geschichtsboden.de

.de crawl

First seen 2026-05-08 · Last seen 2026-05-15 · ok HTTP/1.1 200 4978 ms crawled 2026-05-15

DE · 45.139.158.148 · AS29014 ScaleUp Technologies GmbH & Co. KG

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Der Neue Geschichtsboden - Heimatmuseum und mehr
Description
Im Neuen Geschichtsboden gibt es neben Dauer- und Sonderausstellungen auch Führungen und Events rund um Kultur und Kunst. Mehr erfahren.
Language
de
Generator
WordPress 6.9.4
Canonical
https://www.geschichtsboden.de/
Feeds

Open Graph

url
https://www.geschichtsboden.de/
title
Der Neue Geschichtsboden - Heimatmuseum und mehr
locale
de_DE
site name
Geschichtsboden
description
Im Neuen Geschichtsboden gibt es neben Dauer- und Sonderausstellungen auch Führungen und Events rund um Kultur und Kunst. Mehr erfahren.
updated time
2026-02-02T10:46:55+01:00

Technology

Server
nginx
CMS
WordPress

Social

Registration

Updated
2020-05-27
Name servers
  • dns.dns1.de.
  • dns.dns2.de.
  • dns.dns3.de.
  • dns.dns4.de.

DNS records live

NS
  • dns.dns1.de
  • dns.dns2.de
  • dns.dns3.de
  • dns.dns4.de
MX
  • 0 mail.leipfinger-bader.de
TXT
  • google-site-verification=nUh56pA_FxO3PWTLMavQfjhjXtKGfukV5CK6EogYLqg

Email authentication weak

SPF
v=spf1 mx ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-08 to 2026-07-07
Expires in 49 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.geschichtsboden.de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
sameorigin
permissions-policy
geolocation=(), midi=(), camera=(), usb=(), magnetometer=(), accelerometer=(), gyroscope=(), microphone=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.google-analytics.com *.googletagmanager.com *.facebook.net *.cloudflare.com *.jsdelivr.net *.datatables.net leanbe.ai *.announcekit.app *.helpscout.net *.youtube.com *.vimeo.com *.googleapis.com *.hsforms.com *.hsadspixel.net *.hs-analytics.net *.hscollectedforms.net *.hsforms.net *.hs-scripts.com *.hs-banner.com https://unpkg.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.cloudflare.com leanbe.ai *.fonts.net *.myfonts.net *.datatables.net; img-src 'self' data: *.hubspotusercontent40.net *.facebook.com *.hsforms.net leanbe.ai *.w.org *.vimeocdn.com *.borlabs.io *.google-analytics.com *.ytimg.com *.hubspot.com *.gravatar.com *.google.de *.google.com *.hsforms.com; font-src 'self' data: *.gstatic.com; connect-src 'self' *.hubspot.com *.hubapi.com *.hsforms.com *.google-analytics.com *.cloudfront.net leanbe.ai *.hscollectedforms.net; media-src 'self'; object-src 'none'; frame-src 'self' *.hsforms
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)