vob-online.de
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (3)
- cdn.jsdelivr.net×2
- code.etracker.com×1
- euc-widget.freshworks.com×1
Social
Registration
- Updated
- 2026-01-09
- Name servers
-
- beghidns003.my-it-solutions.net.
- deffmdns01.bdc-services.net.
- usiadns002.saacon.net.
DNS records live
- NS
-
- beghidns003.my-it-solutions.net
- deffmdns01.bdc-services.net
- usiadns002.saacon.net
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA EV R36
Expires in 147 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(self), display-capture=*, fullscreen=*, geolocation=(self), microphone=(), web-share=*- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.aks-dinmedia.net *.algolia.io *.algolia.net *.algolianet.com *.beuth.de *.bing.com *.dinmedia.de *.etracker.com *.etracker.de *.freshworks.com *.google-analytics.com *.googleadservices.com *.googleoptimize.com *.hotjar.com *.podigee-cdn.net *.soundcloud.com *.youtube.com/iframe_api *.ytimg.com https://*.blickinsbuch.de/gateway/ https://*.googletagmanager.com https://blickinsbuch.de/gateway/ https://cdn.jsdelivr.net/npm/friendly-challenge@0.9.14/widget.module.min.js https://cdnjs.cloudflare.com/ajax/libs/mathjax/ https://code.jquery.com https://googleads.g.doubleclick.net https://public.flourish.studio/resources/embed.js siteimproveanalytics.com; style-src 'self' 'unsafe-inline' *.freshworks.com *.podigee-cdn.net https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.algolia.io *.algolia.net *.algolianet.com *.etracker.de *.freshdesk.com *.freshworks.com *.friendlycaptcha.com *.google.c- strict-transport-security
max-age=31536000 ; includeSubDomains
Links to (3)
- din.de×2
- dinmedia.de×2
- facebook.com×2