visit-kitzingen.de
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.googletagmanager.com×1
- www.stadt-kitzingen.de×1
Social
Contact
- Phone
- Address
- Schrannenstraße 197318Kitzingen
Registration
- Updated
- 2026-03-18
- Name servers
-
- helium.ns.hetzner.de.
- hydrogen.ns.hetzner.com.
- oxygen.ns.hetzner.com.
DNS records live
- NS
-
- helium.ns.hetzner.de
- hydrogen.ns.hetzner.com
- oxygen.ns.hetzner.com
- MX
-
- 10 mail.stadt-kitzingen.de
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 140 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; child-src 'self' blob: https://kb.ionas.de/; connect-src 'self' https://*.analytics.google.com https://*.deskline.net https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.readspeaker.com https://*.summ-ai.com https://*.egovernor.de/ https://*.mercury.ai/ https://*.readspeaker.com/ https://www.google-analytics.com; font-src 'self' data: https://*.gstatic.com https://*.mercury.ai/; frame-ancestors 'self' https://www.stadt-kitzingen.de; frame-src 'self' https://*.chargefinder.com https://*.outdooractive.com https://*.readspeaker.com https://*.stadt-kitzingen.de https://*.stadtradeln.de https://*.readspeaker.com/ https://iam.chamaeleon.de/ https://www.meteoblue.com https://www.stadt-kitzingen.de https://www.visit-kitzingen.de; form-action 'self' https://*.readspeaker.com; img-src 'self' data: https://*.analytics.google.com https://*.deskline.net https://*.g.doubleclick.net https://*.google-analytics.com- strict-transport-security
max-age=31536000