steep.de
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (1)
- cdn.datatables.net×3
Social
Contact
- Phone
Registration
- Updated
- 2019-11-19
- Name servers
-
- ns1.steep.de.
- ns2.steep.de.
- ns3.steep.de.
DNS records live
- NS
-
- ns1.steep.de
- ns2.steep.de
- ns3.steep.de
- MX
-
- 10 mxgs02ul.steep.de
- 5 mxgs06bn.steep.de
- TXT
-
apple-domain-verification=GCDqtH37mBWnrogVd56aaae2efef4681a72c098d7f962729cisco-ci-domain-verification=5b6664ea1e11497a737b7587efcdce1d5a655fc2accfabff5316708819b900e
Email authentication strong
- SPF
-
v=spf1 mx ip4:116.203.247.82 ip4:116.203.247.147 ip4:116.203.247.148 ip4:159.69.140.88 ip4:84.44.161.37 ip4:84.44.161.65 include:spf.de.umantis.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=reject; adkim=s; aspf=s; rua=mailto:rua-dmarc@steep.de; ruf=mailto:rua-dmarc@steep.de; fo=1; ri=172800;policy: quarantine · sp=reject - DKIM
-
- s1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxv0ubZoEq7OxapX5dhG7Bavm1LGzbM3m86/Pe2xf/YBDdBwLKGr/L8nD3uESezd27BIAX2I26VXeHE…
selectors probed - s1:
Certificate (current)
R12
Expires in 25 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://matomo.rdts.de/ https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; img-src 'self' https://*.kununu.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://secure.gravatar.com/; frame-src 'self' *.google.com *.youtube-nocookie.com *.youtube.com *.steep.de; connect-src 'self' https://matomo.rdts.de/ https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; font-src 'self' https://fonts.gstatic.com data:; media-src 'self' *.youtube.com *.youtube-nocookie.com data:; object-src 'self' *.googlevideo.com *.ytimg.com *.youtube.com *.youtube-nocookie.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;- strict-transport-security
max-age=63072000