schreinerei-thummet.de
HTML metadata
Technology
- Server
- openresty
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (4)
- app.usercentrics.eu×3
- privacy-proxy.usercentrics.eu×3
- api.usercentrics.eu×1
- mtm.pax.de×1
Contact
- Phone
- Address
- 91077, Neunkirchen, DE
Registration
- Updated
- 2011-02-03
- Name servers
-
- docks14.rzone.de.
- shades11.rzone.de.
DNS records live
- NS
-
- docks14.rzone.de
- shades11.rzone.de
- MX
-
- 5 smtpin.rzone.de
Email authentication strong
- SPF
- not published
- DMARC
-
v=DMARC1;p=reject;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 44 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' https: *.mypax.website; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: *.mypax.website; object-src 'self' 'unsafe-inline' *.mypax.website; style-src 'self' 'unsafe-inline' data: https: *.mypax.website; img-src 'self' data: https: *.mypax.website *.canto.global; media-src 'self' 'unsafe-inline' data: https: *.mypax.website; frame-src 'self' 'unsafe-inline' data: https: *.mypax.website; frame-ancestors *; child-src 'self' 'unsafe-inline' data: https: blob: *.mypax.website; font-src 'self' 'unsafe-inline' https: data: *.mypax.website; connect-src *; report-uri /report-csp-violation; upgrade-insecure-requests- strict-transport-security
max-age=1000; includeSubDomains, max-age=63072000;includeSubDomains; preload