tailwind-ahead.com
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- schwarz-cms.object.storage.eu01.onstackit.cloud×7
- cdn.cookielaw.org×1
Social
Registration
- Registrar
- Key-Systems GmbH
- Created
- 2026-01-09
- Expires
- 2027-01-09 235 days left
- Updated
- 2026-01-09
- Name servers
-
- ns.do-ex.com
- ns.do-ex.net
- ns.do-ex.org
DNS records live
- NS
-
- ns.do-ex.com
- ns.do-ex.net
- ns.do-ex.org
- TXT
-
v=spf1 -allgoogle-site-verification=l7Z-IyEvtTmOmLwowJyb8HblG_kygZKnMPNqdE5nA74
Certificate (current)
E7
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' www.youtube.com analytics.google.com *.google-analytics.com *.googletagmanager.com tagmanager.google.com cdn.cookielaw.org www.google.com www.gstatic.com optimize.google.com *.analytics.google.com *.licdn.com licdn.com *.linkedin.com linkedin.com; img-src 'self' data: static.tws.staging-server.com *.tailwind.cluster.db-n.com *.object.storage.eu01.onstackit.cloud maps.googleapis.com *.google-analytics.com *.google.de *.doubleclick.net cdn.cookielaw.org *.gstatic.com *.google.de *.google.com www.googletagmanager.com *.licdn.com licdn.com *.linkedin.com linkedin.com; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self' https: 'unsafe-inline' www.youtube-nocookie.com; connect-src 'self' *.google.de *.google.com *.google-analytics.com maps.googleapis.com stats.g.doubleclick.net cdn.cookielaw.org *.onetrust.com *.analytics.google.com *.test.schwarz.web.schwarz *.licdn.com licdn.com *.linkedin.com linkedin.com; frame-a- strict-transport-security
max-age=31536000 ; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
credentialless- cross-origin-resource-policy
same-origin