dm-folien.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.jsdelivr.net×2
- www.googletagmanager.com×2
- www.facebook.com×1
Social
Contact
- Address
- st zertifiziert nachISO 9001
Registration
- Registrar
- INWX GmbH
- Created
- 2002-04-29
- Expires
- 2027-04-29 343 days left
- Updated
- 2026-04-29
- Name servers
-
- ns1.timmehosting.de
- ns2.timmehosting.de
- ns3.timmehosting.de
DNS records live
- NS
-
- ns1.timmehosting.de
- ns2.timmehosting.de
- ns3.timmehosting.de
- MX
-
- 10 server1.dm-folien.de
- TXT
-
_axxd7t8o4ehpm0m5n25unsxcls6uvio_xvkfo2z2elprbrotp7ceao70t8b658gwgj4kt5w4x97vwv30tswy5lshbxg5hxs
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 +a +mx include:mail.timmehosting.de ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;sp=none;adkim=s;aspf=r;pct=100;fo=0;rf=afrf;ri=86400;rua=mailto:admin@dm-folien.de;ruf=mailto:admin@dm-folien.depolicy: none (monitoring only) · sp=none - DKIM
-
- default:
v=DKIM1; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDpN3M/qqUJLyb/guBTnweZuPZE9IuoBFQrwPKga3pyjchxDHLBmR3eVJ53nm40CcdHzBCbem1aipybRlQ737sN…
selectors probed - default:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 255 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
deny- permissions-policy
fullscreen=(self "https://www.paypal.com") accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: www.dm-folien.com *.openstreetmap.org *.shopware.com *.google.com www.googletagmanager.com *.googleadservices.com *.bing.com *.facebook.com *.facebook.net *.paypalobjects.com *.media-amazon.com *.payments-amazon.com *.clarity.ms *.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' global.frcapi.com cdn.jsdelivr.net sibautomation.com *.brevo.com *.clarity.ms *.bing.com *.google.com *.google-analytics.com www.googletagmanager.com *.doubleclick.net *.facebook.com *.facebook.net *.amazon.com *.payments-amazon.com *.paypal.com; font-src 'self'; connect-src 'self' *.bing.com *.google.com *.google-analytics.com *.doubleclick.net *.googleadservices.com *.googlesyndication.com *.clarity.ms *.brevo.com *.amazon.com *.paypal.com *.facebook.com; frame-src 'self' *.frcapi.com *.paypal.com www.youtube-nocookies.com *.shopware.io; form-action 'self' *.paypal.com *.amazon.de;- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin;- cross-origin-embedder-policy
require-corp;- cross-origin-resource-policy
same-origin;