thommenmedical.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (3)
- player.vimeo.com×2
- px.ads.linkedin.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- 1API GmbH
- Created
- 2001-08-08
- Expires
- 2026-08-08 68 days left
- Updated
- 2025-11-23
- Name servers
-
- ch.ch-inter.net
- de.ch-inter.net
- nl.ch-inter.net
- nsa2.nts.ch
DNS records live
- NS
-
- ch.ch-inter.net
- de.ch-inter.net
- nl.ch-inter.net
- nsa2.nts.ch
- MX
-
- 10 thommenmedical-com.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
HCZSUn+90yqWZGUMhnvcg/e/Shmeb9ZajbWD6PHyFbYTXqofLZoApmv75CXY47nZaywAdV6uhxEHCXKe7FA4/g==mailerlite-domain-verification=3f175878d5db3162ee74365f16b8bc9d7a028ad0_k9lp4d3fg810bi4ng63q1axv9hpmnu1_dv9ysbijx0xjk1wegvanod0q9pdzmvy
- Verified for
-
- Brevo
- Microsoft 365
- Zoho
Email authentication partial
- SPF
-
v=spf1 include:_spf.mlsend.com ip4:93.187.209.218 ip4:93.187.214.209 ip4:80.147.226.93 ip4:93.187.209.222 ip4:5.148.188.18 include:spf.protection.outlook.com include:zcsend.net include:one.zoho.eu include:spf.protection.cyon.net include:_spf.rexx-systems.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarcreports@thommenmedical.com; ruf=mailto:dmarcreports@thommenmedical.com; fo=1policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnnog0COpBHxKD6EaRvKd1AK4uSXDYH+JP3tILuYlnpmyPejl7Uhy3yFA0SpcqsCfiokpqAl+dhUNsL… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu1QqtNXTK0JR0ncykYszfpRHKb5aTlXwylD7hQhdwrCa7dV2ubUc/ZIKgRA35VIsbWPPbgQI6RY/DZ… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwf0Pdgm3NBqTGa+jv1vYh1sHa2JH/S/ZrdLX7VvDblFsGWbmC95FXUTg0u4ZBJz+E7I/xU4B0ebJ9r…
selectors probed - default:
Certificate (current)
R13
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' css.zohocdn.com cdn-images.mailchimp.com; font-src 'self' https://css.zohocdn.com https://fonts.gstatic.com; img-src 'self' https: data: www.googletagmanager.com *.usefathom.com www.google.com www.google.ch www.google-analytics.com ssl.gstatic.com www.gstatic.com stats.g.doubleclick.net *.vimeocdn.com analytics.google.com; script-src 'self' 'sha256-+L6k7sDT/oMgd9jvwZrg5I0a4j+RDXysVCbNoJb8RIw=' 'sha256-/qULAQ++oYuOguXeeHj+3HOZvEB0sbH+sMkR1bu0mxI=' https://sfyh-zgph.maillist-manage.net https://salesiq.zohopublic.com https://salesiq.zoho.com https://js.zohocdn.com https://connect.facebook.net https://salesiq.zoho.eu https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://cdn.usefathom.com https://player.vimeo.com https://snap.licdn.com 'nonce-ckEaRB9952NB/IXPe+hhjg=='; object-src 'none'; connect-src 'self' https: wss:; frame-src 'self' mailto: *.thommenmedical.com player.vimeo.com https- strict-transport-security
max-age=63072000; includeSubDomains