sennebogen-stiftung.de
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- www.sennebogen.com×2
- i.ytimg.com×1
- s.ytimg.com×1
- www.google.com×1
- www.googletagmanager.com×1
- yt3.ggpht.com×1
Social
Contact
- Phone
Registration
- Updated
- 2019-07-08
- Name servers
-
- a.ns14.net.
- b.ns14.net.
- c.ns14.net.
- d.ns14.net.
DNS records live
- NS
-
- a.ns14.net
- b.ns14.net
- c.ns14.net
- d.ns14.net
- TXT
-
domainVerification=981c2f41-eaf3-43f2-a6c4-a73d4af79406_globalsign-domain-verification=EXyRwYOncTc05ZnBC8xHJyC3tYwbf10xYE6JhqS1QL
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), vr=(), speaker=(), ambient-light-sensor=(), gyroscope=(), microphone=()- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'none'; object-src 'self'; media-src 'self' data: ; font-src 'self' data: fonts.gstatic.com use.typekit.net p.typekit.net; manifest-src 'self'; connect-src 'self' wss: api.leadinfo.com www.facebook.com region1.analytics.google.com region1.google-analytics.com *.tiktokw.us ltracking.de analytics.tiktok.com metrics.articulate.com *.leadinfo.net www.google-analytics.com stats.g.doubleclick.net www.clarity.ms https://s.clarity.ms app.lea-software.com cdp.cloud.unity3d.com config.uca.cloud.unity3d.com *.lf-discover.com cdn.plyr.io maps.googleapis.com cdn.linkedin.oribi.io https://px.ads.linkedin.com https://marketing-test.sennebogen.com/ https://marketing.sennebogen.com https://api.cleverpush.com https://static.cleverpush.co https://docs.google.com https://doc-0c-74-sheets.googleusercontent.com/pub; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://static.cloudflareinsights.com *.googleapis.com www.enterpriseagileconsortium.com sc.lfeeder.com cdn.leadinfo.net cdn.lea- strict-transport-security
max-age=31536000; includeSubDomains