vdi-wissensforum.de
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- consent.cookiebot.com×1
- img.youtube.com×1
- www.google.com×1
- www.vdiconference.com×1
Social
Contact
- Phone
- Address
- VDI-Platz 1, 40468, Düsseldorf, DE
Registration
- Updated
- 2017-08-21
- Name servers
-
- a.ns.nrw.net.
- b.ns.nrw.net.
- c.ns.nrw.net.
DNS records live
- NS
-
- x.ns.joker.com
- y.ns.joker.com
- z.ns.joker.com
- MX
-
- 0 vdiwissensforum-de0i.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com a ip4:194.245.193.32/27 ip4:89.107.184.0/21 ip4:185.18.92.0/22 ip4:176.28.21.205/32 ip6:2a01:50c0::/32 include:_spf.csl.de include:_spf.vdi.de include:auth.msgapp.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 165 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: www.vdi-wissensforum.de www.vdiconference.com; script-src 'self' 'nonce-skotLSm7oWMLxucPMnoSMT7tny0OPLyAt110WJ1qqO3SvBum_zYL7A' 'strict-dynamic' data: www.vdi-wissensforum.de www.vdiconference.com blob: *.adsrvr.org *.bing.com *.cookiebot.com *.clarity.ms *.dmndfrcstng.com dmndfrcstng.com *.doubleclick.net *.facebook.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.google.com *.gstatic.com *.licdn.com *.openai.com *.pay1.de *.podigee-cdn.net *.salesfusion.com *.salesviewer.org salesviewer.org *.scarabresearch.com *.signalize.com *.teads.tv *.xingcdn.com *.xing.com *.virtualbadge.io 'unsafe-eval' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.bing.com *.clarity.ms *.cookiebot.com *.dmndfrcstng.com dmndfrcstng.com *.doubleclick.net *.facebook.com *.google.com *.google.de *.google-analytics.com *.googletagmanager.com *.licdn.com *.linkedin.com *.plyr.io *.salesviewer.org- strict-transport-security
max-age=63072000; includeSubDomains; preload