toppits.de
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- s7g10.scene7.com×10
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2024-09-06
- Name servers
-
- anna.ns.cloudflare.com.
- elmo.ns.cloudflare.com.
DNS records live
- NS
-
- anna.ns.cloudflare.com
- elmo.ns.cloudflare.com
- MX
-
- 100 mx14a.antispameurope.com
- 200 mx14b.antispameurope.com
- 300 mx14c.antispameurope.com
- 400 mx14d.antispameurope.com
- TXT
-
google-site-verification=aokHwij02nYxSRP85tYPa6WIvo7bKpIwsPOyY_JA3HQcsinxJD/VXCzhA5eIUOjLTUuyBaeP0pDajxQbNO7pbXYqHkGzauROh2hsa4PSY+LZELMG6CWqgn6VwGs7D22Hw==
Email authentication strong
- SPF
-
v=spf1 include:spf.hornetsecurity.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc-reports@melitta-group.com; ruf=mailto:dmarc-reports@melitta-group.com; fo=1policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.onetrust.com *.melitta-globe.web.app *.recruitee.com *.adobedtm.com *.scene7.com *.googletagmanager.com *.consentmanager.net cdn.consentmanager.net *.melitta.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.googletagmanager.com consent.cookiebot.com *.googleapis.com code.jquery.com maxcdn.bootstrapcdn.com *.cookielaw.org *.melitta-globe.web.app *.recruitee.com *.adobedtm.com *.onetrust.com challenges.cloudflare.com *.delivery.consentmanager.net *.consentmanager.net cdn.consentmanager.net *.redditstatic.com redditstatic.com str.melitta-group.com *.scene7.com *.melitta.de *.mikmak.ai *.swaven.com; img-src 'self' *.google-analytics.com *.cookielaw.org *.delivery.consentmanager.net cdn.consentmanager.net redditstatic.com data: maps.gstatic.com *.googleapis.com *.ggpht.com *.scene7.com *.googletagmanager.com *.youtube.com *.melitta.de *.mikmak.ai *.swaven.com *.static-swaven.com; font-src- strict-transport-security
max-age=31557600