hsk.de

.de crawl

First seen 2026-04-22 · Last seen 2026-05-17 · ok HTTP/1.1 200 1393 ms crawled 2026-05-15

DE · 89.31.143.90 · AS202108 united-domains GmbH

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
HSK | HSK Duschkabinenbau KG
Language
en
Canonical
https:///www.hsk.de/en/home
Translations
  • de
  • en
  • fr
  • nl

Open Graph

url
https:///www.hsk.de/en/home
title
HSK | HSK Duschkabinenbau KG
site name
HSK

Technology

Server
Google
CMS
Gatsby

Third-party hosts loaded (1)

  • lh3.googleusercontent.com×17

Social

Contact

Email
Phone

Registration

Updated
2015-07-26
Name servers
  • ns.udag.de.
  • ns.udag.net.
  • ns.udag.org.

DNS records live

NS
  • ns.udag.de
  • ns.udag.net
  • ns.udag.org
MX
  • 10 d326708.a.ess.de.barracudanetworks.com
  • 20 d326708.b.ess.de.barracudanetworks.com
TXT
Show 4 TXT records
  • google-site-verification=WgyxSGHZgmDre9SCBK8poDtd2qDzDotgmHpFRhY9B_Q
  • google-site-verification=hJDgTjlic0slkgTpUzfI3Vj4ztFUrFafPwoI7lysmSc
  • google-site-verification=X_KIJsslgHyVxsaGVF5SP4wrbLcw3FWkY80uyhWUXWA
  • apple-domain-verification=1f1gAGjU7PWUSsax

Email authentication partial

SPF
v=spf1 mx a:mail.schulte.de a:mail2.schulte.de a:server-hsk.de ip4:195.243.90.74/29 ip4:62.225.151.101/29 include:spf.ess.de.barracudanetworks.com include:spf.mailjet.com -all
strict (-all)
DMARC
v=DMARC1; p=none; ruf=mailto:it-operation@schulte.de; rua=mailto:it-operation@schulte.de;
policy: none (monitoring only)
DKIM
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificates

Loading certificate

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.hsk.de/en

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
Header values
referrer-policy
strict-origin
permissions-policy
autoplay=(self), camera=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(), geolocation=(), microphone=(), publickey-credentials-get=(), usb=()
x-content-type-options
nosniff
content-security-policy
style-src 'self' https://accounts.google.com/gsi/style accounts.google.com 'unsafe-inline'; default-src 'self'; img-src 'self' storage.googleapis.com *.googleusercontent.com data: 'unsafe-inline' https://www.hsk.de hsk-viur3-live.appspot.com userlike-cdn-operators.userlike.com userlike-store-media-files.s3.amazonaws.com www.userlike.com; script-src 'self' https://accounts.google.com/gsi/client 'unsafe-inline' www.google-analytics.com api.userlike.com accounts.google.com d3dc1lgancj6l0.cloudfront.net userlike-cdn-umm.b-cdn.net stats.hsk.de 'unsafe-eval'; frame-src 'self' www.google.com drive.google.com accounts.google.com www.youtube-nocookie.com www.youtube.com api.userlike.com my.matterport.com www.heinze.de datanorm.hsk.de userlike-cdn-widgets.s3-eu-west-1.amazonaws.com; form-action 'self'; connect-src 'self' accounts.google.com api.userlike.com umd.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com wss://umd.userlike.com data:; upgrade-insecure-requests; object-src 'none';
strict-transport-security
max-age=2678400
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-site

Links to (7)

Linked from (2)