sistrix.es
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (6)
- www.sistrix.com×8
- www.sistrix.de×8
- app.sistrix.com×2
- assets.sistrix.com×1
- cdn.sistrix.com×1
- gmpg.org×1
Social
DNS records live
- NS
-
- ns-1165.awsdns-17.org
- ns-1599.awsdns-07.co.uk
- ns-276.awsdns-34.com
- ns-943.awsdns-53.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
facebook-domain-verification=jyyhlw4n9db8qwq2hlsqzx2qqbz3a5google-site-verification=TeRYM3lTmVvXpqwXYQyJqUtPdXAodtjfEdHhnJR76t4
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 303 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
img-src *.sistrix.com *.sistrix.de *.sistrix.it *.sistrix.fr *.sistrix.es *.facebook.com *.linkedin.com *.ytimg.com secure.gravatar.com data: https: 'self'; style-src *.sistrix.com *.sistrix.de *.sistrix.it *.sistrix.fr *.sistrix.es *.vimeocdn.com *.vimeo.com data: https: 'unsafe-inline' 'self'; object-src *.sistrix.com *.sistrix.de *.sistrix.it *.sistrix.fr *.sistrix.es data: https: 'unsafe-inline' 'self'; script-src *.sistrix.com *.sistrix.de *.sistrix.it *.sistrix.fr *.sistrix.es data: https: 'unsafe-eval' 'unsafe-inline' 'self';- strict-transport-security
max-age=300; includeSubDomains
Links to (8)
- sistrix.com×4
- omr.com×3
- sistrix.de×3
- sistrix.fr×3
- twitter.com×3
- doppelgaenger.io×3
- sistrix.net×3
- sistrix.it×1
Linked from (4)
- sistrix.fr×3
- sistrix.de×3
- aulacm.com×2
- sistrix.com×2