pensador.ch

.ch crawl

First seen 2026-05-29 · Last seen 2026-05-31 · ok HTTP/1.1 200 713 ms crawled 2026-05-31

DE · 188.94.251.8 · AS15817 Mittwald CM Service GmbH & Co. KG

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Experten für unabhängige Vermögensverwaltung | PENSADOR: PENSADOR Partner AG
Description
Von unseren Standorten in Zürich, Baden und St. Gallen aus betreuen wir Kunden in allen Fragen der Vermögensverwaltung bzw. des Wealth Managements.
Language
de
Generator
TYPO3 CMS
Canonical
https://www.pensador.ch/startseite

Open Graph

title
Startseite
description
Von unseren Standorten in Zürich, Baden und St. Gallen aus betreuen wir Kunden in allen Fragen der Vermögensverwaltung bzw. des Wealth Managements.

Technology

Server
Apache
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • k3ks.ateliermerz.com×1
  • www.googletagmanager.com×1

Contact

Phone

DNS records live

NS
  • ns1.hiho.ch
  • ns2.hiho.ch
  • ns3.hihoch.net
MX
  • 0 pensador-ch.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com include:agenturserver.de -all
strict (-all)
DMARC
v=DMARC1; p=none; pct=100; rua=mailto:admin@pensadorpartner.onmicrosoft.com; ruf=mailto:pensadorpartner.onmicrosoft.com; fo=1
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzOqFCnqppr1t08u7sMiLTWw/CLbmQkqWUlMEHjn5BDrVA6KFU6FNAMIaX79eXTsYEsgj2s8hZeD49k…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArxHVQ85CdRneIK5WphH++p0Pppb8xo50gKKegSNmUdFqb+cCkD0guRcPQoBhSrbOXLQb18NPuiOBdx…
selectors probed

Certificate (current)

GeoTrust TLS RSA CA G1
from 2025-10-10 to 2026-11-10
Expires in 162 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.pensador.ch/startseite

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
no-referrer, same-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(self), microphone=(self), midi=(self), camera=(self), usb=(self), magnetometer=(self), accelerometer=(self), gyroscope=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self' k3ks.ateliermerz.com; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' *.google-analytics.com *.g.doubleclick.net *.googletagmanager.com maps.gstatic.com *.googleapis.com k3ks.ateliermerz.com data:; base-uri 'none'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com blob: *.google.com k3ks.ateliermerz.com; style-src-elem 'self' 'nonce-3GXY25F2kJavmP7qdmdzGwrAITS4rfACrwH1V2r8SZ2lXcS9NUiOuw' *.google-analytics.com *.googletagmanager.com k3ks.ateliermerz.com 'report-sample'; style-src 'self' 'unsafe-inline' *.google-analytics.com *.googletagmanager.com k3ks.ateliermerz.com 'report-sample'; worker-src 'self' blob:; object-src 'none'; font-src 'self'; script-src 'self' k3ks.ateliermerz.com 'unsafe-eval' *.googletagmanager.com maps.googleapis.com 'report-sample'; script-src-elem 'self' k3ks.ateliermerz.com 'unsafe-eval' *.googletagmanager.com maps.googleapis.com 'unsafe-inline' 'report-sample'; connect-src 'self' *.google-analytics.com *.google
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (2)

Linked from (1)