therakey.de
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- OneTrust
Third-party hosts loaded (1)
- cdn.cookielaw.org×2
Contact
- Phone
Registration
- Updated
- 2026-02-03
- Name servers
-
- ns1-any.123ns.eu.
- ns3-any.123ns.eu.
- ns4-any.123ns.de.
DNS records live
- NS
-
- ns1-any.123ns.eu
- ns3-any.123ns.eu
- ns4-any.123ns.de
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 alt3.aspmx.l.google.com
- 30 alt4.aspmx.l.google.com
- TXT
-
swisssign-check=0qGR4fbYpH-2T45JXLtX36iGp5sswisssign-check=ViCF4017O0Epc6EBfdPKd8NP4xU
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:_spf.berlin-chemie.de include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
SwissSign RSA TLS DV ICA 2022 - 1
Expires in 288 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
deny, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
connect-src 'self' https://video.therakey.de https://cdn.cookielaw.org https://privacyportal-de.onetrust.com https://berlinchemielive01.wt-eu02.net https://cookies-data.onetrust.io/bannersdk/v1/domaingroupcheck https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://berlinchemietest01.wt-eu02.net; default-src 'self'; font-src 'self' https://fonts.gstatic.com; media-src 'self' https://video.therakey.de; img-src 'self' data: https://berlinchemietest01.wt-eu02.net https://cdn.cookielaw.org https://berlinchemielive01.wt-eu02.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://geolocation.onetrust.com https://berlinchemietest01.wt-eu02.net https://responder.wt-safetag.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload