vetroswiss.ch
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress 6.9.4
Contact
- Phone
DNS records live
- NS
-
- nsa1.nts.ch
- nsa2.nts.ch
- MX
-
- 10 d306835.a.ess.de.barracudanetworks.com
- 20 d306835.b.ess.de.barracudanetworks.com
- TXT
-
trend-micro-v1-domain-verification.4f52de5d10489cc46184b49e6f0cbfb5=8e7f26c2-7b1e-4484-9a3d-d985238ade28
Email authentication weak
- SPF
-
v=spf1 ip4:212.103.69.179 ip4:194.88.197.145 ip4:194.88.197.151 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
geolocation=(*),midi=(*),sync-xhr=(*),microphone=(*),camera=(*),magnetometer=(*),gyroscope=(*),fullscreen=(*),payment=(*)- x-content-type-options
nosniff- content-security-policy
default-src https: wss: data: blob: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' https://www.bern-altstadt.ch https://www.mediservice-news.ch https://rechner.soziale-sicherheit-chss.ch https://bsv.admin.ch https://www.bsv.admin.ch https://jobcloud.ch https://*.jobcloud.ch https://jobs.ch https://*.jobs.ch https://jobup.ch https://*.jobup.ch https://ingjobs.ch https://ictcareer.ch https://jobs4sales.ch https://financejobs.ch https://medtalents.ch https://jobwinner.ch https://alpha.ch https://topjobs.ch https://*.jobscout24.ch https://impieghi.ch https://*.impieghi.ch https://*.stellenmarkt.ch https://www.mediapulse.ch https://app.diespeisekarte.ch https://www.diespeisekarte.ch https://transport.opendata.ch https://www.agfs.ch https://www.immopreis.ch https://hausinfo.ch https://www.hausinfo.ch https://*.scs.scs-sdweb.ch;- strict-transport-security
max-age=31536000; includeSubdomains