dm.pl
HTML metadata
Technology
Third-party hosts loaded (4)
- assets.dm.de×39
- exc.mm.dm.de×1
- media.dm-static.com×1
- www.google.com×1
DNS records live
- NS
-
- auth2.dm-drogeriemarkt.de
- ns.do-ex.com
- ns.do-ex.net
- ns.do-ex.org
- MX
-
- 10 mailgw1.dm.de
- 10 mailgw2.dm.de
- 10 mailgw3.dm.de
- 10 mailgw4.dm.de
- TXT
-
Show 6 TXT records
docker-verification=47f03afa-e024-4d75-9824-333302a04aefwiz-domain-verification=865786f37d551a64016b99b423b7624fb6d14aff4b4de9e5f664a55bfcb2b4250o42/8J2VbGtPGmHI60h1o6H+78u8vzkiu4abKHQwDUW4bRJbFrimijwbzYEsJYp1UnQr13uwa4SYTzMglZDQg==MS=ms39167158 TTL:3600swisssign-check=uHdEfnOGQlDLjkMepypsOETTLMsbw=8zvaWy/1rK+CLoklmN0QD0KEriVOEkzP37C+n961keQt
- Verified for
-
- Adobe
- Anthropic
- Atlassian
- Meta
- Yahoo
Email authentication strong
- SPF
-
v=spf1 include:spf.mailsecurity.dm.de -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@mailsecurity.dm.depolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src data: https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud; script-src 'self' https://*.bazaarvoice.com https://app.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud https://d2pqvatijh75rn.cloudfront.net https://exc.mm.dm.pl https://mpsnare.iesnare.com https://omt.dm.pl https://tags.tiqcdn.com https://web.cmp.usercentrics.eu https://www.dm.pl https://www.google.com https://www.gstatic.com; worker-src 'self' blob:; connect-src 'self' https://*.bazaarvoice.com https://aggregator.service.usercentrics.eu https://api.mapbox.com https://api.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://browser-intake-datadoghq.eu https://cart-recos.services.dmtech.com https://cdcs.usercentrics.eu https://collect.tealiumiq.com https://consent-api.service.consent.usercentrics.eu https://consent-rt-ret.service.consent.usercentrics.eu https://consents- strict-transport-security
max-age=31556952; includeSubDomains; preload- content-security-policy-report-only
default-src 'self'; font-src data: https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud; script-src 'self' https://*.bazaarvoice.com https://app.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://composer.apps.nonprod.gcp.dmtech.cloud https://d2pqvatijh75rn.cloudfront.net https://exc.mm.dm.pl https://mpsnare.iesnare.com https://omt.dm.pl https://tags.tiqcdn.com https://web.cmp.usercentrics.eu https://www.dm.pl https://www.google.com https://www.gstatic.com; worker-src 'self' blob:; connect-src 'self' https://*.bazaarvoice.com https://aggregator.service.usercentrics.eu https://api.mapbox.com https://api.usercentrics.eu https://apps.bazaarvoice.com https://assets.dm.de https://browser-intake-datadoghq.eu https://cart-recos.services.dmtech.com https://cdcs.usercentrics.eu https://collect.tealiumiq.com https://consent-api.service.consent.usercentrics.eu https://consent-rt-ret.service.consent.usercentrics.eu https://consents