bfu-web.de

.de crawl

First seen 2026-06-02 · Last seen 2026-06-02 · ok HTTP/1.1 200 1338 ms crawled 2026-06-02

DE · 141.38.3.30 · AS41289 Deutscher Wetterdienst

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Bundesstelle für Flugunfalluntersuchung - Homepage
Description
Homepage des deutschsprachigen Auftritts
Language
de
Generator
Government Site Builder
Canonical
https://www.bfu-web.de/DE/Home/home_node.html

Technology

Server
Apache

Contact

Email

Registration

Updated
2017-06-19
Name servers
  • dns-3.dfn.de.
  • dnsisp1.dwd.de.
  • dnsisp2.dwd.de.

DNS records live

NS
  • dns-3.dfn.de
  • dnsisp1.dwd.de
  • dnsisp2.dwd.de
MX
  • 10 ofcsgbbm.gbbmvi-wan.de
  • 20 zbcsgbbm.gbbmvi-wan.de
Verified for
  • Cisco

Email authentication partial

SPF
v=spf1 mx ip4:141.38.3.247 ip4:141.38.3.248 ip4:141.38.12.84 ip4:141.38.12.85 ip4:141.38.3.230 ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:reports@report.ofcsgbbm.gbbmdv.bund.de
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

Sectigo Public Server Authentication CA OV R36
from 2025-07-10 to 2026-07-11
Expires in 38 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.bfu-web.de/DE/Home/home_node.html

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' www.bfu-web.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.service.res.bund.de www.bfu-web.de; style-src 'self' 'unsafe-inline'; img-src 'self' data:; child-src 'self' https://www.google.com; frame-src 'self' https://www.google.com;
strict-transport-security
max-age=31536000

Links to (9)

Linked from (1)