wissenschaftsjahr.de
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2023-01-30
- Name servers
-
- ns1.pp-dns.com.
- ns2.pp-dns.com.
- ns3.pp-dns.com.
- ns4.pp-dns.com.
DNS records live
- NS
-
- ns1.pp-dns.com
- ns2.pp-dns.com
- ns3.pp-dns.com
- ns4.pp-dns.com
- MX
-
- 10 mx.bmbfcluster.de
- 90 mx2.bmbfcluster.de
- TXT
-
6bjqk9c1mf3z7hzr6s2j658sm0dxbmsg_bab9tewj1ubimpdf3l0jkylncts2awl
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.crsend.com include:_spf.zimpel.de ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 170 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.etracker.de *.consentmanager.net *.etracker.com cdn.consentmanager.net/delivery/ *.consentmanager.mgr.consensu.org consentmanager.mgr.consensu.org etracker.de tagmanager.google.com www.googletagmanager.com www.google-analytics.com *.openstreetmap.org pixelpark.elaine-asp.de www.bmbf.de www.youtube.com maps.googleapis.com *.mgr.consensu.org; font-src 'self'; style-src 'self' 'unsafe-inline' *.mgr.consensu.org; img-src 'unsafe-inline' 'self' *.googletagmanager.com *.consentmanager.net *.ytimg.com data: www.google-analytics.com *.mgr.consensu.org *.openstreetmap.org cdn.consentmanager.net fonts.googleapis.com; frame-ancestors www.bmbf.de ; media-src 'self' 'unsafe-inline' 'unsafe-eval' pixelpark.elaine-asp.de www.youtube.com www.bmbf.de www.vimeo.com play.google.com; frame-src 'self' 'unsafe-inline' 'unsafe-eval' streaming-out.bmbfcluster.de streaming.sendewerk.berlin pixelpark.elaine-asp.d- strict-transport-security
max-age=63072000; includeSubDomains; preload