threema.com
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Registrar
- COREhub, S.R.L.
- Created
- 2012-10-21
- Expires
- 2026-10-21 155 days left
- Updated
- 2025-10-22
- Name servers
-
- ns1.threema.ch
- ns2.threema.ch
- ns5.threema.ch
DNS records live
- NS
-
- ns1.threema.ch
- ns2.threema.ch
- ns5.threema.ch
- TXT
-
dbf37de8b6f793a18828fb4fbdd451b6google-site-verification=0JtLfG4Qk0bhvlyCU9HqmlfWaUcOZX8nkWctdblaFf4
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; aspf=s; adkim=s;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV E36
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' https://static.threema.ch 'unsafe-inline'; font-src 'self' https://static.threema.ch data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://hcaptcha-ws.threema.ch; script-src-elem 'self' https://hcaptcha-ws.threema.ch 'unsafe-inline' data:; frame-src 'self' https://hcaptcha-assets.threema.ch; img-src 'self' data: https://static.threema.ch blob: ; media-src 'self' data: blob:; connect-src 'self' wss://threema.com https://hcaptcha-assets.threema.ch https://static.threema.ch https://bugs.threema.ch ; object-src 'none'; worker-src 'self' blob:; child-src blob: https://hcaptcha-assets.threema.ch; frame-ancestors 'self'; form-action 'self' https://threema.com https://work.threema.ch ; base-uri https://threema.com; report-uri https://bugs.threema.ch/api/30/security/?sentry_key=33a83d833904ad024494585d9479b3c4; report-to default- strict-transport-security
max-age=31104000; includeSubdomains