spinnrad.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (3)
- d1rbyh6cf2zqb7.cloudfront.net×6
- widgets.trustedshops.com×1
- www.facebook.com×1
Social
Contact
- Address
- Bahnhofstr. 1-3, 23795, Bad Segeberg
Registration
- Updated
- 2022-09-14
- Name servers
-
- auth1.artfiles.de.
- auth2.artfiles.de.
DNS records live
- NS
-
- auth1.artfiles.de
- auth2.artfiles.de
- MX
-
- 0 spinnrad-de.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
_badrhmqd6hs5w1xa7mjwd2q9thd46wo03g0kh0n3dskwjywxm6xkkmtqlhs4b2tfacebook-domain-verification=js02o45pi0flxtprjnoldbq6foj40pzx0rmnmqn38d3qjccl4k3885cd03v0h7
Email authentication weak
- SPF
-
v=spf1 a a:spinnrad.de include:spf.protection.outlook.com include:spf.crsend.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 126 days
HTTP security headers
- present
-
- content-security-policy-report-only
- x-content-type-options
- findings
-
- missing HSTS
- missing Content Security Policy
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy-report-only
font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cleverreach.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com *.google.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adob