walther-pilot.de
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (3)
- consent.cookiefirst.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2023-03-03
- Name servers
-
- auth01.ns.td-fn.net.
- auth02.ns.td-fn.net.
DNS records live
- NS
-
- auth01.ns.td-fn.net
- auth02.ns.td-fn.net
- MX
-
- 10 de-smtp-inbound-1.mimecast.com
- 10 de-smtp-inbound-2.mimecast.com
- TXT
-
gzq1976l5dkpzzfh2jw4c002k9zlbdr1v=DMARC1; p=quarantine; rua=mailto:it-nrw@wagner-group.com; ruf=mailto:it-nrw@wagner-group.com; fo=1;
- Verified for
-
- Microsoft 365
- Miro
- TeamViewer
Email authentication weak
- SPF
-
v=spf1 mx include:spf.protection.outlook.com include:de._netblocks.mimecast.com ip4:62.204.160.93 ip4:35.214.208.81 ip4:35.214.213.218 ip4:35.214.183.81 ip4:35.214.212.238 ip4:217.5.210.160/27 ip4:62.159.214.96/27 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
child-src 'self' blob: cdn.wagner-group.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com bid.g.doubleclick.net gsa://onpageload vars.hotjar.com *.hubspot.com f2150201.td-fn.net www.facebook.com www.google.com; connect-src 'self' *.googleadservices.com api-eu1.hubapi.com dccblobstorage.blob.core.windows.net analytics.tiktok.com *.tiktokw.us tiles.stadiamaps.com *.utils.elfsightcdn.com *.clarity.ms *.elfsight.com meta.wagner-group.com px.ads.linkedin.com *.flockler.app prompts.api.production.neocomapp.com sentry.21torr.com wss://*.onlim.com wss://*.hotjar.com wagner-group.matomo.cloud core.service.elfsight.com *.hsforms.com *.hscollectedforms.net hubspot-forms-static-embed.s3.amazonaws.com api.pinpiaa.com *.onlim.com *.global.commerce-connector.com cdn.wagner-group.com www.wagner-group.com *.cookiefirst.com *.g.doubleclick.net *.google.fr www.google.de *.google.com *.googleapis.com *.google-analytics.com www.google.com analytics.google.com *.hotjar.io *.hotjar.co- strict-transport-security
max-age=63072000