trox.dk

.dk crawl

First seen 2026-05-15 · Last seen 2026-05-20 · ok HTTP/1.1 200 1006 ms crawled 2026-05-20

IE · 63.35.243.168 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
dk | TROX Denmark A/S
Language
dk
Generator
Scrivito by JustRelate Group GmbH (scrivito.com)
Canonical
https://www.trox.dk/

Open Graph

url
/
title
dk

Technology

Server
nginx
jQuery
3.5.1

Third-party hosts loaded (3)

  • cdn.trox.de×9
  • www.recaptcha.net×6
  • ratinglogo.bisnode.com×1

Social

Contact

Phone

DNS records live

NS
  • ns-1281.awsdns-32.org
  • ns-1924.awsdns-48.co.uk
  • ns-23.awsdns-02.com
  • ns-644.awsdns-16.net
MX
  • 10 de-smtp-inbound-1.mimecast.com
  • 20 de-smtp-inbound-2.mimecast.com
TXT
  • HfFxajyl0ZU5twIMO/iYLVgg0pW/g5qclwm/xD1wOCESlAwiliSOS0W9aL4UEe4rBH1ld6ny9gYcS+4tGU7rJA==
Verified for
  • Google
  • Microsoft 365

Email authentication weak

SPF
v=spf1 include:troxgroup.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Amazon RSA 2048 M01
from 2026-03-11 to 2026-09-25
Expires in 128 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.trox.dk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; font-src 'self' data: https://fast.fonts.net https://cdn.fonts.net; img-src 'self' data: https://cdn.trox.de https://preview-cdn.scrvt.com https://camos5.trox.de https://xcube-app.troxgroup.com https://xcube-appdev.troxgroup.com https://xfans-app.troxgroup.com https://www.google.de https://maps.gstatic.com https://maps.googleapis.com https://ratinglogo.bisnode.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://bid.g.doubleclick.net https://scrivito-public-cdn.s3.eu-west-1.amazonaws.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.recaptcha.net https://trox.containers.piwik.pro https://www.gstatic.com https://extend.vimeocdn.com https://camos5.trox.de https://xcube-app.troxgroup.com https://xcube-appdev.troxgroup.com https://xfans-app.troxgroup.com https://www.vimeo.com https://vimeo.com https://widget.intercom.io https:
strict-transport-security
max-age=31536000; includeSubDomains

Links to (4)

Linked from (1)