Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 81.169.145.158 |
|
🔒 🟡 Mixed Content (3 HTTP resources) | The page is served over HTTPS but loads 3 resource(s) over HTTP. This may be blocked in modern browsers. |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 81.169.145.158
🔒 🟡 Mixed Content (3 HTTP resources) The page is served over HTTPS but loads 3 resource(s) over HTTP. This may be blocked in modern browsers.
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://feuerwehr-thalmassing.de:443 | 301 | HTTP/2 301 |
| 2 | https://thalmassing.feuerwehren.bayern/ | 200 | HTTP/2 200 |
#1 URL https://feuerwehr-thalmassing.de:443
HTTP Status Code 301
Status HTTP/2 301
#2 URL https://thalmassing.feuerwehren.bayern/
HTTP Status Code 200
Status HTTP/2 200
Performance
| DNS Lookup | 100.2 ms |
| TCP Connect | 118.5 ms |
| TLS Handshake | 45.7 ms |
| Time To First Byte (TTFB) | 614.1 ms |
| Content Download | 17 ms |
| Total Response Time | 631 ms |
DNS Lookup 100.2 ms
TCP Connect 118.5 ms
TLS Handshake 45.7 ms
Time To First Byte (TTFB) 614.1 ms
Content Download 17 ms
Total Response Time 631 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=63072000; includeSubdomains; |
| CSP | ✔ Configured |
| X-Frame-Options | ✔ sameorigin |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| Permissions Policy | ✔ Configured |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=63072000; includeSubdomains;
CSP ✔ Configured
X-Frame-Options ✔ sameorigin
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
Permissions Policy ✔ Configured
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
| Title | Startseite - Freiwillige Feuerwehr Thalmassing e.V. |
Title Startseite - Freiwillige Feuerwehr Thalmassing e.V.
Detected Technologies
| Technology | Google Analytics |
Technology Google Analytics
HTTP Headers
| Date
| Wed, 19 Aug 2026 22:35:49 GMT |
| Content-type
| text/html; charset=utf-8 |
| Content-length
| 37224 |
| Expires
| Wed, 19 Aug 2026 22:36:49 GMT |
| Cache-control
| max-age=60 |
| Vary
| , Accept-Language, Cookie |
| Content-language
| de |
| Set-cookie
| django_language=de; expires=Thu, 19 Aug 2027 22:35:49 GMT; Max-Age=31536000; Path=/; Secure |
| Alt-svc
| h3=":443"; ma=2592000; persist=1 |
| Strict-transport-security
| max-age=63072000; includeSubdomains; |
| X-frame-options
| sameorigin |
| X-xss-protection
| 1 |
| Expect-ct
| max-age=0 |
| X-content-type-options
| nosniff |
| Referrer-policy
| strict-origin-when-cross-origin |
| Content-security-policy
| default-src * 'unsafe-inline' 'unsafe-eval' data: blob: mediastream:; script-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline' data: blob: mediastream:; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * data: blob: 'unsafe-inline'; font-src * blob: data: 'unsafe-inline'; worker-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval' |
| Permissions-policy
| microphone=*, fullscreen=*, accelerometer=*, autoplay=*, camera=*, display-capture=*, encrypted-media=*, geolocation=*, gyroscope=*, payment=*, picture-in-picture=*, sync-xhr=*, usb=() |
| Cross-origin-embedder-policy
| unsafe-none |
| Cross-origin-opener-policy
| unsafe-none |
| Cross-origin-resource-policy
| cross-origin |
Meta Tags
| Viewport | width=device-width, initial-scale=1, shrink-to-fit=no |
| Msapplication-config | /static/images/fav/browserconfig.xml |
| Msapplication-TileColor | #ffffff |
| Theme-color | #c90024 |
Date Wed, 19 Aug 2026 22:35:49 GMT
Content-type text/html; charset=utf-8
Content-length 37224
Expires Wed, 19 Aug 2026 22:36:49 GMT
Cache-control max-age=60
Vary , Accept-Language, Cookie
Content-language de
Set-cookie django_language=de; expires=Thu, 19 Aug 2027 22:35:49 GMT; Max-Age=31536000; Path=/; Secure
Alt-svc h3=":443"; ma=2592000; persist=1
Strict-transport-security max-age=63072000; includeSubdomains;
X-frame-options sameorigin
X-xss-protection 1
Expect-ct max-age=0
X-content-type-options nosniff
Referrer-policy strict-origin-when-cross-origin
Content-security-policy default-src * 'unsafe-inline' 'unsafe-eval' data: blob: mediastream:; script-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline' data: blob: mediastream:; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * data: blob: 'unsafe-inline'; font-src * blob: data: 'unsafe-inline'; worker-src * data: blob: mediastream: 'unsafe-inline' 'unsafe-eval'
Permissions-policy microphone=*, fullscreen=*, accelerometer=*, autoplay=*, camera=*, display-capture=*, encrypted-media=*, geolocation=*, gyroscope=*, payment=*, picture-in-picture=*, sync-xhr=*, usb=()
Cross-origin-embedder-policy unsafe-none
Cross-origin-opener-policy unsafe-none
Cross-origin-resource-policy cross-origin