techconsult.de
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Font Awesome
Third-party hosts loaded (2)
- use.fontawesome.com×2
- gmpg.org×1
Social
Registration
- Updated
- 2013-06-18
- Name servers
-
- ns1.first-ns.de.
- robotns2.second-ns.de.
- robotns3.second-ns.com.
DNS records live
- NS
-
- ns1.first-ns.de
- robotns2.second-ns.de
- robotns3.second-ns.com
- MX
-
- 0 techconsult-de.mail.protection.outlook.com
- TXT
-
Sendinblue-code:354f5f9d3738b400bdabc5d8d13884d2google-site-verification=x30SZrIaSonXwl42QJPZaBb4qm-MN5htGOgPQ-cco5gMS=ms42951064
Email authentication partial
- SPF
-
v=spf1 mx ip4:185.238.160.250 include:spf.sendinblue.com include:spf.crsend.com include:_spf.salesforce.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc-aggregate@techconsult.de;ruf=mailto:dmarc-forensik@techconsult.de;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDTvu7z0DEdRRHyDgScaN33HOJ9n+z1voCzSUDUGtEd0NP+IkJp4YDW4wm8cDWxYePmNIsTFsKiIVUPntqQDu… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - selector1:
Certificate (current)
E7
Expires in 17 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' http: https: data: blob: 'unsafe-inline'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval';- strict-transport-security
max-age=31536000; includeSubDomains