bstbk-steuerberaterplattform.de

.de crawl

First seen 2026-04-17 · Last seen 2026-05-08 · ok HTTP/1.1 200 1918 ms crawled 2026-05-12

DE · 193.27.50.202 · AS15451 DATEV eG

Reputation 100/100

Classifying

HTML metadata

Title
Steuerberaterpostfach (beSt)
Language
de

Registration

Updated
2026-04-07
Name servers
  • ns01.datev.de.
  • ns02.datev.com.

DNS records live

NS
  • ns01.datev.de
  • ns02.datev.com
MX
  • 0 cdxmailin01.datev.de
  • 0 cdxmailin02.datev.com

Email authentication strong

SPF
v=spf1 include:dpmail._spf.datev.de include:mailout._spf.datev.de ~all
softfail (~all)
DMARC
v=DMARC1;p=reject;rua=mailto:dmarc-a@reports.datev.de
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Thawte TLS RSA CA G1
from 2025-10-15 to 2026-11-13
Expires in 176 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.bstbk-steuerberaterplattform.de/self-service/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Permissions Policy
Header values
referrer-policy
no-referrer
x-frame-options
DENY
content-security-policy
default-src 'self' *.datev.de; frame-src blob: 'self' *.datev.de; script-src blob: 'self' *.datev.de; font-src 'self' *.datev.de *; connect-src 'self' blob: http://localhost:* *.datev.de; img-src 'self' blob: *.datev.de data:; style-src 'self' *.datev.de 'unsafe-inline'; worker-src 'self' blob: *.datev.de;
strict-transport-security
max-age=31536000; includeSubdomains

Linked from (1)