avitea.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- userlike-cdn-widgets.s3-eu-west-1.amazonaws.com×1
- www.hella.com×1
Social
Contact
Registration
- Updated
- 2025-12-10
- Name servers
-
- pns.dtag.de.
- secondary006.dtag.net.
DNS records live
- NS
-
- pns.dtag.de
- secondary006.dtag.net
- MX
-
- 5 mx1.hc106-56.eu.iphmx.com
- 5 mx2.hc106-56.eu.iphmx.com
- TXT
-
knowbe4-site-verification=fe8b1fbbbe674cb2b44b2a173357a9a3
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 exists:%{i}.spf.hc106-56.eu.iphmx.com ip4:209.206.38.65 ip4:209.206.38.66 ip4:209.206.38.67 ip4:209.206.38.68 a:mail.mona-ai.services include:spf.cluster.4hr.de include:_spf.sequrix.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Corporation Service Company RSA OV SSL CA
Expires in 5 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://legalhelper.eu * https://liveupdate.pimcore.org/update-check https://www.mtcaptcha.com https://tr.joblift.de; img-src 'self' https://legalhelper.eu/ccm19/public * data:; script-src 'self' 'unsafe-inline' bundles/pimcoreadmin/js/lib/ckeditor/ckeditor.js * https://hella.containers.piwik.pro * 'unsafe-eval' bundles/pimcoreadmin/extjs/js/ext-all.js https://service.mtcaptcha.com/mtcv1/client/mtcaptcha.min.js https://legalhelper.eu/ccm19/public/app.js https://assets.joblift.com/tr/de.js https://code.jquery.com/jquery-3.6.0.min.js bundles/pimcoreadmin/extjs/js/ext-all.js bundles/pimcoreadmin/js/pimcore/startup.js; style-src 'self' 'unsafe-inline' https://legalhelper.eu/ccm19/public/app.css; report-uri /nelmio/csp/report- strict-transport-security
max-age=31536000; includeSubDomains