scs-holzshop.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (3)
- static.klaviyo.com×1
- web.cmp.usercentrics.eu×1
- widgets.trustedshops.com×1
Social
Contact
Registration
- Updated
- 2013-03-27
- Name servers
-
- docks18.rzone.de.
- shades17.rzone.de.
DNS records live
- NS
-
- docks18.rzone.de
- shades17.rzone.de
- MX
-
- 10 de-smtp-inbound-1.mimecast.com
- 10 de-smtp-inbound-2.mimecast.com
- TXT
-
klaviyo-site-verification=XJp52d
- Verified for
-
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a:mail.scheiffele-schmiederer.de include:spf.protection.outlook.com include:srv-a-cc.c-1632.maxcluster.net include:de._netblocks.mimecast.com include:servers.mcsv.net ip4:212.118.201.158 ip4:212.118.201.156 ip4:159.48.12.233 ip6:2A05:CC00::12:233:10 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
E8
Expires in 76 days
HTTP security headers
- present
-
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- missing Content Security Policy
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy-report-only
font-src www.paypalobjects.com fonts.gstatic.com https://widgets.trustedshops.com typesense.c-479.maxcluster.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com typesense.c-479.maxcluster.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com consentcdn.cookiebot.com *.etrusted.com *.trustedshops.com sst.scs-holzshop.de *.adcell.com *.google.com safeframe.googlesyndication.com *.googletagmanager.com typesense.c-479.maxcluster.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.pa