uestra.de
HTML metadata
Technology
- Server
- myracloud
Third-party hosts loaded (2)
- cloud.ccm19.de×1
- gvh.hafas.de×1
Social
Contact
- Phone
Registration
- Updated
- 2018-03-23
- Name servers
-
- ns2.htp-tel.de.
- ns.htp-tel.de.
DNS records live
- NS
-
- ns.htp-tel.de
- ns1.htp-tel.de
- ns2.htp-tel.de
- MX
-
- 0 uestra-de.mail.protection.outlook.com
- TXT
-
Show 10 TXT records
MS=ms64015299v=spf1 ip4:212.59.34.18 ip4:81.14.173.254 include:spf.protection.outlook.com include:spfhard.crsend.com include:spf-de.emailsignatures365.com -allswisssign-check=df_mscajB1LZkNahbMYScLuwjSYuestralabweb.azurewebsites.netapple-domain-verification=YSg2NzE0EWenYf26MS=15337C91920B51CAD0AF6541CD92B7C49D53A002atlassian-domain-verification=uklsB6TbbFNpVirzoMnhtWa5/pCoH5nX30eHyTqPDEbFJzk7WJuV4jf3fPsPvtD9ms-domain-verification=627d835a-6fc7-4aa2-880e-c62095c7bc42google-site-verification=p8AGb2zfg6r4NE0XmbUyR1hRbVLUbPCMtQbG8JDzSEsadobe-idp-site-verification=2b2460cfd2e87b602b5b01ee46af6a0cf992fe58d7c09d82b2b344119d6d7260
Certificate (current)
E7
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.uestra.de https://cloud.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://img.youtube.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://cloud.ccm19.de https://elma.gvh.de https://www.facebook.com; base-uri 'self' https://*.uestra.de; frame-src 'self' blob: https://*.youtube.com/ https://gvh.demo.hafas.cloud https://gvh.hafas.de https://abo.gvh.de https://cloud.ccm19.de https://deutschlandticket.gvh.de https://transport.novafind.eu/; media-src 'self' blob:; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://cloud.ccm19.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de https://stats.uestra.de 'report-sample'; font-src 'self' data: https://fonts.gstatic.com https://gvh.demo.hafas.cloud https://g- strict-transport-security
max-age=63072000; includeSubdomains;- content-security-policy-report-only
default-src 'self' https://*.uestra.de https://cloud.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://img.youtube.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://cloud.ccm19.de https://elma.gvh.de https://www.facebook.com; base-uri 'self' https://*.uestra.de; frame-src 'self' blob: https://*.youtube.com/ https://gvh.demo.hafas.cloud https://gvh.hafas.de https://abo.gvh.de https://cloud.ccm19.de https://deutschlandticket.gvh.de https://transport.novafind.eu/; media-src 'self' blob:; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://cloud.ccm19.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de https://stats.uestra.de 'report-sample'; font-src 'self' data: https://fonts.gstatic.com https://gvh.demo.hafas.cloud https://g