fde.dk

.dk crawl

First seen 2026-05-29 · Last seen 2026-05-31 · ok HTTP/1.1 200 721 ms crawled 2026-05-31

DK · 195.249.217.239 · AS3292 TDC Holding A/S

Reputation 100/100

Classifying

HTML metadata

Title
VAT Refund with FDE A/S
Description
FDE offer VAT Refund and payment solutions for motorway, tunnel and ferry. Our services provides economical and administrative advantages.
Language
en
Translations
  • da
  • de
  • en

Open Graph

url
.
title
FDE
description
.

Technology

jQuery
1.12.1 known XSS (<3.5)
Stack
ASP.NET

Third-party hosts loaded (2)

  • policy.cookieinformation.com×1
  • www.fdeplus.com×1

Social

Contact

Phone

DNS records live

NS
  • ns-a.eurodns.com
  • ns-b.eurodns.org
  • ns-c.eurodns.eu
  • ns-d.eurodns.biz
MX
  • 10 de-smtp-inbound-1.mimecast.com
  • 10 de-smtp-inbound-2.mimecast.com
TXT
Show 10 TXT records
  • hpd7f6fzs88c2wbq3lr7lcr2m74k767p
  • 3jrdy183whvgyf46x24n2rfqrvxjfr3w
  • x3xtnv1ty7svg8zv018lbj2vmh2fllmj
  • QuoVadis=47d39afc-894a-48de-95e5-f63d88b472fb
  • QuoVadis=43db0e8a-8ae0-417a-8046-b19ba75ae559
  • dmj9z541gv5djgmtbklyk26kr1bd40sy
  • _ctbfplkstnem2kzen291g3z49f38a36
  • BRzO0AtcljAbBr8Bh4YX3dvAfwlDEIpXmr0T7kHG3FJRzWQRI0OfGT9adrXxvfQalQXOlxzxxBhjlkkjbdY4mg==
  • 643c6e7579484603bfdd95003be73bf3
  • ec1aaf4d-2f5e-4387-9fed-e8fd9ced7fc6-16102019
Verified for
  • Apple
  • GlobalSign
  • Microsoft 365

Email authentication strong

SPF
v=spf1 ip4:195.249.217.224/27 include:spf.protection.outlook.com include:support.itrp.com include:de._netblocks.mimecast.com include:spf2.fde.dk -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; sp=reject; rua=mailto:uextvehk@ag.dmarcian-eu.com;ruf=mailto:uextvehk@fr.dmarcian-eu.com; rf=afrf;pct=100;
policy: quarantine · sp=reject
DKIM
no key found at common selectors

Certificate (current)

GlobalSign RSA OV SSL CA 2018
from 2025-10-28 to 2026-11-29
Expires in 181 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.fde.dk/

present
  • strict-transport-security
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • missing Content Security Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
autoplay=(self), camera=(), encrypted-media=(), fullscreen=(self), geolocation=(self), microphone=(), midi=(), payment=(), usb=(), accelerometer=(), gyroscope=(), magnetometer=()
x-content-type-options
nosniff
strict-transport-security
max-age=31536000; includeSubdomains
content-security-policy-report-only
child-src policy.app.cookieinformation.com www.fdeplus.com; connect-src 'self' api1.fde.dk consent.app.cookieinformation.com www.google-analytics.com itd.matomo.cloud policy.app.cookieinformation.com; default-src 'self' 'unsafe-eval' 'unsafe-inline' cdnjs.cloudflare.com consent.app.cookieinformation.com fonts.googleapis.com fonts.gstatic.com policy.app.cookieinformation.com policy.cookieinformation.com www.fdeplus.com www.google-analytics.com itd.matomo.cloud; font-src 'self' cdnjs.cloudflare.com fonts.gstatic.com; form-action 'self'; frame-ancestors 'self'; frame-src www.google.com policy.app.cookieinformation.com www.fdeplus.com youtube-nocookie.com; img-src 'self' data: google-analytics.com gstatic.com coi-prod.azureedge.net policy.app.cookieinformation.com; manifest-src 'self'; object-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' cdn-js.net cdnjs.cloudflare.com policy.app.cookieinformation.com policy.cookieinformation.com www.gstatic.com www.go

Links to (1)

Linked from (1)