meine-gardine-nach-mass.de

.de crawl

First seen 2026-05-15 · Last seen 2026-05-15 · ok HTTP/1.1 200 812 ms crawled 2026-05-20

DE · 185.88.214.186 · AS47447 23M GmbH

Reputation 87/100 weak security headers no dmarc policy

Classifying

HTML metadata

Title
Kiosk Step 001
Language
de

Technology

Server
Apache
CMS
Gatsby
Stack
PHP

Registration

Updated
2026-05-04
Name servers
  • nameserver-1-io.maxcluster.net.
  • nameserver-2-io.maxcluster.net.

DNS records live

NS
  • nameserver-1-io.maxcluster.net
  • nameserver-2-io.maxcluster.net
MX
  • 10 mail-io.maxcluster.net

Email authentication weak

SPF
v=spf1 a mx ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-05-03 to 2026-08-01
Expires in 72 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://meine-gardine-nach-mass.de/

present
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
findings
  • missing HSTS
  • missing Content Security Policy
  • weak frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN, SAMEORIGIN
x-content-type-options
nosniff
content-security-policy-report-only
font-src *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com https://plumrocket.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagma