kzvbw.de

.de crawl

First seen 2026-04-13 · Last seen 2026-05-10 · ok HTTP/1.1 200 3840 ms crawled 2026-05-07

DE · 83.135.46.199 · AS8881 1&1 Versatel GmbH

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Kassenzahnärztliche Vereinigung Baden-Württemberg (KZV BW)
Description
Die KZV BW stellt die zahnmedizinische Versorgung für die etwa neun Millionen gesetzlich versicherten Menschen in Baden-Württemberg sicher.
Language
de
Canonical
https://www.kzvbw.de/

Open Graph

url
https://www.kzvbw.de/
title
Kassenzahnärztliche Vereinigung Baden-Württemberg (KZV BW)
locale
de_DE
site name
KZV BW
description
Die KZV BW stellt die zahnmedizinische Versorgung für die etwa neun Millionen gesetzlich versicherten Menschen in Baden-Württemberg sicher.

Technology

CMS
WordPress
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • gmpg.org×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

Registration

Updated
2018-12-17
Name servers
  • ns1.nepustil.net.
  • ns.nepustil.com.

DNS records live

NS
  • ns.nepustil.com
  • ns1.nepustil.net
MX
  • 10 mx01.hornetsecurity.com
  • 20 mx02.hornetsecurity.com
  • 30 mx03.hornetsecurity.com
  • 40 mx04.hornetsecurity.com
TXT
Show 7 TXT records
  • _6bicgufhrhazk7c7q4um2o7wkzjrsr6
  • google-site-verification=6qwaDedQXoOXKFW6YRgx5icRSnyAYGUBsdMcxVbiDxY
  • _q7k0wicvvehowzrjccv6l2hotjkx2e9
  • _lyjrx86kb4u3lpc39tk41xsxr4qt67v
  • _0od2ltpwtfioy4o9xj4ji069qhgm2h6
  • MS=BBFF9AE06BBCE7CEDA03FA607141EBAC43686F12
  • 195pjxf085nsx21c01rdwh4yy96wdp0t

Email authentication strong

SPF
v=spf1 mx a:rm01.kzvbw.de ip4:62.214.142.181 include:spf.hornetsecurity.com mx:indivsurvey.de ~all
softfail (~all)
DMARC
v=DMARC1;p=none;
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

Thawte EV RSA CA G2
from 2025-06-10 to 2026-07-09
Expires in 50 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.kzvbw.de/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; img-src 'self' data: blob: www.google-analytics.com maps.gstatic.com *.googleapis.com *.ggpht https://i.ytimg.com; media-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://*.googletagmanager.com *.googleapis.com form.kzvbw.de; style-src 'self' 'unsafe-inline' fonts.googleapis.com; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com form.kzvbw.de; font-src 'self' data: fonts.gstatic.com; frame-src https://letscast.fm https://www.youtube-nocookie.com; manifest-src 'self'
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
cross-origin
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
cross-origin

Links to (6)

Linked from (8)