Technical Information
| HTTP Status Code | 200 |
| HTTP Version | HTTP/1.1 |
| HTTPS | ✔ Available |
| IP Address | 80.245.152.182 |
| Server Software | Apache |
|
ℹ 🔵 No Compression | The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage. |
HTTP Status Code 200
HTTP Version HTTP/1.1
HTTPS ✔ Available
IP Address 80.245.152.182
Server Software Apache
ℹ 🔵 No Compression The server does not use Gzip or Brotli. Enable compression to reduce bandwidth usage.
Redirect Chain
| # | URL | HTTP Status Code | Status |
| 1 | https://bamf.de:443 | 301 | HTTP/1.1 301 Moved Permanently |
| 2 | https://www.BAMF.de/ | 302 | HTTP/1.1 302 Found |
| 3 | https://www.BAMF.de/DE/Startseite/startseite_node.html | 200 | HTTP/1.1 200 OK |
#1 URL https://bamf.de:443
HTTP Status Code 301
Status HTTP/1.1 301 Moved Permanently
#2 URL https://www.BAMF.de/
HTTP Status Code 302
Status HTTP/1.1 302 Found
#3 URL https://www.BAMF.de/DE/Startseite/startseite_node.html
HTTP Status Code 200
Status HTTP/1.1 200 OK
Performance
| DNS Lookup | 1.7 ms |
| TCP Connect | 11 ms |
| TLS Handshake | 18.2 ms |
| Time To First Byte (TTFB) | 50.8 ms |
| Content Download | 27.3 ms |
| Total Response Time | 78 ms |
DNS Lookup 1.7 ms
TCP Connect 11 ms
TLS Handshake 18.2 ms
Time To First Byte (TTFB) 50.8 ms
Content Download 27.3 ms
Total Response Time 78 ms
Security
| HTTPS | ✔ Enabled |
| HSTS | ✔ max-age=31536000 |
| CSP | ✔ Configured |
| X-Frame-Options | ✔ sameorigin |
| X-Content-Type-Options | ✔ nosniff |
| Referrer Policy | strict-origin-when-cross-origin |
| HTTP/2 | ⚠ HTTP/1.1 |
HTTPS ✔ Enabled
HSTS ✔ max-age=31536000
CSP ✔ Configured
X-Frame-Options ✔ sameorigin
X-Content-Type-Options ✔ nosniff
Referrer Policy strict-origin-when-cross-origin
HTTP/2 ⚠ HTTP/1.1
SEO Quick Check
Detected Technologies
| Technology | Google Analytics Apache |
Technology Google Analytics Apache
HTTP Headers
| Date
| Thu, 20 Aug 2026 07:15:44 GMT |
| Server
| Apache |
| Vary
| Accept-Encoding |
| Referrer-Policy
| strict-origin-when-cross-origin |
| X-Frame-Options
| sameorigin |
| X-UA-Compatible
| IE=edge |
| X-Content-Type-Options
| nosniff |
| Content-Security-Policy
| default-src 'self' 'unsafe-eval'; base-uri 'self'; font-src 'self' data: ;style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.itzbund.de *.googleapis.com *.google.com *.gstatic.com www.youtube.com *.vimeo.com *.ytimg.com piwik.itzbund.de; object-src 'self' *.gsb.bund.de; media-src blob: 'self' *.gsb.bund.de *.vimeo.com *.youtube.com; frame-src *.google.com *.gstatic.com *.youtube.com *.vimeo.com; img-src 'self' blob: data: *.google.com *.gstatic.com *.youtube.com *.ytimg.com *.openstreetmap.org piwik.itzbund.de; connect-src 'self' *.itzbund.de; frame-ancestors 'self' *.intranet.bund.de; worker-src 'self'; |
| X-Permitted-Cross-Domain-Policies
| none |
| X-XSS-Protection
| 1;mode=block |
| Cache-Control
| max-age=60 |
| Content-Language
| de-DE |
| Strict-Transport-Security
| max-age=31536000 |
| X-Content-Security-Policy
| default-src 'self' 'unsafe-inline'; allow 'self'; img-src * |
| X-WebKit-CSP
| default-src 'self' 'unsafe-inline'; allow 'self'; img-src * |
| Transfer-Encoding
| chunked |
| Content-Type
| text/html;charset=utf-8 |
Meta Tags
| Title | Startseite |
| Viewport | width=device-width, initial-scale=1.0, maximum-scale=1.5, user-scalable=1 |
| Generator | Government Site Builder |
| Google-site-verification | Y9rTM5gqYnerTdBEr1BUuexYB2Y62zBEcXPJMUD7cZI |
| Facebook-domain-verification | echewtsqpvpa5s9xkwjq9wb8xoiw1v |
| Msapplication-TileImage |  |
| Msapplication-square70x70logo |  |
| Msapplication-square150x150logo |  |
| Msapplication-square310x310logo |  |
| Apple-mobile-web-app-title | BAMFWEB |
| Msapplication-TileColor | #ffffff |
| Msapplication-config | none |
| Application-name | BAMFWEB |
| Theme-color | #ffffff |
| Keywords | Die Keywords |
| Description | Homepage des deutschsprachigen Auftritts |
Date Thu, 20 Aug 2026 07:15:44 GMT
Server Apache
Vary Accept-Encoding
Referrer-Policy strict-origin-when-cross-origin
X-Frame-Options sameorigin
X-UA-Compatible IE=edge
X-Content-Type-Options nosniff
Content-Security-Policy default-src 'self' 'unsafe-eval'; base-uri 'self'; font-src 'self' data: ;style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.itzbund.de *.googleapis.com *.google.com *.gstatic.com www.youtube.com *.vimeo.com *.ytimg.com piwik.itzbund.de; object-src 'self' *.gsb.bund.de; media-src blob: 'self' *.gsb.bund.de *.vimeo.com *.youtube.com; frame-src *.google.com *.gstatic.com *.youtube.com *.vimeo.com; img-src 'self' blob: data: *.google.com *.gstatic.com *.youtube.com *.ytimg.com *.openstreetmap.org piwik.itzbund.de; connect-src 'self' *.itzbund.de; frame-ancestors 'self' *.intranet.bund.de; worker-src 'self';
X-Permitted-Cross-Domain-Policies none
X-XSS-Protection 1;mode=block
Cache-Control max-age=60
Content-Language de-DE
Strict-Transport-Security max-age=31536000
X-Content-Security-Policy default-src 'self' 'unsafe-inline'; allow 'self'; img-src *
X-WebKit-CSP default-src 'self' 'unsafe-inline'; allow 'self'; img-src *
Transfer-Encoding chunked
Content-Type text/html;charset=utf-8