vr-payment.de
HTML metadata
Technology
- Server
- Apache
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (1)
- app.usercentrics.eu×1
Social
Contact
Registration
- Updated
- 2023-09-13
- Name servers
-
- ns1.atruvia.de.
- ns2.atruvia.de.
- ns3.atruvia.de.
- ns4.atruvia.de.
DNS records live
- NS
-
- ns1.atruvia.de
- ns2.atruvia.de
- ns3.atruvia.de
- ns4.atruvia.de
- MX
-
- 10 vrpayment-de0e.mail.protection.outlook.com
- TXT
-
Show 9 TXT records
google-site-verification=KygfN6RYi21Qzslct2q3jc24GJKf3jqsk_crL7kzqsoMS=ms60706778pexip-ms-tenant-domain-verification=d1dab791-d294-4dec-97cd-28388e84d027D-TRUST=33UZ28P2L3MPCUJG9E5334Latlassian-domain-verification=cOghwtqgVSaX40Fnl0TQ8G3RA/cTh19jG/k6b8BWXgja9F1s5goaMCajPH91z6cv4753lwgpxmQuoVadis=9ad4a869-44c1-4a89-982e-67c87456e9fc9bfc408ce0d73a4aD-TRUST=QNJIFHAKHFME3DL7M4HDRRJ
Email authentication strong
- SPF
-
v=spf1 ip4:194.149.246.0/23 ip4:195.35.89.0/25 ip4:192.161.144.0/20 ip4:185.12.80.0/22 ip4:96.46.150.192/27 ip4:174.137.46.0/24 ip4:194.50.162.90 ip4:178.16.56.51/32 ip4:153.92.196.167/32 ip4:178.16.56.49/32 ip4:178.16.56.48/32 include:mail.zendesk.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;adkim=r;aspf=r;rua=mailto:dmarc-report@vr-payment.de;ruf=mailto:dmarc-report@vr-payment.depolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA/e1dO7O1jWm/c1lXi8aDV+AUSu/LeS2QdIHCrICLYKGYXDJ8VbZ5S+rleCTNg8PpBJ+8Com9yURme0… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwps807zo89FAez4Yt9ZZffwB3SyvYG5BobQtQ2gSan4muHgRKjinwIbym6IcBGCWcTquBR44E1Pxg8…
selectors probed - selector1:
Certificate (current)
R12
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://www.podcaster.de"), camera=(), encrypted-media=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://www.podcaster.de"), fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://www.podcaster.de"), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https:; frame-ancestors 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin-allow-popups