iba-hamburg.de

.de crawl

First seen 2026-04-23 · Last seen 2026-05-17 · ok HTTP/1.1 200 15995 ms crawled 2026-05-17

DE · 31.220.121.226 · AS15817 Mittwald CM Service GmbH & Co. KG

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Startseite | IBA Hamburg
Language
en
Canonical
https://www.iba-hamburg.de/en/

Technology

Server
Apache
Cookie consent
  • Cookiebot

Third-party hosts loaded (2)

  • code.etracker.com×1
  • consent.cookiebot.com×1

Social

Contact

Phone
Address
IBA Hamburg GmbHAm Zollhafen 1220539 Hamburg

Registration

Updated
2020-03-10
Name servers
  • ns01.agenturserver.co.
  • ns01.agenturserver.de.
  • ns01.agenturserver.it.

DNS records live

NS
  • ns01.agenturserver.co
  • ns01.agenturserver.de
  • ns01.agenturserver.it
MX
  • 10 mx01.hornetsecurity.com
  • 20 mx02.hornetsecurity.com
  • 30 mx03.hornetsecurity.com
  • 40 mx04.hornetsecurity.com
TXT
  • sophos-domain-verification=14faf1a0d79906662ec1846e10af9a6f16508fab
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 a mx ip4:64.4.59.29 include:mymxserver.com include:spf.crsend.com include:spf.protection.outlook.com include:spf.hornetsecurity.com ip4:62.54.195.162 -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-07 to 2026-07-06
Expires in 46 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://www.iba-hamburg.de/en/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
default-src https:; font-src https: data:; img-src https: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob: https:; style-src https: 'unsafe-inline'; connect-src 'self' https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:;

Links to (4)

Linked from (3)