smzh.ch
HTML metadata
Technology
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.hoststar.hosting
- ns2.hoststar.hosting
- MX
-
- 10 smzh-ch.mail.protection.outlook.com
- Verified for
-
- Anthropic
Email authentication weak
- SPF
-
v=spf1 include:_spf.mailersend.net ip4:164.4.49.130 ip4:178.197.220.59 ip4:212.98.43.24 include:spf.protection.outlook.com include:spf-de.emailsignatures365.com include:_spf.salesforce.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCc3BzPPraShISvb6H69FANtP9ouGK0Sj9lWy1z3WQLHCuS7ej8RNo9nO6Fk8fHIg3aFQcIi1LZ+AwF6Qh/75… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPXawnb0omqOJlZnpLCzoCKPeLF+hFgGMTUtVLgmIaHF6IJEhCYU7ur5cdmtm5f1IAsubCYUUhjdWmm7SXl+… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
YR2
Expires in 89 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://s0.2mdn.net https://analytics.tiktok.com https://connect.facebook.net https://smzh.my.site.com https://smzh.my.salesforce-scrt.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://smzh.my.site.com https://smzh.my.salesforce-scrt.com; img-src 'self' data: blob: https://images.unsplash.com https://plus.unsplash.com https://cdnjs.cloudflare.com https://www.google.com https://www.google.al https://www.google.ch https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.gstatic.com https://sst.internal.smzh.ch https://www.facebook.com https://cms.smzh.ch https://smzh.ch https://gatewayapi.smzh.ch; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://vitals.vercel-insights.com https://www.- strict-transport-security
max-age=31536000; includeSubDomains