube.com 'self' 'unsafe-inline'; img-src *.cloudfront.net *.cookielaw.org data: googleads.g.doubleclick.net *.g.doubleclick.net facebook.com www.facebook.com graph.facebook.com connect.facebook.net www.google-analytics.com *.google-analytics.com www.google.com analytics.google.com *.google.com *.analytics.google.com google.com *.google.de www.googleadservices.com *.googleapis.com