stadtwerke-greven.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Third-party hosts loaded (1)
- fonts.stadtwerke-ssl.de×2
Contact
Registration
- Updated
- 2021-01-18
- Name servers
-
- ns63.domaincontrol.com.
- ns64.domaincontrol.com.
DNS records live
- NS
-
- ns63.domaincontrol.com
- ns64.domaincontrol.com
- MX
-
- 10 stadtwerkegreven-de02e.mail.protection.outlook.com
- TXT
-
MS=56C2B86384762CE9F38C5A7C48178ED53D45A2B6MS=ms43512777google-site-verification=71w73dzSCb6B6JF6v69k_H-uTRmTXgRxjC9Qo1ER8Rs
Email authentication weak
- SPF
-
v=spf1 a mx ip4:153.100.8.31 ip4:153.100.8.32 include:spf.protection.outlook.com include:gipsprojekt.de include:_spf.salesforce.com include:_spf.smartservice.de include:spf.eu.exclaimer.net ip4:195.201.85.19 ip6:2a01:4f8:13b:3c82::2 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; media-src 'self'; base-uri 'self'; form-action 'self'; font-src 'self' https://embed.journey.epilot.io https://w5.plusportal.de https://images.plusportal.de https://fonts.stadtwerke-ssl.de https://fonts.gstatic.com https://storage.googleapis.com; connect-src *; img-src 'self' https://www.gipsprojekt.de https://app.energiehaus.stadtwerke-greven.evu-cloud.de:8081 https://app.energiehaus.stadtwerke-greven.evu-cloud.de https://embed.journey.epilot.io https://w5.plusportal.de https://images.plusportal.de https://maps.googleapis.com https://storage.googleapis.com https://maps.gstatic.com https://cs-assets.b-ite.com data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://app.energiehaus.stadtwerke-greven.evu-cloud.de https://embed.journey.epilot.io https://w5.plusportal.de https://connect.facebook.net https://storage.googleapis.com https://maps.google.com https://maps.googleapis.com https://static.b-ite.com https://cs-assets.b-ite.com blob:; frame-src * blob:; style- strict-transport-security
max-age=31536000; includeSubDomains; preload