thueringer-landtag.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- social.bund.de×1
Social
Registration
- Updated
- 2012-03-14
- Name servers
-
- pns.dtag.de.
- secondary006.dtag.net.
- thldns003.toringi.net.
- thldns004.toringi.net.
DNS records live
- NS
-
- pns.dtag.de
- secondary006.dtag.net
- thldns003.toringi.net
- thldns004.toringi.net
- MX
-
- 10 hermes31.toringi.net
- 10 hermes32.toringi.net
Email authentication partial
- SPF
-
v=spf1 include:spfhard.toringi.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@thueringer-landtag.de; fo=1; adkim=s; aspf=s; rf=afrf; sp=nonepolicy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV E36
Expires in 235 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.thueringer-landtag.de *.thlt.de *.youtube.com *.newsletter2go.com; style-src 'unsafe-inline' 'self'; img-src data: blob: 'self' *.ytimg.com *.newsletter2go.com *.thueringen.de *.thueringer-landtag.de;font-src data: 'self';frame-src *.youtube.com *.youtube-nocookie.com *.3qsdn.com *.nc3-cdn.com *.thlt.de *.thueringen.de *.thueringer-landtag.de; media-src 'self' data:; connect-src 'self' *.newsletter2go.com; object-src 'none'- strict-transport-security
max-age=604800
Links to (12)
- thueringen.de×6
- bund.de×3
- facebook.com×3
- instagram.com×3
- parlamentsspiegel.de×3
- t1p.de×3
- youtube.com×3
- whatsapp.com×3
- x.com×3
- twitter.com×3
- thltcloud.de×1
- tinyurl.com×1