wisswerk.de
HTML metadata
Technology
- Server
- Apache
- Cookie consent
-
- Usercentrics
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (5)
- app.usercentrics.eu×3
- privacy-proxy.usercentrics.eu×3
- api.usercentrics.eu×1
- www.google.com×1
- www.youtube-nocookie.com×1
Social
Contact
Registration
- Updated
- 2020-10-23
- Name servers
-
- helium.ns.hetzner.de.
- hydrogen.ns.hetzner.com.
- oxygen.ns.hetzner.com.
DNS records live
- NS
-
- helium.ns.hetzner.de
- hydrogen.ns.hetzner.com
- oxygen.ns.hetzner.com
- MX
-
- 0 wisswerk-de.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
swisssign-check=S7xeg3Mlv09XzGzioCVe4GUDeiwknowbe4-site-verification=56175a7763a83838e627105d030843bams=ms16495133mt/MiuBX4bfasdbtwABFqVPopo7o+7YKLDOXCCcGy4Jdq4BxHKc5CAznDw7GQrLNZ8O/zQDj6QDrCW/G06D4Vg==
- Verified for
-
- Apple
- Atlassian
Email authentication strong
- SPF
-
v=spf1 mx a include:spf.protection.outlook.com include:spf.cloud.ci-solution.com include:spf.dc-cluster.de include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@wisswerk.de; ruf=mailto:dmarc@wisswerk.de; fo=0;sp=nonepolicy: quarantine · sp=none - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5S70aQeMKe6qKy62nDJoy+gxYaH4WNe/XeBGw+HuxxroYRPKbsLzrckfWvTCnGsMJ6oAg8LYyXjy5qywaOT… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDdPvdt+H6br396c+9e4TneVznYJrcn93LCCHt1QVBFF+ZXp6XV07naZekclUVeuyVvgV+9X0HtMIKMkPSwJ0… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq4K9j9xZI3gDS/Zl2Q3gJCneL8OWUKiAUpbHgYLe4UrX1mPzk2NwT7DGmCq/iNtOZ4EOipkLpshn9B6aCL… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI7y9Zi7rzsb3725l8KS8v3L+2/gbkuixvPOVi6G4Br8vxBRaK796FgrBUPO4qUhwF1hCPP4nGnT+nPZo6xXkcHo…
selectors probed - selector1:
Certificate (current)
E8
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self' payments-de-sandbox.amazon.com payments-de.amazon.com payments.amazon.de ws://127.0.0.1:35729; script-src 'self' 'unsafe-eval' 'unsafe-inline' use.typekit.net www.googletagmanager.com www.google.com www.google-analytics.com www.gstatic.com maps.google.com maps.googleapis.com connect.facebook.net *.payments-amazon.com payments-de-sandbox.amazon.com tagmanager.google.com static.hsappstatic.net userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com challenges.cloudflare.com app.usercentrics.eu https://static.hotjar.com https://script.hotjar.com https://www.googleadservices.com/ https://*.usercentrics.eu userlike-cdn-umm.b-cdn.net *.lamapoll.de; style-src 'self' 'unsafe-inline' use.typekit.net fonts.googleapis.com tagmanager.google.com p.typekit.net https://www.googletagmanager.com; img-src 'self' data: p.typekit.net www.google-analytics.com *.googleapis.com maps.google.com *.cloudfront.net *.ssl-images-amazon.com *.ggpht.com *- strict-transport-security
max-age=31536000; includeSubDomains; preload