therwil.ch
HTML metadata
Technology
- Server
- Apache
Social
Contact
DNS records live
- NS
-
- dns1.talus.ch
- dns2.talus.ch
- dns3.talus.ch
- MX
-
- 10 therwil-ch.mail.protection.outlook.com
- TXT
-
mbzkpkn334gnb131mln7qqb0n2mgzmm2_tujgzc5batmebizzqvznb61d34vd4bntk45cvvx1mvyqdyq4jlbj4zx0tgxkcfm
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx ip4:146.4.42.27 ip4:212.120.37.100 a:mail.ostendis.ch include:spf.protection.outlook.com include:spf-de.emailsignatures365.com include:_spf.talus.ch -allstrict (-all) - DMARC
-
v=DMARC1; p=none; adkim=r; aspf=r;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8pLDhedRY220mC0Dh0rILoROOGi6Y62em/2m+pBjhIJ1ZdvYX0koCP3sB6sqyufPLsCTfZtgnD4jS/…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 281 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
camera=(),geolocation=(),microphone=(), camera=(),geolocation=(),microphone=()- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' *.readspeaker.com *.typekit.net abaservices.ch *.abaservices.ch alcdn.msauth.net *.google.com www.gstatic.com *.openstreetmap.org *.xing-share.com *.guidle.com weblics.de platform.twitter.com maps.google.com stats.format-webagentur.ch *.readspeaker.com *.talus.ch *.cloudflare.com *.linkedin.com *.google-analytics.com *.hs-scripts.com *.googleapis.com *.facebook.net *.googletagmanager.com https://appsforoffice.microsoft.com https://ajax.aspnetcdn.com https://reporting.talus.ch https://odm.ostendis.com data: blob:; script-src 'self' abaservices.ch *.abaservices.ch alcdn.msauth.net *.google.com www.gstatic.com *.openstreetmap.org *.xing-share.com *.guidle.com weblics.de platform.twitter.com maps.google.com stats.format-webagentur.ch *.readspeaker.com code.jquery.com *.fontawesome.com *.talus.ch *.typekit.net *.cloudflare.com *.linkedin.com *.google-analytics.com *.hs-scripts.com *.googleapis.com *.facebook.net *.googletagmanager.com https://appsforoffice.microsoft.com h- strict-transport-security
max-age=155552000; includeSubDomains