dm.at
HTML metadata
Technology
Third-party hosts loaded (4)
- assets.dm.de×39
- exc.mm.dm.de×1
- media.dm-static.com×1
- www.google.com×1
DNS records live
- NS
-
- auth2.dm-drogeriemarkt.de
- ns.do-ex.com
- ns.do-ex.net
- ns.do-ex.org
- MX
-
- 10 mailgw1.dm.de
- 10 mailgw2.dm.de
- 10 mailgw3.dm.de
- 10 mailgw4.dm.de
- TXT
-
Show 7 TXT records
bw=q82dIrH+Nn/xr8stmsuoGhoj7pM+gON3dOnRcOJ8Lq6xwiz-domain-verification=865786f37d551a64016b99b423b7624fb6d14aff4b4de9e5f664a55bfcb2b425bw=SVUTKRDdvlpMLqnvb/5Sro09ju+bBYLX+9fElbWNB9fd5h3A59nLfJVrEI1i/evGyv75+zL3/mjOHyynfahbWNS4VXKRhy5e4BDriYsPsV4BHxocy+msYZ/ljOGAiaX9nA==bw=nw59TnW4VC4xfID0drJ4Z8Q4x52iODXE6RQrCymx3Ptwswisssign-check=24QO9-atLcv7r63dR1l7zaBnYgYjamf-site-verification=tH551mfrJ8bm_QPD2emlBA
- Verified for
-
- Adobe
- Anthropic
- Apple
- Atlassian
- Meta
- Microsoft 365
- Yahoo
Email authentication strong
- SPF
-
v=spf1 include:spf.mailsecurity.dm.de -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@mailsecurity.dm.depolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src data: https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud; script-src 'self' https://*.bazaarvoice.com https://app.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud https://d2pqvatijh75rn.cloudfront.net https://exc.mm.dm.at https://mpsnare.iesnare.com https://omt.dm.at https://tags.tiqcdn.com https://web.cmp.usercentrics.eu https://www.dm.at https://www.google.com https://www.gstatic.com; worker-src 'self' blob:; connect-src 'self' https://*.bazaarvoice.com https://aggregator.service.usercentrics.eu https://api.mapbox.com https://api.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://browser-intake-datadoghq.eu https://cart-recos.services.dmtech.com https://cdcs.usercentrics.eu https://collect.tealiumiq.com https://consent-api.service.consent.usercentrics.eu https://consent-rt-ret.service.consent.usercentrics.eu https://consents- strict-transport-security
max-age=31556952; includeSubDomains; preload- content-security-policy-report-only
default-src 'self'; font-src data: https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud; script-src 'self' https://*.bazaarvoice.com https://app.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud https://d2pqvatijh75rn.cloudfront.net https://exc.mm.dm.at https://mpsnare.iesnare.com https://omt.dm.at https://tags.tiqcdn.com https://web.cmp.usercentrics.eu https://www.dm.at https://www.google.com https://www.gstatic.com; worker-src 'self' blob:; connect-src 'self' https://*.bazaarvoice.com https://aggregator.service.usercentrics.eu https://api.mapbox.com https://api.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://browser-intake-datadoghq.eu https://cart-recos.services.dmtech.com https://cdcs.usercentrics.eu https://collect.tealiumiq.com https://consent-api.service.consent.usercentrics.eu https://consent-rt-ret.service.consent.usercentrics.eu https://consents