pwbox.de

.de crawl

First seen 2026-04-23 · Last seen 2026-05-17 · ok HTTP/1.1 200 5052 ms crawled 2026-05-17

DE · 195.201.173.232 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

sector tech type app saas

HTML metadata

Title
Bitwarden Web vault

Technology

Server
nginx

Registration

Updated
2024-09-16
Name servers
  • ns2.inwx.de.
  • ns3.inwx.eu.
  • ns.inwx.de.

DNS records live

NS
  • ns.inwx.de
  • ns2.inwx.de
  • ns3.inwx.eu
MX
  • 5 mail.cdom.de

Email authentication weak

SPF
v=spf1 mx a:mail.cdom.de ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-03-30 to 2026-06-28
Expires in 41 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://pwbox.de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin, same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://haveibeenpwned.com; child-src 'self' https://*.duosecurity.com https://*.duofederal.com; frame-src 'self' https://*.duosecurity.com https://*.duofederal.com; connect-src 'self' wss://pwbox.de https://api.pwnedpasswords.com https://api.2fa.directory; object-src 'self' blob:;
strict-transport-security
max-age=31536000; includeSubdomains; preload

Links to (1)

Linked from (1)