rafi-group.com
HTML metadata
Technology
- Server
- Apache
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (4)
- cdn.consentmanager.net×1
- code.etracker.com×1
- www.youtube-nocookie.com×1
- www.youtube.com×1
Social
Contact
- Phone
Registration
- Registrar
- Key-Systems GmbH
- Created
- 2005-04-02
- Expires
- 2027-04-02 317 days left
- Updated
- 2026-04-03
- Name servers
-
- ns1.domaindiscount24.net
- ns2.domaindiscount24.net
- ns3.domaindiscount24.net
DNS records live
- NS
-
- ns1.domaindiscount24.net
- ns2.domaindiscount24.net
- ns3.domaindiscount24.net
- MX
-
- 10 mx-in01.eu.retarus.com
- 10 mx-in02.eu.retarus.com
- TXT
-
Show 10 TXT records
apple-domain-verification=hgW6h08sInC9Oyqxbw=5PnyWgC7Hmn9IOfRPKOgGcYTDJ135mmxaRv0Z2JHkwwumindmanager-verification=d7bf868887161884a7d5f05c26e5d257c4b7a64772406b70837390dc24d735d7NK2cYRSt0nZvNMt0apOgrcB1x26Mv0GLY8gc66qNGyJUT1QfGtEBtBOO1axrDmzk9imL+caoooOy2cauyWwxFA==ZA=Toqv1NgFrFsxu92teIXOlw==google-site-verification=6aDvRfvhYpqh5JVk3t3cEgA2c0Z2x0RdykFX3JPoKs8atlassian-domain-verification=l1wttc/nlEry4r5okAJEo92R8NG1nrCXz9RYva54/CIBPFCFVTU5tphCuUMJLaMoautodesk-domain-verification=KP052kp-2xzCrSyeq6zedocusign=57d3dc47-b72e-459a-bf44-af2373bc41cfgoogle-site-verification=y0GVJQxtIPScQ04U_oJ0k8m0MBRrHjxOoc-P2hAr5mQ
Email authentication strong
- SPF
-
v=spf1 ip4:192.81.121.100 include:spf-mail.rafi.de include:spf.crsend.com include:spf-meltwater.rafi.de include:spf.imc-hosting.com include:agenturserver.de include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc@rafi-group.com;aspf=r;fo=1;adkim=r;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 119 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' fonts.gstatic.com; base-uri 'self'; img-src 'self' data: fast.fonts.net *.leadfeeder.com *.lfeeder.com *.consentmanager.net *.etracker.de *.etracker.com *.leadlab.click assets.schiertz-laemmer.de *.google-analytics.com www.google.com www.google.de maps.gstatic.com maps.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.leadfeeder.com *.lfeeder.com www.youtube.com www.youtube-nocookie.com maps.google.com maps.googleapis.com www.google-analytics.com www.googletagmanager.com fast.fonts.net *.consentmanager.net *.etracker.de *.etracker.com *.leadlab.click *.schiertz-laemmer.de; worker-src 'self' blob:; connect-src 'self' *.leadfeeder.com *.lfeeder.com stats.g.doubleclick.net maps.googleapis.com fast.fonts.net *.consentmanager.net *.etracker.de *.etracker.com *.leadlab.click *.google-analytics.com; style-src 'self' 'unsafe-inline' data: *.leadfeeder.com *.lfeeder.com fast.fonts.net *.consentmanager.net *.etracker.de *.etracker.com *.leadlab.click fonts.go- strict-transport-security
max-age=31536000; includeSubDomains; preload