serto.com
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (4)
- app.usercentrics.eu×1
- data.my.permaleads.ch×1
- privacy-proxy.usercentrics.eu×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- CH: SERTO AG+41 52 368 11 11shop-ch@serto.cominfo-ch@serto.com
Registration
- Registrar
- NetZone AG
- Created
- 1997-02-28
- Expires
- 2027-03-01 273 days left
- Updated
- 2026-02-22
- Name servers
-
- ns1.netzone.ch
- ns2.netzone.ch
- ns3.netzone.ch
DNS records live
- NS
-
- ns1.netzone.ch
- ns2.netzone.ch
- ns3.netzone.ch
- MX
-
- 0 serto-com.mail.protection.outlook.com
- TXT
-
swisssign-check=1xv6wM6mhylSAO9KaIV44ENeH-gsophos-domain-verification=ca6d753255d0390b12012e4757cb1b4bb7e23384fc994a53c60ef540711f8b4b
- Verified for
-
- Apple
- Cisco
Email authentication weak
- SPF
-
v=spf1 mx include:spf.protection.outlook.com ip4:195.49.23.50 include:_spf.senders.scnem.com include:_spf.jpberlin.de -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv87vir5pIs77+0KMm81YMDnHbj1RNaoKX5t6bn3770uGd/jamtUizXsalvkiIEoB8k59t6oa7BMZHK… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0eL700eOI1PWZXuPd/wUdqrTqmGWE1ol3WeUZMaIHzRdkuER4/zaDkZ97V3296SLdDmPkKx38qYV/t…
selectors probed - selector1:
Certificate (current)
E8
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' data:; font-src * data:; img-src * data:; script-src 'unsafe-eval' 'unsafe-inline' *.serto.com *.exmar.de *.heidelpay.com *.unzer.com webapi.partcommunity.com privacy-proxy.usercentrics.eu app.usercentrics.eu www.googletagmanager.com data.my.permaleads.ch cdn.mouseflow.com; style-src * 'unsafe-inline'; frame-src 'self' *.heidelpay.com *.unzer.com www.youtube-nocookie.com player.vimeo.com webapi.partcommunity.com app.usercentrics.eu live.solique.ch; connect-src 'self' *.heidelpay.com *.unzer.com webapi.partcommunity.com *.usercentrics.eu data.my.permaleads.ch *.google-analytics.com scnem3.com evprxy.test.brandweite.com *.mouseflow.com scnem3.com; object-src 'none'; frame-ancestors 'self' *.partcommunity.com; worker-src blob:;- strict-transport-security
max-age=31536000; includeSubDomains; preload