sza.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Nuxt
Social
Contact
- Phone
Registration
- Updated
- 2022-07-05
- Name servers
-
- ns2.inwx.de.
- ns3.inwx.eu.
- ns.inwx.de.
DNS records live
- NS
-
- ns.inwx.de
- ns2.inwx.de
- ns3.inwx.eu
- MX
-
- 10 mail1.sza.de
- 100 mail2.sza.de
- TXT
-
vM1ZCQNs29R8EKFbxpoNoVw1V4PvxcTAtRecai/9i/ryCul1bXEyeYxM+Y3gB5yxTOcX0X8kO2j1TCz25rniaw==MS=AF56A290D59221EE5D7DD5C02EE4C511C1A85CE4
- Verified for
-
- Apple
- DocuSign
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx include:dkd.de include:servers.mcsv.net include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:sza-it@sza.de; ruf=mailto:sza-it@sza.de; fo=0:1;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuP+0fmBBXx2ksTzpnBgFBU9sBAQ8ov1V7VUSl9qCxUP0dDZgxaVZpK9lvZClqt37X4Q6wpJXEHqlgt… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxIIzpcbjI0hwZn0Lxu2oMpqg3L508NqFWWCAyZCpabrWgdg4XZGVUKYk1e7bap17CjH+nvg7NBV459… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - selector1:
Certificate (current)
R12
Expires in 43 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src https://www.sza.de https://cms.sza.de; frame-src https://proxy.lexcrm.de https://proxy-sza.lexcrm.de https://www.youtube-nocookie.com; script-src https://www.sza.de https://proxy.lexcrm.de https://proxy-sza.lexcrm.de 'unsafe-inline' 'unsafe-eval' https://webanalytics.sza.de; img-src 'self' https://cms.sza.de https://webanalytics.sza.de https://img.youtube.com; style-src https://proxy.lexcrm.de https://proxy-sza.lexcrm.de 'unsafe-inline' 'self'; font-src 'self' https://fonts.gstatic.com; object-src 'none'; connect-src 'self' https://sentry.s-v.de https://cms.sza.de https://webanalytics.sza.de; frame-ancestors 'self' https://cms.sza.de