cosmopolitan.de
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Ads
-
- Google AdSense
- Google Ads (DoubleClick)
Third-party hosts loaded (8)
- cdn.bauerdcs.io×1
- dev.visualwebsiteoptimizer.com×1
- images.bauerdcs.io×1
- native.emsservice.de×1
- pagead2.googlesyndication.com×1
- securepubads.g.doubleclick.net×1
- static.emsservice.de×1
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2025-09-16
- Name servers
-
- ns-1035.awsdns-01.org.
- ns-1837.awsdns-37.co.uk.
- ns-289.awsdns-36.com.
- ns-558.awsdns-05.net.
DNS records live
- NS
-
- ns-1035.awsdns-01.org
- ns-1837.awsdns-37.co.uk
- ns-289.awsdns-36.com
- ns-558.awsdns-05.net
- MX
-
- 10 cosmopolitan-de.mail.protection.outlook.com
- TXT
-
Show 10 TXT records
MS=ms11422380Sendinblue-code:8e4e013a6825ec564c3ce3ab87a82611VuDSO9KUoDbzd2zdeYxMvxkIDg6kDDiLD7PQC5V+xxxvfjL1PA/b+S3jT8SvPfg1L3gziYW5LZSLJJoYcPVoaA==ahrefs-site-verification_d11f42e4e2439fe4b786e6f432cc781e4a8b06f2f89035587eed4303591080e9facebook-domain-verification=diettragv2qz4sgr7g826ykgcc2uxwgoogle-site-verification=XHjaaxoWpeOx6MjaZfPmmCN33XD04dLxkKz7Oyf4NX8qX1VECD/TlEJU4QVgGTkHUXmeLQjs88wlv0KgXYcHyMe7vh9ynkBw8ckz6I9Q7F7OZCzwC2c8MGzGR4kmMUfOA==site-verification=f844ef0154a2bcfcec9bd1ded3f14b12tollbit-domain-verification=106d04605e0fe144e3219904757c8cd6ee1848ed363ec55dd32295bfa88a7597woOBK5/79YX2yHx36GCoHFG9sYvHxXg5CA6+wlb2N4nRFF+KMry3ZkvRKN2oTq00mugb6uQuTS8fr0mHV2+8OA==
Email authentication strong
- SPF
-
v=spf1 include:_u.cosmopolitan.de._spf.smart.ondmarc.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=none; rua=mailto:5352a03e@inbox.eu.redsift.cloud,mailto:dmarc@mailinblue.com,mailto:rua@dmarc.brevo.com; ruf=mailto:5352a03e@inbox.eu.redsift.cloud,mailto:dmarc@mailinblue.com; fo=1; rf=afrf; ri=86400policy: reject (enforced) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7CFuOJ3xuigbwyy8lAtJcH2umQa6bNeZBGe2g4V5RF1Z3Y3uALZIUyIZPp7P4LSX2RQ2XCN9OTA8ye… - mail:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 149 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' * data: blob:;font-src 'self' * data:;script-src 'self' * 'unsafe-inline' 'unsafe-eval' blob:;style-src 'self' * 'unsafe-inline';media-src 'self' * blob:;frame-ancestors 'self' https://cms.production.toeknee.zone- strict-transport-security
max-age=31536000; includeSubDomains; preload