kvno.de
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn.consentmanager.net×1
- www.googletagmanager.com×1
Social
Registration
- Updated
- 2017-05-16
- Name servers
-
- ns8.colt.net.
- pns.dtag.de.
- secondary004.dtag.net.
DNS records live
- NS
-
- ns8.colt.net
- pns.dtag.de
- secondary004.dtag.net
- MX
-
- 10 s38mx02.kvno.de
- 20 s38mx01.kvno.de
- 50 s38hub30.kvno.de
- TXT
-
Show 5 TXT records
miro-verification=09e942cc44f94b3214b93c743d16ca121ac9f561_telesec-domain-validation=356279_2026-01-07_AqijqlOtFW7rEGxX4dPipFJOhUyl3O9g6XoxBBjk4Na7oUl0Hdcisco-ci-domain-verification=651a65d8e140b64a26dc78767386775905fedd7fc09191dcba3945bd55cb1510MS=ms72037738apple-domain-verification=ZmUG36zz5b61STpF
Email authentication partial
- SPF
-
v=spf1 mx -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports@kvno.de; ruf=mailto:dmarc-reports@kvno.de; pct=100policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Telekom Security ServerID OV Class 2 CA
Expires in 163 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
same-origin- x-frame-options
allow-from https://*.kvno.de https://*.cleverreach.com https://www.deutsches-ausschreibungsblatt.de https://*.kvnoportal.de/ https://*.kvnoportal.kvno.kv-safenet.de/ https://kvnoportal.kvno.kv-safenet.de/- permissions-policy
geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), gyroscope=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' https://static.dvinci-easy.com; script-src-elem 'self' https://www.piwik-kvno.de https://d.delivery.consentmanager.net https://cdn.consentmanager.net https://gmg.dvinci-hr.com https://static.dvinci-easy.com https://www.deutsches-ausschreibungsblatt.de/ https://www.googletagmanager.com https://snap.licdn.com/ https://connect.facebook.net/ 'sha256-OkHAkctZHHyuiKLX5X4fZkgwX44+DZup26VociU9JpI=' 'sha256-4ld+JekfYWTelVvQkT3TXJpQxlqgY5HR+GxEL0SlKf4=' 'sha256-hIbSxWkBqx9hQJGYPwM43BSIbAQysXyrpT+ZFVpWYqk=' 'sha256-t6Am9GZHkvME0ZcsCHAKD+3l3KKyF1M8Nu2LFYegPw8=' 'sha256-31CLyvBjdFYF2M8kgM5kXyDEaTzmXSZtzfdavPiQni4='; img-src 'self' https://kvno.dvinci-easy.com/ https://www.piwik-kvno.de https://cdn.consentmanager.net https://d.delivery.consentmanager.net https://i.ytimg.com/ https://*.ads.linkedin.com/ https://www.facebook.com/ https://www.googletagmanager.com https://ad.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com ht- strict-transport-security
max-age=31536000;includeSubdomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
require-corp, unsafe-none- cross-origin-resource-policy
cross-origin