mlp-se.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-06 · ok HTTP/1.1 200 1643 ms crawled 2026-05-08

DE · 195.170.185.120 · AS41699 MLP Banking AG

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
MLP SE - Home
Description
Welcome at MLP
Language
de
Canonical
https://mlp-se.com/

Open Graph

title
MLP SE - Home
locale
de_DE
site name
home_mlp_ag_com_1
description
Welcome at MLP
updated time
2026-04-29T00:00:00Z

Technology

Server
Apache
Analytics
  • Google Tag Manager
Cookie consent
  • Usercentrics

Third-party hosts loaded (4)

  • charts3.equitystory.com×1
  • privacy-proxy.usercentrics.eu×1
  • web.cmp.usercentrics.eu×1
  • www.googletagmanager.com×1

Contact

Phone

Registration

Registrar
InterNetX GmbH
Created
2016-12-05
Expires
2026-12-05 198 days left
Updated
2025-12-06
Name servers
  • b.ns14.net
  • c.ns14.net
  • d.ns14.net
  • ns1.mlp.de
  • ns2.mlp.de

DNS records live

NS
  • b.ns14.net
  • c.ns14.net
  • d.ns14.net
  • ns1.mlp.de
  • ns2.mlp.de
MX
  • 10 mlpse-com0i.mail.protection.outlook.com
TXT
  • rovag_verification_token=2173D16A7440475AB1F6A7ECAAAB774C
  • RmZD7Wx3pXqsgdYu2uYUeQ6B6p2mIsV7k85nfzPu6oo=
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 include:spf.eqs-externaladdress.com include:spf2.mlp.de include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3SMr0k0Gu2WyIUWlgybi8z0rbjE+qGNmnguoX5aRxXcEr+2Z4bKHbISGGVSnAfOfs7bgDkZlBr44TX…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6jvx608BUiMJYsmNPC37OTbS0P0kWyWmPu6vv8SLxvtS3LNTKAfL6/yAddRwDXhG4tywCX4j6I8NXP…
selectors probed

Certificate (current)

GeoTrust EV RSA CA G2
from 2025-11-10 to 2026-12-12
Expires in 205 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://mlp-se.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), autoplay=(self), camera=(), display-capture=(), encrypted-media=(self), fullscreen=(self "https://www.youtube-nocookie.com"), geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), hid=(), idle-detection=(), serial=(), unload=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' https://portal.mlpdialog.de/ https://eu.b2c.com/ https://cdnjs.cloudflare.com/ https://*.pricehubble.com/ https://*.googleapis.com/ https://www.whofinance.de/ https://*.mlp.de/ https://*.usercentrics.eu https://www.googletagmanager.com https://*.google-analytics.com https://*.google.com https://*.hotjar.com https://connect.facebook.net https://lite.ekomiapps.de/ 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https://www.facebook.com wss://*.b2c.com/ https://*.b2c.com/ https://ad.doubleclick.net/ https://*.googleapis.com/ https://*.hotjar.io/ https://pagead2.googlesyndication.com/ wss://ws.hotjar.com/ https://*.mlp.de/ https://*.usercentrics.eu https://www.googletagmanager.com https://*.google-analytics.com https://*.google.com https://*.hotjar.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://www.whofinance.de/ https://*.mlp.de/ https://lite.ekomiapps.de/; font-src 'self' https://www.whofina
strict-transport-security
max-age=63072000

Links to (2)

Linked from (1)