hyfra.com

.com crawl

First seen 2026-05-04 · Last seen 2026-05-11 · ok HTTP/1.1 200 1611 ms crawled 2026-05-11

DE · 49.12.53.106 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Industriekühler Hersteller ▶️ Wasserkühler für die Industrie
Description
HYFRA ist einer der erfahrensten Anbieter industrieller Prozesskühlung: Kompakte Anlagen, zuverlässiger Service & individuelle Lösungen.
Language
de
Generator
TYPO3 CMS
Canonical
https://www.hyfra.com/de/
Translations
  • de
  • en
  • es
  • fr

Open Graph

image:url
https://www.hyfra.com/fileadmin/_processed_/2/a/csm_hyfra_event-115_32e5e18766.jpg

Technology

Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • consent.page-paper.com×1
  • px.ads.linkedin.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

Registration

Registrar
InterNetX GmbH
Created
2004-11-15
Expires
2026-11-15 179 days left
Updated
2025-11-16
Name servers
  • a.ns14.net
  • b.ns14.net
  • c.ns14.net
  • d.ns14.net

DNS records live

NS
  • a.ns14.net
  • b.ns14.net
  • c.ns14.net
  • d.ns14.net
MX
  • 0 hyfra-com.mail.protection.outlook.com
TXT
Show 12 TXT records
  • google-site-verification=NdxrWHQhUlII0YvH13E-77v3JkTrjuPfQUylns8FHkE
  • b3mpu8n2732hn7s93229571016
  • MS=ms18715559
  • MS=ms96485195
  • atlassian-domain-verification=oEbyaIaEvEos8348/kUInIbtnc9RATg03Ia0YpaIvtmaTbMfUg3HBk3/xGy5d6lO
  • _globalsign-domain-verification=MppSBaVaDY8UFgSz2QSblNZ8mQnk4Wpeir4TuhK60b
  • G0L0E15337
  • D2Bh5ImmtA/JjBKDU2Jp5dUv4q0SlCJOBOJtdHc3LjoxPIy+LcxIPbCw1DdrBZYQEgOTY6xpKUy6sWswU9M13g==
  • 86aa0858f37e0930a63f4261e32eb776.txt
  • MS=ms77286530
  • 73pi5mho3u69kt60081jh195h5
  • m0mI+rUpy8vFyp75aJ6zIMeP9JzDkU/C9BIFrsidRHQTVLHdGQdE7B6q5zk7/UWOr+yk35hZbNTSR/gnNkYkAw==

Email authentication weak

SPF
v=spf1 ip4:178.23.154.90 ip4:12.148.128.219 ip4:205.145.193.7 ip4:195.145.29.132 include:spf.protection.outlook.com include:spf.nl2go.com include:ispgateway.de include:amazonses.com include:spf.messagelabs.com include:spf.mailjet.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArQWN1saWBVfNPYMeihApaEgaqFdOTeRHvjz0O3zdkpE8QkHZJdwIwGzL/i8CuPi926sZh+alTq6YgQ…
selectors probed

Certificate (current)

R12
from 2026-03-29 to 2026-06-27
Expires in 39 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.hyfra.com/de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(self), autoplay=(), camera=(), display-capture=(), encrypted-media=(self), fullscreen=(self https://www.youtube-nocookie.com), geolocation=(), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self https://www.youtube-nocookie.com), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), browsing-topics=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' www.googletagmanager.com snap.licdn.com www.google-analytics.com maps.google.com maps.googleapis.com consent.page-paper.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' consent.page-paper.com; style-src-elem 'self' 'unsafe-inline' consent.page-paper.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' data: px.ads.linkedin.com www.google-analytics.com maps.gstatic.com maps.google.com px4.ads.linkedin.com consent.page-paper.com; font-src 'self'; connect-src 'self' region1.google-analytics.com cdn.linkedin.oribi.io px.ads.linkedin.com maps.googleapis.com www.google-analytics.com consent.page-paper.com; media-src 'self'; object-src 'self'; child-src 'self'; frame-src 'self'; worker-src 'self'; frame-ancestors 'self'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'
strict-transport-security
max-age=15768000; includeSubDomains

Links to (4)

Linked from (3)