sw-lindau.de
HTML metadata
Technology
- CMS
- Gatsby
Social
Contact
Registration
- Updated
- 2022-12-29
- Name servers
-
- ns29.domaincontrol.com.
- ns30.domaincontrol.com.
DNS records live
- NS
-
- ns29.domaincontrol.com
- ns30.domaincontrol.com
- MX
-
- 0 mx-01-eu-central-1.prod.hydra.sophos.com
- 10 mx-02-eu-central-1.prod.hydra.sophos.com
- TXT
-
Show 7 TXT records
1VxvGnMoEM0h5PGye3W21LoA3lSmrjzIFnT26JYTFLrq3KZBMLYXAJKJUwWLiNBsh2CbUPqPRpXtr+Y+XOloGA==sophos-domain-verification=5538d22237b2923401478a7d0d35f293f7f9688b12d3edcfc6e4fc2e7dec0622duo_sso_verification=9tL22VFXr33NxGNFyFyKZSNv1AG4XTOYDAfOiqSRDXK3OFQ9uUUaLtkzkDWoBoYVsophos-domain-verification=6efdc8522889539081c8db96292ca531faf9ff64sophos-domain-verification=6efdc8522889539081c8db96292ca531faf9ff64sophos-domain-verification=83b029101b068dab21c919f063a1220f50201cf2sophos-domain-verification=e0f4de754f854a3b52a5baf4d4db76880b9394a8
- Verified for
-
- Microsoft 365
- Zoom
Email authentication weak
- SPF
-
v=spf1 include:spf.mailjet.com mx ip4:178.212.90.82 ip4:93.184.179.184 ip4:37.60.175.252 ip4:62.55.182.68 ip4:37.60.175.225 ip4:217.78.168.114 ip4:93.184.191.75 include:_spf_eucentral1.prod.hydra.sophos.com include:_spf_euwest1.prod.hydra.sophos.com include:spf.tomcom.de include:spf-de.emailsignatures365.com include:amazonses.com include:spf.protection.outlook.com a:mx-service01.sivdc.services a:mx-service02.sivdc.services ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
microphone=*, fullscreen=*, accelerometer=*, autoplay=*, camera=*, display-capture=*, encrypted-media=*, geolocation=*, gyroscope=*, payment=*, picture-in-picture=*, sync-xhr=*, usb=()- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob: mediastream:; script-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline' data: blob: mediastream:; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * data: blob: 'unsafe-inline'; font-src * blob: data: 'unsafe-inline'; worker-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval'- strict-transport-security
max-age=63072000; includeSubdomains;- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin