pavana-wind.com

.com crawl

First seen 2026-04-20 · Last seen 2026-05-14 · ok HTTP/1.1 200 1093 ms crawled 2026-05-14

DE · 217.160.0.182 · AS8560 IONOS SE

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
Pavana GmbH | Akkreditiertes Unternehmen für Windplanungsleistungen
Description
Expertin für Wind-, Schall- und Schattenwurfgutachten, Durchführung von Windmessungen und LiDAR-Verifizierung
Language
de
Generator
TYPO3 CMS
Canonical
https://www.pavana-wind.com/
Translations
  • de
  • en
  • pl

Open Graph

title
Pavana GmbH | Akkreditiertes Unternehmen für Windplanungsleistungen
description
Expertin für Wind-, Schall- und Schattenwurfgutachten, Durchführung von Windmessungen und LiDAR-Verifizierung

Technology

Server
Apache
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • consent.cookiebot.eu×1
  • www.googletagmanager.com×1

Contact

Phone

Registration

Registrar
IONOS SE
Created
2017-03-22
Expires
2027-03-22 305 days left
Updated
2026-03-23
Name servers
  • ns1025.ui-dns.org
  • ns1063.ui-dns.biz
  • ns1095.ui-dns.com
  • ns1098.ui-dns.de

DNS records live

NS
  • ns1025.ui-dns.org
  • ns1063.ui-dns.biz
  • ns1095.ui-dns.com
  • ns1098.ui-dns.de
MX
  • 0 pavanawind-com01e.mail.protection.outlook.com
TXT
  • linkedin-site-verification=a458db03-1ee7-415d-b401-b19c2f04af2b
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:_spf-eu.ionos.com include:spf.protection.outlook.com include:_spf.rexx-suite.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarc@pavana-wind.com; adkim=s; aspf=s; pct=100
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwmn1fj2i8p4I4p0VYuxt/4ViGyfAkPhwldTZfq450m4SZ+Q0CqLQkGFWhBfZ740VLCUHuC6GSR/4Ch+a+N1…
selectors probed

Certificate (current)

Sectigo RSA Domain Validation Secure Server CA
from 2025-05-28 to 2026-06-12
Expires in 22 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://www.pavana-wind.com//

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self' 'unsafe-inline' data: fonts.gstatic.com maps.gstatic.com maps.google.com *.googleapis.com *.cookiebot.eu https://*.googletagmanager.com *.google-analytics.com *.fonts.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com maps.google.com *.cookiebot.eu *.googletagmanager.com; connect-src 'self' *.googleapis.com *.google-analytics.com *.cookiebot.eu;

Linked from (1)