sec-hosting.de
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
Contact
- Phone
Registration
- Updated
- 2024-01-21
- Name servers
-
- helium.ns.hetzner.de.
- hydrogen.ns.hetzner.com.
- oxygen.ns.hetzner.com.
DNS records live
- NS
-
- helium.ns.hetzner.de
- hydrogen.ns.hetzner.com
- oxygen.ns.hetzner.com
- MX
-
- 10 mx1.sec-hosting.de
- TXT
-
Show 4 TXT records
apple-domain-verification=9U3ThXI73L872nyC-TgODEfYIlkt5b8qbvrShIvYA8Egoogle-site-verification=3bwbzLbf-CM3OFtxRUMG_oY2n4gu95bFLKkfYD1oZzQgoogle-site-verification=tN14NVObuTjdxE2IKCselk6TMM-rjBqXLwnKRbDaj1sv=DMARC1; p=reject;
Email authentication strong
- SPF
-
v=spf1 ip4:5.158.166.162 ip4:5.75.249.34 a mx -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:mailauth-reports@sec-hosting.de;policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw8ArPplfcB8zLfmVUKpx2b5GTOmZU9th+7254joVwnvqd7DvDHsJrcY3PRMXQg1I1A224y8DPrmB6RXqO3VV4…
selectors probed - default:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 193 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' data: 'unsafe-inline'; img-src 'self' sec-hosting.de data: sec-hosting.de; font-src 'self' data:- strict-transport-security
max-age=63072000; includeSubDomains