sommerlad.de
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2019-07-22
- Name servers
-
- ns.udag.de.
- ns.udag.net.
- ns.udag.org.
DNS records live
- NS
-
- ns.udag.de
- ns.udag.net
- ns.udag.org
- MX
-
- 0 sommerlad-de.mail.protection.outlook.com
- TXT
-
mistral-domain-verification=cfdfb7676b2254a55af08738b83becdaeccf7267
- Verified for
-
- Brevo
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 mx include:spf.protection.outlook.com include:spf.emailsignatures365.com a:er-mail.erecruiter.net include:agenturserver.de include:_spf_v4.webhosting.systems ip4:62.153.168.200/29 ip4:87.191.157.107 ip4:80.147.185.65 ip4:80.151.49.190 ip4:80.151.121.212 ip4:80.153.2.58 ip4:80.153.185.236 ip4:80.153.222.132 ip4:80.153.222.136 ip4:87.128.2.247 ip4:87.129.161.152/29 ip4:87.130.125.160/29 ip4:87.138.223.25 ip4:87.138.184.57 ip4:87.140.51.233 ip4:91.16.37.81 ip4:87.191.166.32 ip4:217.86.203.96 ip4:217.89.74.144/29 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; ruf=mailto:authfail@sommerlad.de; rua=mailto:aggrep@sommerlad.depolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwFMAr+8fsKt9y1Cl0HDGHXTr3+yFLlkjTCLdgzWC4LP1U83uAB+5sZt3ewKpWPJGCxRGzIUI1B1whr… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzpkInhEx4KVbn4qsU3ohs2XCt3qujflY89TPyWezuKqu/TnO0rDHfK1+WJEFRdsaKVSYpwhvGtojhCjHRL… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApQDrWkrxzQmuAVL1dKhHuFCzIAgD/fBnQzV4Xt4XRBKLgijtsObUZHUIQymazzJwxM3PsNG54VAYaTUdJx…
selectors probed - selector1:
Certificate (current)
R13
Expires in 31 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-eval' 'unsafe-inline' data: sommerlad.de *.sommerlad.de sellanizer.net *.sellanizer.net service-check.com *.service-check.com googletagmanager.com *.googletagmanager.com planungswelten.de *.planungswelten.de cookiebot.com *.cookiebot.com googlesyndication.com *.googlesyndication.com google-analytics.com *.google-analytics.com *.google.com *.google.de doubleclick.net *.doubleclick.net facebook.net *.facebook.net facebook.com *.facebook.com googleadservices.com *.googleadservices.com ldnzr.de *.ldnzr.de saleschecker.io *.saleschecker.io *.stackadapt.com *.youtube-nocookie.com; frame-src *;