rheinenergie.com
HTML metadata
Technology
- CMS
- Nuxt
Third-party hosts loaded (2)
- rheinenergieprod-media.e-spirit.cloud×30
- widget.trustpilot.com×1
Social
Registration
- Registrar
- RegistryGate GmbH
- Created
- 2001-01-08
- Expires
- 2027-01-08 232 days left
- Updated
- 2026-01-09
- Name servers
-
- ns1.rheinenergie.com
- ns3.rheinenergie.com
DNS records live
- NS
-
- ns1.rheinenergie.com
- ns3.rheinenergie.com
- MX
-
- 10 smtpp-11.rheinenergie.com
- 10 smtpp-21.rheinenergie.com
- TXT
-
Show 9 TXT records
wiz-domain-verification=fcd0c71c3ca5bcd896e0bddf9d8e75a552aed49dbd8e9ebb2ea99f90558ed3cemindmanager-verification=a764f2ce24df741df79eb20ca0c81a9b81f48a0494050146c0f6569ecf26749aZM45P5DR/QkqtsiuSqQ2jobrmOwmAMGcSz3/bh4bKs/eHX2SnR55EKH00JFfP+cxKzUtiHobPmZRKQIksCku+A==MYsHoaqg=6c1746e012883477daa76cf4f55ddbca_telesec-domain-validation=EE7D4466BD5E5CECFD6AB833AA91011399E270A0B444F7859E45B369F1008715_ukldse3ayjbtp9ummfk9INTXTvpce:Fo0FsxfsWTDwDVK11bgMr4pt59ahbk0b6qn71snni8hoquN30CAKRduXQlbXRkOjIlN/xTVvAafDl5m/xLh9Qr6y79j93k1Qy8RLKeOKfK5fRTHAwjUQdNqSebUpPOFzoMFA==8kcn7an277s4m2aq81475mk854
- Verified for
-
- Apple
- Atlassian
- HashiCorp
- Microsoft 365
- Miro
Email authentication partial
- SPF
-
v=spf1 mx ip4:80.82.206.0/26 ip4:185.98.184.0/24 ip4:195.245.65.145 ip4:195.245.65.146 ip4:195.245.64.80 ip4:195.245.64.81 include:spf.protection.outlook.com include:_spf.zimpel.de -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- mail:
v=DKIM1 h=sha256 k=rsa p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9EuKXyPIb2VWX3KvEUmN/gHqHaRBmG8PDo+Q1/zFXQmUDHlPt/RHYQhV244HxNF+fqzEn6L…
selectors probed - mail:
Certificate (current)
Amazon RSA 2048 M04
Expires in 203 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self' *.e-spirit.cloud *.e-spirit.hosting; img-src 'self' data: *.rheinenergie.com *.kununu.com *.e-spirit.cloud *.e-spirit.hosting maps.googleapis.com maps.gstatic.com https://assets.prd.heyflow.com https://vlink-production.obs.eu-de.otc.t-systems.com *.adition.com *.ytimg.com *.doubleclick.net *.google.com *.google.de *.facebook.com *.facebook.net *.bing.com *.bing.net www.googletagmanager.com; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' https: blob: 'unsafe-inline' 'strict-dynamic' 'nonce-u1hwAp9ZiHlJKj7KjPulnemE' 'unsafe-eval'; upgrade-insecure-requests;- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin