schuerholz-group.com
HTML metadata
Technology
- Server
- Apache
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (4)
- sdp.eu.usercentrics.eu×3
- app.eu.usercentrics.eu×2
- api.eu.usercentrics.eu×1
- web.cmp.usercentrics.eu×1
Social
DNS records live
- NS
-
- ns1a.dodns.net
- ns2a.dodns.net
- MX
-
- 10 mail.schuerholz-group.com
- 20 mail2.schuerholz-group.com
- 30 mail.schuerholzit.com
- TXT
-
Show 8 TXT records
MS=3E0AA291C395CC7F1AE3B252FAA38E900799D4153fi3ail2fe84l81mnn6rhdfjtubtiZTB2lfIm41TxTYDd1IUFnMEABUVxp0akcio7qSHINgYy+0iM+ZROaS+Dql2QcmOO7Wt9DqAgwnanks8ZgPQ==8GfRXqlNu+15zgrwPMji37K1fIxpDke+AitGhNjLol0=u91ahluhngh7m614kou56dauk956o1bd9dkat974q02v41g0pvnmswisssign-check=exNhcM-xleXZpWXPqyISFWBY6AY1mchdnv9rg1qu6l9kb73dhvo7f
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 mx -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; ri=3600policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 262 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin, same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'none', default-src 'unsafe-inline' 'self' https://*.usercentrics.eu data: blob:;- strict-transport-security
max-age=31536000; includeSubDomains, max-age=2592000; includeSubdomains