vci.de
HTML metadata
Technology
- Server
- server
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (4)
- challenges.cloudflare.com×2
- code.etracker.com×1
- d74yk5tw8l368.cloudfront.net×1
- www.youtube-nocookie.com×1
Social
Registration
- Updated
- 2012-12-07
- Name servers
-
- ns.plusline.de.
- ns.s.plusline.de.
DNS records live
- NS
-
- ns.plusline.de
- ns.s.plusline.de
- MX
-
- 10 vci-de.mail.protection.outlook.com
- TXT
-
nitro-verification-code=LTc3NTc0NzU3MDI5ODI0NzI4MzE=Eqk/j7oU8M9dYFnZTyJS6PdunGeiXMTwEPw9SPt2dwPeOrn6u1ZEduwzkHdQP5L/KNpVANoxA4e/JosT7wXrcQ==Foxit-domain-verification=6683a5f4ed67d76fe4ea487355c854b1
- Verified for
-
- Apple
- Microsoft
- Microsoft 365
- Miro
Email authentication weak
- SPF
-
v=spf1 a include:spf.protection.outlook.com ip4:82.98.88.72/32 ip4:213.83.19.216/32 ip4:212.19.54.2/32 include:tixxt.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 128 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=(), gyroscope=(), magnetometer=(), payment=(), usb=(), bluetooth=(), accelerometer=(), autoplay=(self 'https://playout.3qsdn.com'), encrypted-media=(self 'https://playout.3qsdn.com'), fullscreen=(self 'https://playout.3qsdn.com'), picture-in-picture=(self 'https://playout.3qsdn.com')- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://www.vci.de; script-src 'self' 'unsafe-inline' https://*.vci.de *.google-analytics.com *.googletagmanager.com *.gstatic.com *.youtube.com *.vimeo.com *.twitter.com *.linkedin.com *.xing.com https://ihre-chemie.de https://chemie3.de https://challenges.cloudflare.com https://code.etracker.com https://www.etracker.de *.etracker.com; style-src 'self' 'unsafe-inline' https://www.vci.de *.googleapis.com *.gstatic.com; img-src 'self' https://*.vci.de data: *.google-analytics.com *.googletagmanager.com *.youtube.com *.vimeo.com *.gravatar.com *.w.org *.twitter.com *.linkedin.com *.xing.com *.etracker.com https://d74yk5tw8l368.cloudfront.net https://widgets.kununu.com https://assets.kununu.com; font-src 'self' https://www.vci.de data: *.googleapis.com *.gstatic.com; connect-src 'self' https://*.vci.de *.google-analytics.com *.googletagmanager.com *.etracker.com *.etracker.de; frame-src 'self' https://*.vci.de *.youtube.com *.youtube-nocookie.com *.vimeo.com *.twitter.c- strict-transport-security
max-age=63072000; includeSubDomains; preload