sva.de
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn.consentmanager.net×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Updated
- 2022-11-03
- Name servers
-
- ns1-any.123ns.eu.
- ns3-any.123ns.eu.
- ns4-any.123ns.de.
DNS records live
- NS
-
- ns1-any.123ns.eu
- ns3-any.123ns.eu
- ns4-any.123ns.de
- MX
-
- 10 mx01.sva.de
- 20 mx02.sva.de
- TXT
-
Show 20 TXT records
_f54lyo2af80yoey0xwnyarnzkustfcpsva.de status-page-domain-verification=t8tfgggls75fatlassian-sending-domain-verification=4d5e9fcf-bbec-4596-a111-94aa587ce0b5/OVGTMH1SJFTAKLxh5MYSt4b2IuPkUHxVgrHVeMkwUNnUtczhis8nqR1PIfgqDqLur4svKG5QMce9lmhYwoRYw==6b5eea75d7d285438edcf7c8d3d4e3cbb83f54577ceaea23bfca0eefd6ede6e1_fma9x1tltdeu1lk7hos1n1k122blskdmiro-verification=af07edf249d8a2c942fa54f55e766b72685fa8c7D-TRUST=CFMLV8F2NPNM3D6M9J7AA4J_ius13dok9dbvaq2au3y3qwdcw9l620i_vsz0yx1jwq8yze7a9lpnom2io8l5r25vpwHQ05D6bMAemTcpHroUniCr1Hu7Mi0LkWuLlFXBxIDITsSd8/1N+E8Bb2aEVTa+qN6LuBCdvQQ5lxvQpnfdA==atlassian-domain-verification=mNpB0cXfaHkyUfAHAtDeDn/Xseb4KqhizcmNwgjajaGL9URR3YbeAfBgq312zDobapple-domain-verification=NsYtQgM5x9CxX3rJgoogle-site-verification=3cBEcXWjhj1rqVQBN5j85BoCSXRTuki099Ldt7OZ6gkswisssign-check=dY8tLwNL-v_3GtFl_eBDbFO726Qteamviewer-sso-verification=eb5383feae4e4aefb3de2784c730042bv=spf1 mx ip4:23.21.109.197 ip4:23.21.109.212 ip4:147.160.167.0/26 include:_spf.senders.scnem.com include:spf.protection.outlook.com ~allSendinblue-code:6ef1bdca0140128a0b0cdffd769c529fintersight=d5cc6e61396e5857f6832a8d7f7d67e4c070537443591012f5ece941ac8dbe3a+OjCe7KMjHODsqwnbSy7EPcACS80UMnLqkdfiZWR4PDWdGHPdGf6vm5E2IAixAUJV+rDeXkH26q9raaU2Ztn9Q==
Certificate (current)
D-TRUST BR CA 1-20-2 2020
Expires in 156 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: googleads.g.doubleclick.net *.googlesyndication.com *.googleadservices.com *.googletagmanager.com *.google.com google.com *.google.de google.de *.youtube.com youtu.be *.spotify.com *.scdn.co *.spotifycdn.com *.sva.de *.consentmanager.net 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:;- strict-transport-security
max-age=31536000; includeSubDomains