st-lukas-nuernberg.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Registration
- Updated
- 2020-08-19
- Name servers
-
- ns3.powerdns.de.
- ns4.powerdns.de.
DNS records live
- NS
-
- ns3.powerdns.de
- ns4.powerdns.de
- MX
-
- 10 mail.die-otts.net
- TXT
-
mailconf=https://autoconfig.st-lukas-nuernberg.de/mail/config-v1.1.xml
Email authentication weak
- SPF
-
v=spf1 ip4:134.119.111.20 ip6:2a00:1158:2:4100::2 ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- mail:
v=DKIM1; h=sha256; k=rsa; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAnGx5HVD3/JkQEB18s6rkczabjJT2OHADavs24Vz/K6UAssRkYPnFWVbpMQwwO9GmOrph…
selectors probed - mail:
Certificate (current)
E7
Expires in 44 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer 'none' ; autoplay 'none' ; camera 'none' ; encrypted-media 'none' ; fullscreen 'none' ; geolocation 'none' ; gyroscope 'none' ; magnetometer 'none' ; microphone 'none' ; midi 'none' ; payment 'none' ; sync-xhr 'none' ; usb 'none'- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https:- strict-transport-security
max-age=15552000; includeSubDomains; preload;