sundo.de
HTML metadata
Technology
- Server
- Apache
Social
Contact
- Phone
Registration
- Updated
- 2021-02-21
- Name servers
-
- ns1083.ui-dns.biz.
- ns1083.ui-dns.com.
- ns1083.ui-dns.de.
- ns1083.ui-dns.org.
DNS records live
- NS
-
- ns1083.ui-dns.biz
- ns1083.ui-dns.com
- ns1083.ui-dns.de
- ns1083.ui-dns.org
- MX
-
- 10 mx-01-eu-central-1.prod.hydra.sophos.com
- 20 mx-02-eu-central-1.prod.hydra.sophos.com
- TXT
-
Show 6 TXT records
1hkvrv2j8ccu1qcfrf6caespn0MS=4A927C83BF6F40EF4CD95DB8647319E4DF82EB29v=spf1 include:_spf_eucentral1.prod.hydra.sophos.com include:spf.dc-cluster.de include:spf.crsend.com -allqb92nphkfnshf8ls291hg2r7qasophos-domain-verification=8f8466d99e1c3577edc4d670a286105b94fbd30dhfpnsjj148c0geh4cup2jjpuev
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 264 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer-when-downgrade, strict-origin-when-cross-origin, no-referrer, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' https://www.google-analytics.com https://maps.googleapis.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'self'; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.youtube-nocookie.com; img-src 'self' https://i.ytimg.com data: https://i.vimeocdn.com https://www.google-analytics.com https://maps.gstatic.com https://maps.googleapis.com; object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com- strict-transport-security
max-age=31536000; includeSubDomains