lotto24.de
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Hotjar
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- customer-f2ft7bq6n7wg8wej.cloudflarestream.com×1
- fonts.googleapis.com×1
- vars.hotjar.com×1
- vc.hotjar.io×1
- w.usabilla.com×1
- www.googletagmanager.com×1
Registration
- Updated
- 2020-02-05
- Name servers
-
- gordon.ns.cloudflare.com.
- sara.ns.cloudflare.com.
DNS records live
- NS
-
- gordon.ns.cloudflare.com
- sara.ns.cloudflare.com
- MX
-
- 10 lotto24-de.mail.eo.outlook.com
- TXT
-
Show 9 TXT records
A67E70D99C374491552-153758614bw=TvwXrNODqYga0jy6rSygenewOzcNhy0x7ZGQVMliQD82G0EjpvjezG73TeOQVmuzjFBDj8AadHbbwyEQtLmyBlEstatus-page-domain-verification=snw5s1fd1np9f220bd8e-ffbf-4ab7-a916-193e08afb166swisssign-check=xdiunIyUQnfuQKtusv8jrsKhS11uwxbTEnGTUJlAlrGkdJJVjNkuD57yPF5PXyqG2S2sv8VhoOJyu3qcdbmJrlLSqVSm/Qq5DWovyejluSklTkvMXEGHxrawizCJhQCQ==PuUQotftZwd2KXpbVkeCCnqVUGcMmz3M7FQw4+fFWwM=
- Verified for
-
- Ahrefs
- Apple
- Atlassian
- Cursor
- DocuSign
- Google Workspace
- Meta
- Microsoft 365
- Miro
- OpenAI
- Slack
- Workplace
- Zoom
Email authentication strong
- SPF
-
v=spf1 ip4:217.111.5.216 ip4:185.62.24.216 ip4:185.62.25.216 ip4:217.111.5.203 include:mail.zendesk.com include:de._spf.fagms.net include:stspg-customer.com include:spf.protection.outlook.com include:_spf.mailgun.org include:_spf.eu.mailgun.org include:spf.mailjet.com include:spf.mandrillapp.com include:mg-spf.greenhouse.io -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; ruf=mailto:dmarc-report@zealnetwork.de; rua=mailto:bd34c240685849ff9db4726460dbd49b@dmarc-reports.cloudflare.net,mailto:dmarc_agg@vali.email,mailto:dmarc-report@zealnetwork.de; fo=1:d:s; ri=14400; sp=rejectpolicy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqypv7r5J8RonXT8j31OjaAM4uGzktJgNSkdm6rTG3y0ySNGrfp0KFg69t3dzEXXUXsdM6Ceh2qpVdK… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArrU2L4niO596SKLpy+CXuZpKNj+9e0lQNihvKoMfPPBra4mV80aKWkZJ0AIwzlZD5Ggs0+/Ml9Hz7x… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
Corporation Service Company RSA OV SSL CA 2
Expires in 248 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(self "https://demo-api.incodesmile.com" "https://api.incodesmile.com"), autoplay=(self), camera=(self "https://demo-api.incodesmile.com" "https://api.incodesmile.com"), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(self), geolocation=(self "https://demo-api.incodesmile.com" "https://api.incodesmile.com"), gyroscope=(self "https://demo-api.incodesmile.com" "https://api.incodesmile.com"), keyboard-map=(), magnetometer=(), microphone=(self "https://static.zdassets.com" "https://demo-api.incodesmile.com" "https://api.incodesmile.com"), midi=(), payment=(), picture-in-picture=(self "https://challenges.cloudflare.com"), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(self), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(self), gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), unload=(*)- x-content-type-options
nosniff- content-security-policy
base-uri 'self' https://d6tizftlrpuof.cloudfront.net/; default-src 'self'; manifest-src 'self'; style-src 'unsafe-inline' 'self' https://d6tizftlrpuof.cloudfront.net/ https://integrations.etrusted.com/ *.gstatic.com vorteilsguru.de *.surveygizmo.com; connect-src 'self' lotto24.de *.lotto24.de *.www.lotto24.de *.data.lotto24.de wss://lotto24.de wss://www.lotto24.de wss://games.lotto24.de tipp24.com *.tipp24.com tipp24.de *.tipp24.de gmx.de *.gmx.de gmx.net *.gmx.net lotto.gmx.de *.lotto.gmx.de *.lotto.gmx.net *.web.de lotto.web.de *.lotto.web.de lotto.n-tv.de *.lotto.n-tv.de google.com *.google.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net *.googlesyndication.com frontends.zig.lotto24.de *.frontends.zig.lotto24.de tx-service.zig.lotto24.de mylotto24.frontend.zig.services sentry.io *.sentry.io *.grafana.net cloudflareinsights.com *.cloudflareinsights.com aswpsdkeu.com aswpapieu.com analytics.tiktok.com *.taboola.com- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-site