stall-frei.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (2)
- ka-p.fontawesome.com×2
- kit.fontawesome.com×1
Social
Registration
- Updated
- 2005-07-25
- Name servers
-
- ns2.bf-easy-webhosting.de.
- ns.bf-easy-webhosting.de.
DNS records live
- NS
-
- ns.bf-easy-webhosting.de
- ns2.bf-easy-webhosting.de
- MX
-
- 10 admin.stall-frei.de
- TXT
-
facebook-domain-verification=vwc4n1kitfwg9msa4zkxstlj0dgerv
Email authentication partial
- SPF
-
v=spf1 mx a include:spf.crsend.com include:spf.isrunning.de ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@stall-frei.depolicy: none (monitoring only) - DKIM
-
- mail:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPKgSk/Zz0M1IsxhyBRo+l+v3hXUr6SJzp71stquflpLcN8K5/8j5hx/pC7IwR2Zpn1KgqkpZpW+Hs2zag8A…
selectors probed - mail:
Certificate (current)
R12
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'none';script-src 'self' 'unsafe-inline' *.stall-frei.de *.maptiler.com *.fontawesome.com unpkg.com https://accounts.google.com/gsi/client https://appleid.cdn-apple.com/;img-src 'self' data: *.stall-frei.de *.maptiler.com *.fontawesome.com img.youtube.com *.ytimg.com *.gstatic.com translate.google.com https://appleid.cdn-apple.com/;style-src 'self' 'unsafe-inline' unpkg.com *.maptiler.com https://accounts.google.com/gsi/style https://appleid.cdn-apple.com/;child-src 'self' blob: mat.stall-frei.de s-static.ak.facebook.com www.facebook.com *.gstatic.com player.vimeo.com *.youtube.com;connect-src 'self' *.stall-frei.de api.maptiler.com *.fontawesome.com https://accounts.google.com/gsi/ https://appleid.cdn-apple.com/;form-action 'self';frame-ancestors 'self';frame-src https://accounts.google.com/gsi/ https://appleid.cdn-apple.com/ https://www.facebook.com/plugins/ https://player.vimeo.com/video/ https://www.youtube.com/embed/;base-uri 'self';manifest-src 'self';object-src 'self- strict-transport-security
max-age=31536009; includeSubDomains; preload