stiftung-faro.ch
HTML metadata
Technology
- Server
- Microsoft-IIS
- jQuery
- 2.1.3 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- ajax.googleapis.com×2
- f1-eu.readspeaker.com×1
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- ns5.hintag.ch
- ns6.hintag.ch
- MX
-
- 10 mail3.hintag.ch
- 20 mail4.hintag.ch
- TXT
-
Show 8 TXT records
_t92ydv5gbbd01mbi9al94wvcel5ngrt_sl0d150ptnqp2wecir1bb8p9p63vf2t_5aei5x0dau82h25tik4iyozdanf9dxp_6r7ebi9g5lq9735g7v5kssymsqyihkf_e7zxzge3zxd5t56f6si12bqea5fdbgblz7sgy9lyn1qggt4vrmqvhvzfw0jyrlw1c9gt5kyw9pdkr949ztbstv9zz362ms4s2616cp7rmtsyh8wd5jx5frzc229m0qc
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx include:spf.mail.hostpoint.ch include:servers.mcsv.net a:mx3.hin.ch a:mx4.hin.ch ip4:168.119.26.180 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
sameorigin- permissions-policy
camera=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'self'; style-src 'self' 'unsafe-inline' hello.myfonts.net *.myfonts.net https://f1-eu.readspeaker.com; font-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com https://f1-eu.readspeaker.com *.googleapis.com *.googletagmanager.com; img-src 'self' *.raisenow.io; frame-src 'self' *.youtube.com scnem2.com *.youtube-nocookie.com *.vimeo.com *.google.com; connect-src 'self' https://f1-eu.readspeaker.com *.youtube-nocookie.com *.youtube.com *.google-analytics.com;- strict-transport-security
max-age=31536000
Links to (2)
Linked from (2)
- webzeit.ch×1
- vokus.ch×1