thomann.de
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (20)
- fast-images.static-thomann.de×142
- thumbs.static-thomann.de×24
- images.static-thomann.de×2
- www.thomannmusic.com×2
- www.googletagmanager.com×1
- www.thomann.ae×1
- www.thomann.at×1
- www.thomann.co.uk×1
- www.thomann.dk×1
- www.thomann.es×1
- www.thomann.fr×1
- www.thomann.it×1
- www.thomann.nl×1
- www.thomann.pl×1
- www.thomann.pt×1
- www.thomann.ro×1
- www.thomann.se×1
- www.thomannmusic.ch×1
- www.thomannmusic.hu×1
- www.thomannmusic.no×1
Social
Registration
- Updated
- 2023-09-15
- Name servers
-
- dns1.netzmarkt.de.
- dns2.netzmarkt.de.
DNS records live
- NS
-
- dns1.netzmarkt.de
- dns2.netzmarkt.de
- MX
-
- 10 mail1.thomann.de
- 10 mail2.thomann.de
- TXT
-
MS=ms40254401google-site-verification=8bjpdTzcd_Orxv952NYYu6n4LqviSzJnKyExh42hKGYgoogle-site-verification=rf1HS0eTw9KO9GRlKV1sYp7u7iE5wrZUu40lJiK9uew
Email authentication partial
- SPF
-
v=spf1 ip4:217.6.235.184/29 ip4:193.158.3.160/28 ip4:212.184.107.64/26 ip4:212.204.75.0/24 ip4:85.10.233.0/24 ip4:212.204.112.192/26 ip4:212.114.206.81 ip4:167.89.26.162 ip4:54.229.2.165 ip4:52.30.130.201 include:spf.protection.outlook.com a mx -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;aspf=r;adkim=r;policy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnYeeJFRJmM2x6nnewymzDs+qABn+w19LAGduj4Q+xes8XgC8cllfw1u6pL80w+ucCKxgU9uE91VSpv… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxL1nRfNbi5ScEZg7sKFTSfklfmzp0Hco0TpZs1VjiBx/qF7Cu+3um7UePJk+r4thvwxvQzFjrT24U8jvSp… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwV/tjs5rcBXeHfWU2cSm1KXMkCNPtri24fGxgZChMY4FgsC0Gc6aEUcuKgsAEC+NvHnWSNlgRtfi8W4tnQ…
selectors probed - dkim:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 121 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-inline' *.thomann.de app.storyblok.com connect.facebook.net analytics.tiktok.com *.adform.net www.google-analytics.com sc-static.net s.pinimg.com www.youtube.com challenges.cloudflare.com *.payments-amazon.com www.googleadservices.com userlike-cdn-umm.b-cdn.net bat.bing.com www.googletagmanager.com www.googletagservices.com tr.snapchat.com ct.pinterest.com js.appboycdn.com *.g.doubleclick.net widgets.trustedshops.com tpc.googlesyndication.com *.clarity.ms cdn.avo.app maps.googleapis.com pagead2.googlesyndication.com ep2.adtrafficquality.google www.paypal.com; frame-src 'self' *.thomann.de *.g.doubleclick.net *.safeframe.googlesyndication.com challenges.cloudflare.com ct.pinterest.com td.doubleclick.net tpc.googlesyndication.com tr.snapchat.com www.facebook.com www.google.com www.youtube-nocookie.com www.googletagmanager.com ep2.adtrafficquality.google www.paypal.com; frame-ancestors 'self' app.storyblok.com; object-src 'none'
Links to (7)
- apple.com×2
- facebook.com×2
- google.com×2
- instagram.com×2
- pinterest.com×2
- tiktok.com×2
- youtube.com×2
Linked from (32)
- wuerzmischung.de×2
- dasaweb.de×2
- ausbildungsmesse-bamberg.de×2
- top-webradio-liste.de×2
- goetzmd.de×2
- grupoditram.com×2
- technische-aufklaerung.de×2
- takustik.com×2
- spreeblick.com×2
- fairsein.org×2
- ocarina.de×2
- sonicscoop.com×2
- oktoberfestband.com×2
- capital-p.de×2
- einsteiger-keyboard.de×2
- sph-music-masters.de×2
- backstagepro.de×2
- thomann.io×1
- peter-tribute.de×1
- pocketscion.com×1
- delicious-audio.com×1
- paddyhats.com×1
- ronaldkah.de×1
- feinarbyte.de×1
- beamerlasershow.com×1
- brasswiesn.de×1
- touellskouarn.fr×1
- glp.de×1
- webradiovoting.de×1
- beamerlasershow.de×1
- webdesign-schweinfurt.de×1
- netzgemuese.com×1