onemarkets.eu

.eu crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1910 ms crawled 2026-05-18

NL · 2.16.27.85 · AS20940 Akamai International B.V.

Reputation 100/100

Classifying

HTML metadata

Title
onemarkets by UniCredit
Description
The onemarkets brand demonstrates a collective skillset (“one”) in investment and leverage products, as well as market access worldwide. onemarkets offers a wide range of products, especially in Germany, Austria and in Central and Eastern Europe, which include different levels of risk tolerance, market opinions and investment horizons. This includes investment products with and without capital protection as well as leverage products for more aggressive independent decision-makers.
Language
en

Technology

Third-party hosts loaded (1)

  • code.etracker.com×1

DNS records live

NS
  • a1-65.akam.net
  • a11-66.akam.net
  • a13-67.akam.net
  • a22-64.akam.net
  • a28-65.akam.net
  • a6-66.akam.net
TXT
Show 8 TXT records
  • actalis-dcv=ru2b1qk9atpm1s3bjnut2emuvj
  • actalis-dcv=so6416q1t4jhh0g3ii5mqj0dfd
  • actalis-dcv=ddf55ha5mfnobhgkf9toaelst9
  • actalis-dcv=kkc9t4c1sl8j32bojdj08n5sor
  • actalis-dcv=3090lncc4u2gut8vg6a802hb5q
  • Actalis-dcv=os006ujo0k6agbsa4odlca0a1d
  • actalis-dcv=nvh80rahtdhuhv8cp4g8u8ogkn
  • actalis-dcv=m91o2spnvgsftila072pfkqeic

Email authentication no MX

SPF
not published
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Actalis Organization Validated Server CA G3
from 2026-03-06 to 2027-03-06
Expires in 290 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.onemarkets.eu/en.html

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' *.etracker.com *.etracker.de; script-src 'self' *.etracker.com *.etracker.de *.video-cdn.net 'unsafe-inline' https://cdn.jsdelivr.net ; style-src 'self' 'unsafe-inline'; font-src 'self' *.video-cdn.net;
strict-transport-security
max-age=31536000; preload

Links to (2)

Linked from (1)