healinghotelsoftheworld.com

.com crawl

First seen 2026-04-22 · Last seen 2026-05-20 · ok HTTP/1.1 200 3513 ms crawled 2026-05-16

DE · 176.28.34.6 · AS34011 Host Europe GmbH

Reputation 100/100

Classifying

HTML metadata

Title
Healing Hotels of the World – Where Your Healing Journey Begins
Description
Experience holistic wellbeing at our Healing Hotels. Rely on expert health programs to support you on your healing journey.
Language
en-US
Generator
WPML ver:4.8.6 stt:1,3;
Canonical
https://healinghotelsoftheworld.com/

Open Graph

url
https://healinghotelsoftheworld.com/
title
Front Page
locale
en_US
site name
Healing Hotels of the World
description
Experience holistic wellbeing at our Healing Hotels. Rely on expert health programs to support you on your healing journey.

Technology

Server
Apache
CMS
WordPress
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cdnjs.cloudflare.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone
Address
Healing Hotels of the World GmbH50858 KölnGERMANY

Registration

Registrar
Mesh Digital Limited
Created
2005-07-21
Expires
2026-07-21 61 days left
Updated
2025-07-20
Name servers
  • ns57.domaincontrol.com
  • ns58.domaincontrol.com

DNS records live

NS
  • ns57.domaincontrol.com
  • ns58.domaincontrol.com
MX
  • 1 smtp.google.com
TXT
  • D8815134
  • bju28ei4ohakg22ehlupthfi0r
Verified for
  • Google

Email authentication strong

SPF
v=spf1 a mx include:spf.server-he.de -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Starfield Secure Certificate Authority - G2
from 2025-11-17 to 2026-12-17
Expires in 210 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://healinghotelsoftheworld.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), microphone=(), fullscreen=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' https: www.googletagmanager.com www.google-analytics.com js-eu1.hs-scripts.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: fonts.googleapis.com 'unsafe-inline'; img-src 'self' https: data: blob: i0.wp.com i1.wp.com i2.wp.com www.google-analytics.com; font-src 'self' https: data: fonts.gstatic.com; connect-src 'self' https: www.google-analytics.com region1.google-analytics.com js-eu1.hs-scripts.com; frame-src 'self' https: www.youtube.com player.vimeo.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests;
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin
cross-origin-embedder-policy
credentialless
cross-origin-resource-policy
same-origin

Links to (8)

Linked from (3)