travelcircus.it
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (11)
- static-prod.travel-cdn.net×38
- s3.travel-cdn.net×13
- www.googletagmanager.com×3
- m.tcsrv.net×2
- www.google-analytics.com×2
- script.travelcircus.de×1
- www.travelcircus.at×1
- www.travelcircus.be×1
- www.travelcircus.ch×1
- www.travelcircus.de×1
- www.travelcircus.nl×1
Social
DNS records live
- NS
-
- gwen.ns.cloudflare.com
- owen.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=QNBE49v6tKAiHsVQfJc0byB4SUQT56VB8G6ws7IMuF0google-site-verification=DMdD4hDMCSupRmWB8OGITDW2TdwKLhH2fA5IcLQk6SI
Email authentication weak
- SPF
-
v=spf1 include:spf.dixa.io include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://www.dein-dlrp.de https://www.lidl-reisen.de https://*.stage-entertainment.de- strict-transport-security
max-age=63072000; preload, max-age=63072000; preload, max-age=63072000; preload