pax.de
HTML metadata
Technology
- Server
- openresty
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (3)
- app.usercentrics.eu×3
- privacy-proxy.usercentrics.eu×3
- api.usercentrics.eu×1
Social
Contact
- Phone
- Address
- 55218, Ingelheim, DE
Registration
- Updated
- 2026-03-31
- Name servers
-
- ns2.inwx.de.
- ns3.inwx.eu.
- ns.inwx.de.
DNS records live
- NS
-
- ns.inwx.de
- ns2.inwx.de
- ns3.inwx.eu
- MX
-
- 100 d200412.a.ess.uk.barracudanetworks.com
- 200 d200412.b.ess.uk.barracudanetworks.com
- TXT
-
abuseipdb-verification=DBnmZIrK
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 mx ip4:212.99.222.106 include:spf.crsend.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3ErKuH7KmHCTQdIqOM3Gog71Mj/I08KZ8kPdTFtXX0C6+qKiGrexTABjRZvPQBhVykyHZS3OJ4xdVBEoQl… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDVNTetkg5OvC3sZZrnlvvJuU0ez8BB9Fuq9d+hMJjMTaw2NjKEr7NL/STDO/JCIUMyM3k10SI4/bsZbf3w4MuP4/…
selectors probed - s1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 218 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' https: *.mypax.website; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: *.mypax.website; object-src 'self' 'unsafe-inline' *.mypax.website; style-src 'self' 'unsafe-inline' data: https: *.mypax.website; img-src 'self' data: https: *.mypax.website *.canto.global; media-src 'self' 'unsafe-inline' data: https: *.mypax.website; frame-src 'self' 'unsafe-inline' data: https: *.mypax.website; frame-ancestors *; child-src 'self' 'unsafe-inline' data: https: blob: *.mypax.website; font-src 'self' 'unsafe-inline' https: data: *.mypax.website; connect-src *; report-uri /report-csp-violation; upgrade-insecure-requests- strict-transport-security
max-age=1000; includeSubDomains, max-age=63072000;includeSubDomains; preload
Links to (6)
- facebook.com×2
- instagram.com×2
- kununu.com×2
- linkedin.com×2
- mypax.de×2
- xing.com×2