pax-bkc.de

.de crawl

First seen 2026-04-14 · Last seen 2026-05-14 · ok HTTP/1.1 200 1009 ms crawled 2026-05-08

DE · 194.149.253.55 · AS15590 Atruvia AG

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Startseite - Pax-Bank für Kirche und Caritas eG
Description
Startseite
Language
de-DE
Canonical
https://www.pax-bkc.de/startseite.html

Open Graph

url
https://www.pax-bkc.de/startseite.html
title
Startseite
language
de
description
Startseite

Technology

Third-party hosts loaded (2)

  • atruvia.scene7.com×21
  • contentmanager.incognito.ms×2

Social

Registration

Updated
2025-05-09
Name servers
  • ns1.atruvia.de.
  • ns2.atruvia.de.
  • ns3.atruvia.de.
  • ns4.atruvia.de.

DNS records live

NS
  • ns1.atruvia.de
  • ns2.atruvia.de
  • ns3.atruvia.de
  • ns4.atruvia.de
MX
Show 8 MX records
  • 20 gmail22.gadmail.de
  • 20 gmail23.gadmail.de
  • 20 wmail22.gadmail.de
  • 20 wmail23.gadmail.de
  • 30 omail22.gadmail.de
  • 30 omail23.gadmail.de
  • 30 rmail22.gadmail.de
  • 30 rmail23.gadmail.de
TXT
Show 4 TXT records
  • D-TRUST=VBNBJCX5NCQTLJBUFJJNZ82
  • D-TRUST=8ANHTYZQG6UDAGRQ2WYSMVW
  • MS=ms42871783
  • apple-domain-verification=YO5QS5oZ9Bn9Q5fu

Email authentication partial

SPF
v=spf1 include:net1.spf.fiduciagad.de include:inxserver.com a:tea83716a.emailsys1a.net include:spf.protection.infrontfinance.com ip4:85.235.66.150 IP4:78.47.8.147 IP6:2a01:4f8:d0a:42c2::2 -all
strict (-all)
DMARC
v=DMARC1; p=none; adkim=r; aspf=r
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

D-TRUST SSL Class 3 CA 1 EV 2009
from 2026-04-05 to 2026-10-20
Expires in 154 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.pax-bkc.de/startseite.html

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' https://maps.googleapis.com 'sha256-aSqN2R3jDvHFUL3vVOUtG6OJr1IF+Y31IPMdo0dLU6U=' 'nonce-9116a85a91c5c52065ac316129aff732' https://www.etracker.de https://code.etracker.com; base-uri 'self'; font-src 'self' https: data:; form-action 'self'; frame-src 'self' https://www.youtube-nocookie.com https://fincalc-services-vrnw.de https://vra.module.vr-networld.de https://www.ruv-aktion.de https://cloud.ruv.de https://suche.geno-banken.de https://webmodul.incognito.ms https://reisebank.de https://www.etracker.de https://code.etracker.com; frame-ancestors 'none'; object-src 'self'; style-src 'self' 'unsafe-inline' https:; img-src https: data:; connect-src 'self' data: https://maps.googleapis.com wss://*.mypurecloud.de https://www.etracker.de https://code.etracker.com https://atruvia.scene7.com; block-all-mixed-content; script-src-attr 'none'; media-src https: https://atruvia.scene7.com
strict-transport-security
max-age=31536000

Links to (9)

Linked from (6)