heimbs.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-08 · ok HTTP/1.1 200 1312 ms crawled 2026-05-08

DE · 195.201.215.123 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Heimbs - Kaffee Manufaktur
Description
Manufaktur seit 1880. Traditionsreiches Kaffeehandwerk. Zusammenspiel aus Zeit, Erfahrung und Fingerspitzengefühl. Handverlesene Kaffees.
Language
de
Canonical
https://www.heimbs.com/

Open Graph

url
https://www.heimbs.com/
title
HEIMBS - Kaffee Manufaktur - Kaffeekultur in Vollendung
description
Manufaktur seit 1880. Traditionsreiches Kaffeehandwerk. Zusammenspiel aus Zeit, Erfahrung und Fingerspitzengefühl. Handverlesene Kaffees.

Technology

Server
Apache
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
RegistryGate GmbH
Created
2001-08-16
Expires
2026-08-16 89 days left
Updated
2025-11-24
Name servers
  • ns0.de.clara.net
  • ns1.de.clara.net

DNS records live

NS
  • ns0.de.clara.net
  • ns1.de.clara.net
MX
  • 10 mail.heimbs.com

Email authentication weak

SPF
v=spf1 ip4:195.201.215.123 ip6:2a01:4f8:d0a:676d::2 a:prelay01.mgt.dallmayr.de include:spf.hornetsecurity.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Encryption Everywhere DV TLS CA - G2
from 2025-09-07 to 2026-09-07
Expires in 111 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.heimbs.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(*),payment=()
x-content-type-options
nosniff
content-security-policy
default-src https: data: blob: 'self' assets.adobedtm.com cdn.cookielaw.org www.youtube-nocookie.com; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src https: data: 'self' 'unsafe-inline'
strict-transport-security
max-age=31536000; includeSubDomains

Links to (7)

Linked from (1)