vnw.de
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Updated
- 2018-09-05
- Name servers
-
- ns.gopas.de.
- ns.gopas.net.
- ns.gopas-solutions.de.
DNS records live
- NS
-
- ns.gopas-solutions.de
- ns.gopas.de
- ns.gopas.net
- MX
-
- 10 mail.vnw.de
- 20 pm03.gopas.de
- TXT
-
Show 8 TXT records
apple-domain-verification=D3J4QbKdl3DmmurBatlassian-domain-verification=aruTFEiNs6vlOWjN/fug5CLfbHwz/V8AW79DMyffvQZKniZFaand9sRvJuiu/HKLzone-ownership-verification-44c9c6f33c32192cb186eb78985c4b24fa70f89758ab7481973293355a926222MS=ms1986691679a6c660de9c41ba535d08fc74cf48e4REDDCRYPT=63a2bd137c28dd1b0eabc2521eBTzs9x7Ti20Az9oB/ifiYB0hNupwfGHIZAM3jTR3On15ACRDdkjQHIMwFQKnuhzg+9HQMBAH1TduT0fmdBqQ==atlassian-sending-domain-verification=0eeb7cd9-0d37-4e7e-a226-b7f5b8b42d41
Email authentication partial
- SPF
-
v=spf1 ip4:62.112.51.69 ip4:62.112.32.41 ip4:52.169.0.179 include:spf.protection.outlook.com include:_spf.zimpel.de include:_spf.atlassian.net include:spf.smtp.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDkpLgLL4IJVAX49QtIbJLrzfPrFQMtnbe4M12nzpyEDPq80WId53vXPjLCXtzLCoAK6m7Lm6S1WJOAMFPoiI… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClUH6z+LeE5bOZt/oNiB6iIfBFK44uRWI0JE5fR9ZOmiu3T5fCfrZsAcjaMs+u8Mf0mCyCSlawxpjZSk87yW… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzI9X1Nujnxa5YeEh2iTZVkMB5Ip/fZNXxp44ghxQDNdE+qAWEUBPednPqJRPUFfxMMeUKtozVCqp9Wvozn… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7IlzLGAiU+/V27VMcKfADBOaaOMnvKmnod1R7BbgTcXgPELojY/MQBZ/WycBdjVxCwZe87z5Qr7ptLelvp…
selectors probed - selector1:
Certificate (current)
E8
Expires in 19 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com; connect-src 'self' https://maps.googleapis.com; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com; media-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'- strict-transport-security
max-age=31536000; includeSubDomains; preload