stadtwerke-speyer.de
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Third-party hosts loaded (3)
- cdn.eye-able.com×2
- code.etracker.com×1
- translate-cdn.eye-able.com×1
Social
Contact
Registration
- Updated
- 2018-08-30
- Name servers
-
- docks15.rzone.de.
- shades19.rzone.de.
DNS records live
- NS
-
- docks15.rzone.de
- shades19.rzone.de
- MX
-
- 10 mx1.stadtwerke-speyer.de
- 20 mx2.stadtwerke-speyer.de
- 200 stadtwerkespeyer-de02e.mail.protection.outlook.com
- TXT
-
wiBYEPVaxOZRco2wZkU/72CbXVokZod6sLU1hHebcPI=BPoJFHLVGG05fApPpErw0K+mjwVl0THd+KrhHI+W+eY=
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:185.170.120.25 ip4:185.170.120.26 ip4:185.170.120.28 ip4:185.170.120.29 include:spf.protection.outlook.com include:amazonses.com include:spf.pitcom.net include:gipsprojekt.de include:spf.crsend.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCEzUhrDVaQa8NQ8mdL6YepUwKh4eQFwEnet81QqmJeYIwh6qV7rrHmbihx8ZI6LrHQTQ6NlUNa4x16ecvvi… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCbgbGXTYy8jpmm0covgZKyrI3YYKXuSFrGK15x3hzmLHwXCNex1iNKVaylX2p9SAQSBiq2AO+7ECpzk6r1DR…
selectors probed - selector1:
Certificate (current) wrong cert
Sectigo Public Server Authentication CA DV R36
Expires in 327 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob:; base-uri 'self'; form-action 'self'; font-src 'self' https://fonts.stadtwerke-ssl.de https://fonts.gstatic.com https://www.fairplaid.org; connect-src *; img-src 'self' data: blob: https://www.gipsprojekt.de https://cdn.eye-able.com https://www.google.com https://www.google.de https://maps.gstatic.com https://maps.googleapis.com https://cs-assets.b-ite.com https://www.facebook.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' blob: https://gipsprojekt.de https://www.gipsprojekt.de https://cdn.eye-able.com https://www.googletagmanager.com https://connect.facebook.net https://www.facebook.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://www.googleadservices.com https://www.google.com https://maps.google.com https://maps.googleapis.com https://static.b-ite.com https://cs-assets.b-ite.com https://www.stadtwerke-ssl.de https://code.etracker.com https://www.etracker.de https://translate-cdn.eye-able.com https://cdn.jsdelivr.net; fra- strict-transport-security
max-age=31536000; includeSubDomains