weissundweiss.de
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- a.storyblok.com×39
- consent.cookiebot.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Updated
- 2013-01-15
- Name servers
-
- ns1.register-it.net.
- ns2.register-it.net.
DNS records live
- NS
-
- ns1.register-it.net
- ns2.register-it.net
- MX
-
- 10 weissundweiss-de.mail.protection.outlook.com
- TXT
-
apple-domain-verification=ZNYRGzfScSsoEWqhwd8l1pmz678flzx37sdsw9gbbjbsqpfgMS=ms90717064
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:217.89.111.144/29 ip4:195.4.211.124/32 ip4:83.246.77.0/24 ip6:2a02:790:1:19::77:201 MX -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; ruf=mailto:it-department@weissundweiss.de; fo=1;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx6kNy1TQs0vpPrm4EXVXttr7/n314EizrwUmSze/Q8ga5z61g0adDToyUZdQAlVUkEWWLOqQS0+jlH…
selectors probed - selector1:
Certificate (current)
E7
Expires in 34 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; frame-src 'self' *; font-src 'self' data: *; img-src 'self' data: *; script-src 'self' 'unsafe-eval' 'unsafe-inline' *; style-src 'self' 'unsafe-inline' *; connect-src 'self' *- strict-transport-security
max-age=31536000