bundesimmobilien.de
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
Third-party hosts loaded (2)
- cdn0.scrvt.com×7
- api.scrivito.com×2
Registration
- Updated
- 2025-12-13
- Name servers
-
- ns1.itzbund.de.
- ns2.itzbund.de.
- pns.dtag.de.
- secondary006.dtag.net.
DNS records live
- NS
-
- ns1.itzbund.de
- ns2.itzbund.de
- pns.dtag.de
- secondary006.dtag.net
- MX
-
- 10 mx1.bund.de
- 10 mx2.bund.de
- Verified for
-
- Apple
- Cisco
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:_spf1.bund.de include:spfa.myconvento.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:bundesimmobilien.de@dmarc.reports.bund.de;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 126 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; default-src 'self' data: https: wss: blob:; style-src 'self' data: https: wss: 'unsafe-inline'; script-src 'self' blob: *.arcgis.com https://api.scrivito.com https://assets.scrivito.com https://analytics.bundesimmobilien.de https://evergabe-proxy.bundesimmo.de https://static.bundesimmobilien.de https://static.bundesimmo.de localhost:*; connect-src 'self' *.arcgis.com https://api.scrivito.com https://api.vimeo.com https://assets.scrivito.com https://analytics.bundesimmobilien.de https://api.bundesimmobilien.de https://login.bundesimmobilien.de https://evergabe-proxy.bundesimmo.de https://*.bundesimmo.de localhost:*; img-src data: 'self' *.arcgis.com *.scrvt.com *.bundesimmo.de *.bundesimmobilien.de *.amazonaws.com gravatar.com maps.gstatic.com *.googleapis.com *.ggpht.com *.vimeocdn.com i0.wp.com i1.wp.com i2.wp.com localhost:*; block-all-mixed-content; frame-ancestors 'self' https://*.scrivito.com; object-src 'self' *.arcgis.com- strict-transport-security
max-age=63072000; includeSubDomains; preload
bundesimmobilien.de