rwe-foundation.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1800 ms crawled 2026-05-19

NL · 20.105.216.30 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
RWE Foundation
Description
Mit der RWE Foundation wollen wir mit unserer Energie auch im sozialen Bereich nachhaltig für Veränderungen sorgen, um langfristig etwas in der Gesellschaft zu bewegen.
Language
de-DE
Canonical
https://www.rwe-foundation.com

Open Graph

url
https://www.rwe-foundation.com/
title
RWE Foundation
description
Mit der RWE Foundation wollen wir mit unserer Energie auch im sozialen Bereich nachhaltig für Veränderungen sorgen, um langfristig etwas in der Gesellschaft zu bewegen.

Technology

CDN
Cloudflare
Cookie consent
  • Usercentrics

Third-party hosts loaded (2)

  • app.usercentrics.eu×1
  • code.etracker.com×1

Registration

Registrar
CSC Corporate Domains, Inc.
Created
2023-02-24
Expires
2027-02-24 279 days left
Updated
2026-02-20
Name servers
  • dns01.rwe.com
  • dns02.rwe.de
  • dns03.rwe.net
  • spdns3.cscdns.net

DNS records live

NS
  • dns01.rwe.com
  • dns02.rwe.de
  • dns03.rwe.net
  • spdns3.cscdns.net
MX
  • 10 secmail.rwe.com
Verified for
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 a:secmail.rwe.com a:rwe-com.mail.protection.outlook.com include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
v=DMARC1;p=reject;fo=1;ri=3600;rua=mailto:rwe@rua.agari.com;ruf=mailto:rwe@ruf.agari.com
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

GlobalSign RSA OV SSL CA 2018
from 2026-04-20 to 2026-11-05
Expires in 168 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.rwe-foundation.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: blob: 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: blob: *.rwe.com *.usercentrics.eu img.youtube.com static.ctctcdn.com *.sleeknote.com; font-src 'self' fonts.gstatic.com data: *.sleeknote.com; worker-src blob:; media-src 'self' data: https: ;connect-src 'self' data: https:
strict-transport-security
max-age=31536000; includeSubdomains; preload

Linked from (3)