mvz-ke.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- cdn.eye-able.com×2
- consent.amedick-sommer.de×1
Registration
- Updated
- 2026-02-12
- Name servers
-
- nsa0.schlundtech.de.
- nsb0.schlundtech.de.
- nsc0.schlundtech.de.
- nsd0.schlundtech.de.
DNS records live
- NS
-
- nsa0.schlundtech.de
- nsb0.schlundtech.de
- nsc0.schlundtech.de
- nsd0.schlundtech.de
- MX
-
- 10 mail.kliniken-es.net
- Verified for
-
- Cisco
Email authentication weak
- SPF
-
v=spf1 mx ip4:134.119.46.207 ip4:84.201.104.81 include:spf.protect.kvnbw.de -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 25 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: data: www.youtube.com s.ytimg.com *.usercentrics.eu *.google.com *.googletagmanager.com *.google-analytics.com analyzer.amedick-sommer.de klinikum-esslingen.concludis.de consent.amedick-sommer.de cdn.eye-able.com; style-src 'self' 'unsafe-inline' klinikum-esslingen.concludis.de cdn.eye-able.com consent.amedick-sommer.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: www.youtube.com s.ytimg.com *.usercentrics.eu *.google.com *.googletagmanager.com *.google-analytics.com analyzer.amedick-sommer.de klinikum-esslingen.concludis.de arzt.medflex.de cdn.eye-able.com consent.amedick-sommer.de; img-src * data: consent.amedick-sommer.de; object-src 'none'; frame-ancestors 'self' http://klinikum-esslingen.de https://wirke.klinikum-esslingen.de http://staffbase.com capacitor://klinikum-esslingen.de capacitor://wirke.klinikum-esslingen.de capacitor://staffbase.com http://localhost https://localhost; frame-src *;- strict-transport-security
max-age=31536000; includeSubDomains; preload