trauffer.ch
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
Third-party hosts loaded (2)
- ik.imagekit.io×79
- cdn.shopify.com×28
Social
Contact
- Phone
- Address
- Trauffer Holzspielwaren AGHolzkuhplatz 13858 Hofstetten bei BrienzRoutenplaner+41 33 952 15 00
DNS records live
- NS
-
- ch.pro.io
- nl.pro.io
- p.dnh.net
- MX
-
- 10 trauffer-ch.mail.protection.outlook.com
- TXT
-
mx-f7453550f9c32516mx-9ef6f1d4b7f327f1
- Verified for
-
- Meta
Email authentication partial
- SPF
-
v=spf1 a a:mail.ostendis.ch ip4:217.26.60.189 include:spf.protection.outlook.com include:luxsci.com include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCyK6qgr4ZB8X83sDlVm+cfay82QKC8cgM0MQcpXe8PYclL+DjFGc0PAD2uENEZeh4n6T5Q6l2qOSB/aWTfUq… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCu/d5jeqAqZ+7WNTyA+YLQ9W/d5gsJ//wiQ0pfP7RAmdVNz5lnjEyEQmTACu2qRyr1h28IkwJW1BMLIUDCRZ…
selectors probed - selector1:
Certificate (current)
E8
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'self' 'nonce-f2dfd81c4bfa85ea2962b778a0f19357' https://cdn.shopify.com https://shopify.com; frame-ancestors 'self' https://trauffer.ddev.site https://cms.trauffer.ch https://ulanofuz.myhostpoint.ch https://accounts.shopify.com; style-src 'self' *.mews.com *.aptrinsic.com https://fonts.googleapis.com/ https://odm.ostendis.com/ 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' *.mews.com https://www.google.com/ https://www.google-analytics.com/ https://analytics.google.com https://app.launchdarkly.com/ https://events.launchdarkly.com/ https://dc.services.visualstudio.com/ https://log-api.eu.newrelic.com/ *.aptrinsic.com *.ingest.sentry.io https://trauffer.ddev.site https://cms.trauffer.ch https://ulanofuz.myhostpoint.ch https://core.service.elfsight.com/ https://odm.ostendis.com/ https://cdnjs.cloudflare.com/ajax/libs/moment.js/ https://cdnjs.cloudflare.com/ajax/libs/list.js/ https://app.privacybee.io/ https://universe-static.elfsightcdn.com- strict-transport-security
max-age=31536000