justiz.de

.de crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 416 ms crawled 2026-05-18

DE · 93.184.133.233 · AS43066 Information und Technik Nordrhein-Westfalen

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Justizportal des Bundes und der Länder: Startseite
Language
de

Technology

Server
Apache

Registration

Updated
2025-06-12
Name servers
  • a.it.nrw.
  • b.nrw.de.
  • c.nrw.de.
  • dns.globvill.de.

DNS records live

NS
  • a.it.nrw
  • b.nrw.de
  • c.nrw.de
  • dns.globvill.de
MX
  • 40 relay7m.it.nrw.de
  • 60 relay7v.it.nrw.de
TXT
  • zone-ownership-verification-acaca770a15af946cb8c54fdcfa4316a4a31724ecf9e3a225e7a79e0ceca0435
  • D-TRUST=KINJFYVGP9LGVEFDEBI54F2

Email authentication partial

SPF
v=spf1 ip4:213.214.12.0/25 ip4:213.214.0.32/27 ip4:212.63.64.0/23 ip4:212.63.85.0/24 ip4:77.76.215.128/25 ip4:213.214.11.243 include:_spf.nrw.de include:_spf2.nrw.de -all
strict (-all)
DMARC
v=DMARC1; p=none; ruf=mailto:forensic_dmarc@mail.it.nrw.de
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

Telekom Security ServerID OV Class 2 CA
from 2025-11-12 to 2026-11-17
Expires in 181 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://justiz.de/index.php

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-content-type-options
nosniff
content-security-policy
default-src 'self' *.nrw.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.nrw.de *.google.com *.youtube.com *.youtu.be *.twimg.com *.twitter.com twitter.com *.jwpcdn.com *.gstatic.com *.googleapis.com *.googlesyndication.com *.openstreetmap.org *.mozilla.org *.vimeo.com *.vimeocdn.com *.flickr.com *.staticflickr.com *.cloudflare.com cdn.jsdelivr.net svc.webspellchecker.net; style-src 'self' 'unsafe-inline' *.nrw.de *.twitter.com twitter.com *.facebook.com *.googleapis.com *.twimg.com *.cloudflare.com cdn.jsdelivr.net svc.webspellchecker.net; font-src data: *; img-src data: *; frame-ancestors 'self' *.nrw.de *.facebook.com *.facebook.de *.twitter.com twitter.com *.google.com *.youtube.com *.youtu.be ytchannelembed.com; worker-src 'self' *.nrw.de *.facebook.com *.facebook.de *.twitter.com twitter.com *.google.com *.youtube.com *.youtu.be ytchannelembed.com *.openstreetmap.org broschueren.nordrheinwestfalendirekt.de; frame-src 'self' *.nrw.de *.facebook.co
strict-transport-security
max-age=31536000; preload

Links to (1)

Linked from (8)