weig.de
HTML metadata
Technology
- Server
- nginx
- CMS
- Joomla
Third-party hosts loaded (1)
- elfsightcdn.com×1
Social
Registration
- Updated
- 2022-02-25
- Name servers
-
- ns1.timmehosting.de.
- ns2.timmehosting.de.
- ns3.timmehosting.de.
DNS records live
- NS
-
- ns1.timmehosting.de
- ns2.timmehosting.de
- ns3.timmehosting.de
- MX
-
- 10 weig-de.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
o4e2ixjjstlzjqhiyknjwe5vvcu84q/kv2l9snsfg+bs4fu/xci4ok2asfgjn5iob7njgze2ao6jwzsnvw3juq==knowbe4-site-verification=4a7709c74fd0cc68c4710ef2c0cc2e59swisssign-check=rW-MODVfjj47ShycvjgbviZdpQ4swisssign-check=Bx5ZHzephXuezdc1pGN_cVaQ8XY
Email authentication strong
- SPF
-
v=spf1 ip4:176.9.21.118 ip4:195.63.193.194 ip4:217.244.2.118 ip4:91.215.73.161 ip4:2.207.143.133 ip4:212.185.206.116 ip4:188.111.0.251 include:spf.protection.outlook.com include:spf.eu.exclaimer.net include:_spf.psm.knowbe4.com include:_spf-dc33.sapsf.eu include:20092979.spf08.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; ruf=mailto:mailreporting@weig.de; fo=1;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0srppwx/JfjviRzDjUNEn4Jg1V9MNHHoIQ/v1IU3wxvkzspIqbNjoMWLA+EV/imQgP+NOuLp31smP2… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt025jsZw3dbWhl4WnJ8EFCy+o6Te4tRyZZyKBdfWB2bYYuweZ+7yek4oLbaEelJDxLcEUxwLlpauuo…
selectors probed - selector1:
Certificate (current)
R13
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self';- strict-transport-security
max-age=31536000; includeSubDomains