tfgonlineplus.de

.de crawl

First seen 2026-04-28 · Last seen 2026-05-18 · ok HTTP/1.1 200 860 ms crawled 2026-05-05

DE · 185.111.170.45 · AS204147 Cordes & Graefe KG

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
ONLINE PLUS

Registration

Updated
2025-08-22
Name servers
  • ns5.adacor.net.
  • ns.europe.adacor.net.
  • ns.global.adacor.net.

DNS records live

NS
  • ns.europe.adacor.net
  • ns.global.adacor.net
  • ns5.adacor.net
MX
  • 0 tfgonlineplus-de.mail.protection.outlook.com
TXT
  • v=spf1 mx ip4:185.111.169.10 ip4:185.111.169.12 ip4:185.111.169.29 ip4:185.111.170.23 include:spf.protection.outlook.com -all
Verified for
  • GlobalSign
  • Microsoft 365

Certificate (current)

GlobalSign GCC R3 DV TLS CA 2020
from 2026-02-10 to 2027-03-14
Expires in 298 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://tfgonlineplus.de/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.hotjar.com https://script.hotjar.com https://www.datadoghq-browser-agent.com/ https://maps.google.com/ https://maps.googleapis.com/ https://youtu.be/ https://*.usercentrics.eu/ https://*.omtrdc.net/ https://*.tt.omtrdc.net/ https://*.demdex.net/ https://cm.everesttech.net https://assets.adobedtm.com/ https://wconfigure.com/ https://at.wconfigure.com/ https://widget.itek.de/ https://widget.itek.de/; style-src 'self' 'unsafe-inline' https://static.hotjar.com https://script.hotjar.com https://wconfigure.com/ https://at.wconfigure.com/ https://widget.itek.de/ https://plattform.baudocs.de https://plattform.baudocs.de; img-src 'self' https://static.hotjar.com https://script.hotjar.com https://*.onlineplus.store https://*.grosshaendlernetzwerk.de/ https://ablexprod.blob.core.windows.net/ https://maps.google.com/ https://csi.gstatic.com/ https://maps.gstatic.com/ https://maps.googleapis.com https://i1.ytimg.com/

Linked from (1)