tradegatebsx.com
HTML metadata
Registration
- Registrar
- Mesh Digital Limited
- Created
- 2025-09-01
- Expires
- 2026-09-01 103 days left
- Updated
- 2025-12-19
- Name servers
-
- ns01.wesystems.cloud
- ns02.wesystems.cloud
DNS records live
- NS
-
- ns01.wesystems.cloud
- ns02.wesystems.cloud
- MX
-
- 10 mx2.tradegate.de
- 5 mx1.tradegate.de
Email authentication strong
- SPF
-
v=spf1 mx ip4:62.96.239.30 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:postmaster@tradegatebsx.com; ruf=mailto:postmaster@tradegatebsx.com; fo=0; adkim=r; aspf=rpolicy: quarantine - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDEivug+aztjlrKd5eIqhEd4bYETFxrTs/bD27zZ/Hts4vNIgArwnVZsp64P0G1JYLwm53GaTiIoSg8jwS5us…
selectors probed - default:
Certificate (current)
Starfield Secure Certificate Authority - G2
Expires in 199 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
ALLOW-FROM https://www.effektenbank.de- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(self), clipboard-write=(self), gamepad=(), speaker-selection=(), conversion-measurement=(), focus-without-user-activation=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), sync-script=(), trust-token-redemption=(), unload=(), window-placement=(), vertical-scroll=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' ajax.googleapis.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval'; font-src 'self'; connect-src 'self';media-src 'self'; frame-src www.effektenbank.de irpages2.equitystory.com www.tradegate.ag; base-uri 'self'; object-src 'self';- strict-transport-security
max-age=31536000; includeSubDomains; preload;
Links to (2)
- apple.com×2
- google.com×2