studysmarter.es
HTML metadata
Technology
- Server
- BunnyCDN-DE1-1331
- CMS
- WordPress
- Analytics
-
- Google Analytics
- Google Tag Manager
- Hotjar
- Ads
-
- Meta Pixel
- TikTok Pixel
- Cookie consent
-
- Termly
Third-party hosts loaded (17)
- website-cdn.studysmarter.de×57
- www.googletagmanager.com×3
- analytics.tiktok.com×2
- connect.facebook.net×2
- dev.visualwebsiteoptimizer.com×2
- resources.usersnap.com×2
- script.hotjar.com×2
- w.likebtn.com×2
- www.google-analytics.com×2
- www.gstatic.com×2
- app.termly.io×1
- cdn.fuseplatform.net×1
- www.studysmarter.co.uk×1
- www.studysmarter.de×1
- www.studysmarter.fr×1
- www.studysmarter.it×1
- www.vaia.com×1
Social
DNS records live
- NS
-
- ns-1073.awsdns-06.org
- ns-1641.awsdns-13.co.uk
- ns-178.awsdns-22.com
- ns-945.awsdns-54.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=none; rua=mailto:postmaster+dmarc@studysmarter.de; fo=1policy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs6ajuPOUBabM5LvOHWvm3S0uDA+xPXI1xEujh3/NoUAFyCcX2VC/0cCmOjEpV5q7+BN3LpNz4eI5pM9SpL… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDHpqA6z+w2fKzRFG2ibVRVtkiZvWepUKTzrN6eKGAxnOjNBvXd/6+fhdTbI1xq3SYePofuNP+jpcYfx7L/HIx3v1…
selectors probed - s1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 150 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.youtube.com *.vimeo.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin