visitmelk.com
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.0.0 known XSS (<3.5)
Third-party hosts loaded (2)
- code.jquery.com×1
- fast.fonts.net×1
Social
Contact
- Phone
Registration
- Registrar
- Hetzner Online GmbH
- Created
- 2019-03-03
- Expires
- 2027-03-03 271 days left
- Updated
- 2026-03-04
- Name servers
-
- ns1.first-ns.de
- robotns2.second-ns.de
- robotns3.second-ns.com
DNS records live
- NS
-
- ns1.first-ns.de
- robotns2.second-ns.de
- robotns3.second-ns.com
- MX
-
- 10 mail.visitmelk.com
- Verified for
-
- Brevo
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=none; rua=mailto:postmaster@stadt-melk.atpolicy: none (monitoring only) - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current)
R13
Expires in 66 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.ddev.site https://*.ddev.site:5137 https://*.gugler.at https://*.visitmelk.com; script-src 'self' https://*.ddev.site https://*.ddev.site:5137 'unsafe-inline' https://*.topcamp.at/ https://*.googleapis.com https://*.google-analytics.com https://*.gstatic.com https://www.googletagmanager.com *.google.com https://*.ggpht.com *.googleusercontent.com https://fast.fonts.net https://code.jquery.com https://*.gugler.at https://*.visitmelk.com *.sibforms.com *.code.jquery.com https://sibforms.com https://connect.facebook.net https://conversations-widget.brevo.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://*.ddev.site https://*.ddev.site:5137 https://*.gstatic.com *.google.com https://maps.googleapis.com https://status.stadt-melk.at https://*.gugler.at https://*.visitmelk.com https://www.facebook.com; base-uri 'self'; frame-src 'self' https://*.ddev.site https://*.ddev.site:5137 https://*.topcamp.at/ *.google.com *.- strict-transport-security
max-age=31536000; includeSubDomains