bonnfinanz.de
HTML metadata
Technology
- Server
- nginx
Social
Registration
- Updated
- 2026-02-23
- Name servers
-
- dns11.netcologne.de.
- dns12.netcologne.de.
- dns13.netcologne.de.
- dns14.netcologne.de.
DNS records live
- NS
-
- dns11.netcologne.de
- dns12.netcologne.de
- dns13.netcologne.de
- dns14.netcologne.de
- MX
-
- 0 bonnfinanz-de.mail.protection.outlook.com
- TXT
-
cftp2d8+fbN7xlW3hvXJCBw5TTM3JnO57CGIw6SsiU3tehFHrOixRTVzyQ6MMSkvaxgQm5/dJs8kuP+pj6BlHA==
- Verified for
-
- Anthropic
- Apple
- Atlassian
- Microsoft 365
- OpenAI
Email authentication strong
- SPF
-
v=spf1 a:otc-de-spf.mms.t-systems-service.com ip4:80.158.7.225 ip4:80.158.39.126 include:spf.protection.outlook.com include:spf.softfair.de include:mail.timmehosting.de -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@bonnfinanz.de; pct=100; aspf=r; adkim=rpolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqyUPUydfiNLa5gwXWHio7FCTkujxpvlo1n8vrsmGWLU0BZ2bWx0sDRrzcpHOuldRFcwzDUiavRZkBTv7xjs…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 293 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=*- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-eval' 'unsafe-inline' https://*.googletagmanager.com https://*.googleadservices.com https://*.g.doubleclick.net https://*.google.com https://*.licdn.com https://maps.googleapis.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.analytics.google.com https://*.google.com https://*.google.de https://*.google-analytics.com https://*.googleapis.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.linkedin.com https://maps.gstatic.com https://*.facebook.com https://*.europace2.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://*.doubleclick.net https://*.finoso.de https://*.bonnfinanz.de; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://maps.googleapis.com https://*.baufi-lead.de https://*.europace.de https://*.licdn.com https://*.facebook.net 'report-sample'; connect-src 'self' data:- strict-transport-security
max-age=31536000; includeSubdomains