nordlb.de
HTML metadata
Technology
Third-party hosts loaded (1)
- www.nordlb.com×1
Social
Registration
- Updated
- 2024-12-05
- Name servers
-
- ns1.s-fg-net.de.
- ns2.s-fg-net.com.
- ns3.s-fg-net.eu.
- ns4.s-fg-net.de.
- ns5.s-fg-net.com.
DNS records live
- NS
-
- ns1.s-fg-net.de
- ns2.s-fg-net.com
- ns3.s-fg-net.eu
- ns4.s-fg-net.de
- ns5.s-fg-net.com
- MX
-
- 100 mail-1.nordlb.de
- 100 mail-2.nordlb.de
- TXT
-
Show 28 TXT records
atlassian-domain-verification=xZSR3eg9ZY3IGuy77QwPTUhr6cX6vNjKNVgdiOSj2QzlBiZ3OjZs3NaIkwLTNexzfifdmiL8GGUS3BPisGfTJ3cy2FDHbYzhMS=ms58895089DJ5q1s50AKJZY2g0V4k1xXeYfM6GeCj6rgzdc3170r5ylg8qz4tg82dfqbmxpjyvTXT=rVHDph8v8gt0AwA96w1cdYE9KSPSefErTXT=rJqz5THu77K3ThuyTzb1JkiXgTqfVPbbVbR1zj3r8kyZmK8uvdt4U9gPgHeHWVKJw3zph7p5jwh7x3zqy4td164hgp2cgxm3_4dgwapxkphrkhq518r07ak6jwuo87jd_974vpmi1gp92dxz3xwfo6kcigaewoe4F0uUDRZUknMBcKYDFMVRuGCpD3TfsBvcYBrWV2U1qETqvNP8hWceLqPCszTdNLDQyhww1wxm0YHmGg1Tv0KCEfjSXZ5D1QpLamC5zLJAg72wppsZv7Quar39SRjKaQwrZdpm9VQEzpAkknLa57frniWptV5Ydb1hBwxWZ96WtnI5tpzhHNjqzPZAI7rePdf073Cz5NKGzvp7C3wypL99gXLHygH7rSMJfZ45zJTSJzpQwySrH2dmizkLhnNqVQ1X0HKxPwafuX9Ygh5rZnmtu9v6srRkXgsTapple-domain-verification=u6TcjUppVKUCsaQLdocusign=e6fc1f23-115d-43f4-be57-accdd2580e620NEkT4CYHNyDqks2VC4cv9SyByZcm90keAYN7JK5ZbVRY9SeLFpZwcfDfx3BeNPxNyqFH581UkZhQa7MDT8LDdR3WrFyZ6CBrjlFlsnk6oBWfRXjQtsEPMgXoN2QK46JzYy1z2ofrLQiRU5VuO90VcXwrOxYgp0bFvvWbCvJ4jTmNbWytF2nCw==_xyms4i8pgdir5iydopv1b2x00xczxdpk1wP1UC584mjvfEHkGeRUNpHuZWiBuYy
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.mail.s-web.de include:spf.emma.sparkasse.de include:spf.protection.outlook.com include:osnow.de include:spf.bevent.eu ip4:5.9.189.189 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:ees@nordlb.depolicy: none (monitoring only) - DKIM
-
- s1:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVKQpJmlzGNMqE/dpnyyUL6rTocQ5PHEnXlUBnzV9wLfV7MYNndMPRxzExeVw4rzHCkuewkU+rCL1ZJSz4rsyUFge83…
selectors probed - s1:
Certificate (current)
Atos TrustedRoot Server CA RSA 2022
Expires in 147 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' https://cdn.trackboxx.info 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://nordlb.de https://*.nordlb.de https://nordlb.com https://*.nordlb.com https://hit.trackboxx.info; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://mailing.nordlb.de; media-src 'self' blob:; script-src-elem 'self' https://cdn.trackboxx.info 'report-sample'; style-src 'self' 'sha256-GqiEX9BuR1rv5zPU5Vs2qS/NSHl1BJyBcjQYJ6ycwD4=' 'sha256-imM3HZi7Y+FaJ86tYMKkfeIFtkVV27aGv/h/xsSiOkI=' 'sha256-B6s7c9GN+kYMLD8pbbmA1VDEDGPFLtfUgjJXeCGLuNk=' 'report-sample'; worker-src blob: 'report-sample'; connect-src 'self' https://hit.trackboxx.info; object-src 'none'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.nordlb.de/@http-reporting?csp=report&requestTime=1778590292382515&requestHash=3e93cfb7571fd8a9a84145244d7cc05f3c26e727- strict-transport-security
max-age=31536000; includeSubDomains
Links to (10)
- youtube.com×2
- blsk.de×2
- facebook.com×2
- instagram.com×2
- linkedin.com×2
- nordlb.com×2
- s-investor.de×2
- twitter.com×2
- xing.com×2
- deutsche-hypo.de×1