gfo-online.de

.de crawl dns

First seen 2026-04-19 · Last seen 2026-05-19 · ok HTTP/1.1 200 9277 ms crawled 2026-05-13

DE · 23.88.92.128 · AS24940 Hetzner Online GmbH

Reputation 100/100

Classifying

HTML metadata

Title
GFO Online: Die GFO - gemeinnützige Gesellschaft der Franziskanerinnen zu Olpe mbH
Description
großer Verbund im Gesundheits- und Sozialwesen, 17.500 Mitarbeitende an 100 Standorten in NRW und dem nördlichen RLP
Language
de
Generator
TYPO3 CMS
Canonical
https://www.gfo-online.de/
Translations
  • de
  • en

Technology

Server
Apache
CMS
Joomla
Cookie consent
  • Cookiebot

Third-party hosts loaded (3)

  • cdn.eye-able.com×2
  • cdnjs.cloudflare.com×1
  • consent.cookiebot.com×1

Social

Contact

Phone
Address
GFO mbH(Gemeinnützige Gesellschaft der Franziskanerinnen zu Olpe mbH)Maria-Theresia-Str. 42a57462 Olpe

Registration

Updated
2021-02-04
Name servers
  • dns11.netcologne.de.
  • dns12.netcologne.de.
  • dns13.netcologne.de.
  • dns14.netcologne.de.

DNS records live

NS
  • dns11.netcologne.de
  • dns12.netcologne.de
  • dns13.netcologne.de
  • dns14.netcologne.de
MX
  • 10 mx0.gfo-online.de
TXT
Show 5 TXT records
  • swisssign-check=Z49HEPNgu-lAm77SUQWfAEs1KzU
  • _d95437rqbmh2585tljbieyzl68wd5ps
  • 10hsuk2mpeobdt5lrala4u9bhk
  • b5ntm2bilk3hb928deu260tgc2
  • si5ga36cek3pmo2v8oi3her79
Verified for
  • Apple
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 mx include:spfhosts.gfo-online.de include:spf-policy.mailrelay-out.netcologne.de -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:fundamental@gfo-its.de; ruf=mailto:fundamental@gfo-its.de; fo=1:d:s; adkim=r; aspf=r
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

R12
from 2026-04-14 to 2026-07-13
Expires in 53 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.gfo-online.de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), microphone=(), geolocation=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'nonce-nPiA89m6aOGivAKx07uO-2ilMICHcPeHr2aRCqsTMcKeooW-ytIaPw' data: https://*.openstreetmap.org 'unsafe-eval' https://consent.cookiebot.com https://consentcdn.cookiebot.com https://*.livechatinc.com https://maps.googleapis.com https://www.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://connect.facebook.net https://www.surfersident.de https://mautic.gfo-online.de https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://code.jquery.com https://netdna.bootstrapcdn.com https://tracking.gfo-online.de https://cdn.eye-able.com https://api.eye-able.com 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' 'sha256-KWTVRBrUA9F8RKcvzEELAljor5PgkhQDbRlUkkI+e74=' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cdn.livecha
strict-transport-security
max-age=31536000; includeSubDomains

Links to (23)

Linked from (20)