coebad.de

.de crawl

First seen 2026-05-05 · Last seen 2026-05-18 · ok HTTP/1.1 200 7038 ms crawled 2026-05-12

DE · 92.205.173.217 · AS21499 Host Europe GmbH

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Coebad Coesfeld: Erlebnisbad und Sauna für die ganze Familie
Description
Entdecken Sie das Coebad Coesfeld – Ihr Erlebnisbad mit Rutsche, Freibad und entspannender Saunawelt. Hier mehr erfahren!
Language
de
Generator
TYPO3 CMS
Canonical
https://www.coebad.de/

Technology

Server
Apache
CMS
Gatsby
Social widgets
  • YouTube Embed

Third-party hosts loaded (1)

  • www.youtube-nocookie.com×1

Social

Contact

Email
Phone

Registration

Updated
2014-10-28
Name servers
  • ns1.p1.omc.net.
  • ns3.p1.omcnet.de.
  • ns4.p1.omc.info.

DNS records live

NS
  • ns1.p1.omc.net
  • ns3.p1.omcnet.de
  • ns4.p1.omc.info
MX
  • 10 mail.stadtwerke-coesfeld.de
  • 20 mail1.stadtwerke-coesfeld.de
TXT
  • hlXyphHgB4dzGWM48CDKdvH7vCk6Paa29eoAgDuralLk/id5Ek2rUTlOQma7xFvVgzUGDLkHPTebNydJyOtSGw==
  • roml6b4uj0do5ua8r5utbl1f4g
  • naturbbmrt5u6l0racfbjq1kfg
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:secureserver.net mx a:relay.omc-mail.de ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:mailcheck@stadtwerke-coesfeld.de; ruf=mailto:mailcheck@stadtwerke-coesfeld.de; adkim=r; aspf=r
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

Starfield Secure Certificate Authority - G2
from 2025-11-04 to 2026-11-29
Expires in 192 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.coebad.de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src *; script-src * 'unsafe-eval' 'unsafe-inline' blob:; style-src 'self' 'unsafe-inline' *.googletagmanager.com *.googleapis.com; img-src 'self' *.linkedin.com *.google.de *.google.com *.googletagmanager.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com data:; font-src 'self' *.gstatic.com data:
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (6)

Linked from (2)