payone.com

.com crawl dns

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1430 ms crawled 2026-05-19

US · 34.49.175.236 · AS396982 Google LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
PAYONE | Das beste PAYMENT | PAYONE
Description
PAYONE bietet das beste Payment für Ihr Business: Sparen Sie Zeit, Geld & Nerven! ✔️ Online, Instore oder Omnichannel ➤ Jetzt mehr erfahren!
Language
de
Canonical
https://www.payone.com/DE-de
Translations
  • de-de
  • en-de

Open Graph

url
https://www.payone.com/DE-de
title
PAYONE | Das beste PAYMENT
locale
de_DE
site name
PAYONE
description
PAYONE bietet das beste Payment für Ihr Business: Sparen Sie Zeit, Geld & Nerven! ✔️ Online, Instore oder Omnichannel ➤ Jetzt mehr erfahren!
article:author
Default Author
locale:alternate
en_DE

Technology

CDN
Amazon CloudFront
CMS
Nuxt

Third-party hosts loaded (1)

  • widget.moin.ai×1

Social

Contact

Address
Lyoner Straße 15, 60528, Frankfurt am Main, DE

Registration

Registrar
CSC Corporate Domains, Inc.
Created
1998-10-02
Expires
2026-10-01 134 days left
Updated
2025-09-27
Name servers
  • ns-cloud-a1.googledomains.com
  • ns-cloud-a2.googledomains.com
  • ns-cloud-a3.googledomains.com
  • ns-cloud-a4.googledomains.com

DNS records live

NS
  • ns-cloud-a1.googledomains.com
  • ns-cloud-a2.googledomains.com
  • ns-cloud-a3.googledomains.com
  • ns-cloud-a4.googledomains.com
MX
  • 10 mx1.payone.com
  • 10 mx2.payone.com
TXT
Show 9 TXT records
  • canva-site-verification=VOBY4CAY6ik36NChA8aNEQ
  • 8fws4s81122dfsxlcpvxkdrxysk6fzhy
  • miro-verification=9a18503a11acd467a6176c2fe5eb1c8b61d34966
  • cisco-ci-domain-verification=57e3d0a4d160f89f557fe5d399b69dc54ec6be2d87e3f3f92dea807aa2352280
  • google-site-verification=S-dCI9DFsYGOHYiDLZ3bHFnwnXMb9hw3gLFm5okw5XI
  • swisssign-check=I8WqDDTy8dfADZoFf6qgHT58UyU
  • apple-domain-verification=B4n5NPkDtSEiA5Yc
  • MS=ms64519113
  • MS=ms66260373

Email authentication partial

SPF
v=spf1 a mx include:spfextend.payone.com include:_spf.services.ingenico.com include:_spf.salesforce.com include:amazonses.com include:_spf.senders.scnem.com ip4:45.143.177.14 ip4:45.143.177.15 ip4:18.195.170.81/32 ip4:82.97.146.0/23 ~all
softfail (~all)
DMARC
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:iej4eobm@ag.eu.dmarcadvisor.com;ri=86400;aspf=r;adkim=r;fo=1
policy: none (monitoring only) · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvs/Di38iMnRgZtXd8DvgQDb6BCF8RGaRvTFqIeJlAJtZMBhKmUblp8by42j2s582WjZ/t/Hr4KK9BM…
selectors probed

Certificate (current)

WR3
from 2026-05-11 to 2026-08-09
Expires in 82 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.payone.com/DE-de

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()
x-content-type-options
nosniff
content-security-policy
base-uri 'none'; font-src 'self' data: https://*.moin.ai https://payone-static.s3.eu-central-1.amazonaws.com; form-action 'self'; frame-ancestors 'self' https://app.storyblok.com; img-src 'self' data: https://*.payone.com https://a.storyblok.com https://*.usercentrics.eu https://bat.bing.com https://*.doubleclick.net https://*.moin.ai https://*.facebook.com https://www.google.de https://*.google.com; object-src 'none'; script-src-attr 'unsafe-hashes' 'sha256-qOBd84dGYZ1TXAj+NIqiwfe6+6cjjOJx8QNDBdoNQyM='; style-src 'self' https: 'unsafe-inline'; script-src 'self' https://bat.bing.com https://ad4m.at https://connect.facebook.net https://sswt.payone.com https://unpkg.com https://*.usercentrics.eu https://*.moin.ai https://*.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com 'unsafe-inline' 'strict-dynamic' 'unsafe-eval' 'nonce-vdgaGWBRF7YBu81zQI1I6N9P'; upgrade-insecure-requests; default-src 'self'; connect-src 'self' https://*.moin.ai wss://*.moin.ai h
strict-transport-security
max-age=15552000; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-origin

Links to (6)

Linked from (6)