ich-tanke.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (4)
- cdn.privacy-mgmt.com×1
- dn0qt3r0xannq.cloudfront.net×1
- www.google.com×1
- www.googletagservices.com×1
Registration
- Updated
- 2025-08-11
- Name servers
-
- ns2.inwx.de.
- ns3.inwx.eu.
- ns.inwx.de.
DNS records live
- NS
-
- ns.inwx.de
- ns2.inwx.de
- ns3.inwx.eu
- MX
-
- 10 smtp-in0.prod0.webspace.bz
- 20 smtp-in1.prod0.webspace.bz
- TXT
-
google-site-verification=UDNN4-pLDuPpKfuGmz1s7fEX2RqwZ2G9s3aJU9VcQwI
Email authentication partial
- SPF
-
v=spf1 a mx include:_spf.webspace.bz ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
same-origin- x-frame-options
DENY- permissions-policy
camera=(self), fullscreen=(self), geolocation=(self)- x-content-type-options
nosniff- content-security-policy
default-src https: blob: data:; script-src https: 'unsafe-inline' 'unsafe-eval' blob: data:; style-src https: 'unsafe-inline' blob: data:; img-src https: blob: data:; font-src https: data:; connect-src https:; frame-src https:; child-src https: blob:; worker-src https: blob:;- strict-transport-security
"max-age=31536000"- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin