fshep-ursberg.de

.de crawl

First seen 2026-04-22 · Last seen 2026-05-16 · ok HTTP/1.1 200 1427 ms crawled 2026-05-16

DE · 159.69.188.178 · AS24940 Hetzner Online GmbH

Reputation 94/100 dmarc monitor-only

sector health type homepage

HTML metadata

Title
Fachschule für Heilerziehungspflege
Language
de
Generator
TYPO3 CMS
Canonical
https://fshep-ursberg.de/

Technology

Server
Apache
Analytics
  • Google Tag Manager
Cookie consent
  • Usercentrics

Third-party hosts loaded (5)

  • cdn.eye-able.com×2
  • www.googletagmanager.com×2
  • access.eye-able.com×1
  • app.usercentrics.eu×1
  • privacy-proxy.usercentrics.eu×1

Social

Registration

Updated
2018-08-17
Name servers
  • ns1025.ui-dns.biz.
  • ns1025.ui-dns.com.
  • ns1025.ui-dns.de.
  • ns1025.ui-dns.org.

DNS records live

NS
  • ns1025.ui-dns.biz
  • ns1025.ui-dns.com
  • ns1025.ui-dns.de
  • ns1025.ui-dns.org
MX
  • 10 mx00.ionos.de
  • 10 mx01.ionos.de

Email authentication partial

SPF
v=spf1 include:_spf-eu.ionos.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-05-01 to 2026-07-30
Expires in 72 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://fshep-ursberg.de/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.usercentrics.eu *.googletagmanager.com *.eye-able.com *.flocklr.com *.flockler.com *.flockler.app *.youtube-nocookie.com *.youtube.com *.googleapis.com *.vhs-connect.de; worker-src blob:; img-src 'self' data: *.usercentrics.eu *.flocklr.com *.flockler.com *.googletagmanager.com *.eye-able.com *.google.de *.cdninstagram.com *.fbcdn.net *.gstatic.com *.googleapis.com *.ytimg.com hcm.drw.de *.vhs-connect.de; style-src 'self' 'unsafe-inline'; font-src 'self' data: *.gstatic.com; media-src 'self'; object-src 'self'; connect-src 'self' *.usercentrics.eu *.analytics.google.com *.flocklr.com *.flockler.com *.eye-able.com *.flockler.app *.google-analytics.com *.googleapis.com *.g.doubleclick.net *.doubleclick.net login.microsoftonline.com; style-src-elem 'self' 'unsafe-inline' *.googleapis.com *.eye-able.com *.vhs-connect.de; frame-ancestors 'self' drw.meine-vhs.de ; frame-src 'self' *.youtube-nocookie.com
strict-transport-security
max-age=63072000; includeSubdomains;

Links to (6)

Linked from (2)