avitea-meisterbetriebe.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- userlike-cdn-widgets.s3-eu-west-1.amazonaws.com×1
- www.hella.com×1
Contact
Registration
- Updated
- 2025-12-10
- Name servers
-
- pns.dtag.de.
- secondary006.dtag.net.
DNS records live
- NS
-
- pns.dtag.de
- secondary006.dtag.net
- MX
-
- 5 mail4.hella.com
- 5 mail5.hella.com
- 5 mail6.hella.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx ip4:209.206.38.66 ip4:209.206.38.68 a:les1.mx.csod.com a:les2.mx.csod.com include:spf.cluster.4hr.de -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 293 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://legalhelper.eu * https://liveupdate.pimcore.org/update-check https://www.mtcaptcha.com https://tr.joblift.de; img-src 'self' https://legalhelper.eu/ccm19/public * data:; script-src 'self' 'unsafe-inline' bundles/pimcoreadmin/js/lib/ckeditor/ckeditor.js * https://hella.containers.piwik.pro * 'unsafe-eval' bundles/pimcoreadmin/extjs/js/ext-all.js https://service.mtcaptcha.com/mtcv1/client/mtcaptcha.min.js https://legalhelper.eu/ccm19/public/app.js https://assets.joblift.com/tr/de.js https://code.jquery.com/jquery-3.6.0.min.js bundles/pimcoreadmin/extjs/js/ext-all.js bundles/pimcoreadmin/js/pimcore/startup.js; style-src 'self' 'unsafe-inline' https://legalhelper.eu/ccm19/public/app.css; report-uri /nelmio/csp/report- strict-transport-security
max-age=31536000; includeSubDomains
Links to (2)
- avitea.de×2
- buderus.de×2