中文

Website Security Scanner

Comprehensive security check · Vulnerability scan · Threat intel · SSL analysis

bzga.de
Scan Time: 2026-05-21 07:50:30
Re-scan
25
Low Risk
2026-05-21 07:50:30

Security Issues Found

  • ⚠️[LOW] 服务器信息泄露
  • ⚠️[MEDIUM] 缺少 HTTP 安全头

Recommendations

  • 💡添加 DMARC 记录增强邮件安全
  • 💡配置 Web 服务器添加这些安全头
  • 💡移除或修改 Server/X-Powered-By 响应头

🌐Domain Info

Targetbzga.de
Registeredbzga.de
TLD.de

🛡️Threat Intelligence (7 platforms)

BlacklistNot Blacklisted
Malware0
Phishing0
Abuse Score0/100

🐛Vulnerabilities Found (2)

MEDIUM缺少 HTTP 安全头
缺少以下安全头: X-Frame-Options, Permissions-Policy
Fix: 配置 Web 服务器添加这些安全头
LOW服务器信息泄露
响应头泄露服务器信息: Server: nginx, X-Powered-By: nothing
Fix: 移除或修改 Server/X-Powered-By 响应头

🔌Open Ports (2)

80
http
443
https

🌐DNS Records

A: 194.153.219.100
MX: 10 mx1.bund.de.
MX: 10 mx2.bund.de.
NS: ns1.dimdi.de.
NS: sif.komtel.net.
TXT: "cisco-ci-domain-verification=c17155493cc019b0d6e9ae29a97669d34c67d3381dd85e6069af6b419995311"
TXT: "HARICA-PSAC7arOEPKtzt52l92"
TXT: "apple-domain-verification=EpcTr0VRoIywsRxJ"
TXT: "v=spf1 include:_spf1.bund.de include:_spf.bzga.de -all"
SOA: ns1.dimdi.de. hostmaster.bfarm.de. 2026031601 10800 3600 604800 86400

📋HTTP Headers

X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content-Security-Policy: default-src 'self' https://piwik.bzga.de/ https://shop.bioeg.de/ https://www.youtube.com/ https://www.youtube-nocookie.c
Referrer-Policy: strict-origin-when-cross-origin
Server: nginx
X-Powered-By: nothing