aau.dk
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- policy.app.cookieinformation.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Fredrik Bajers Vej 7K, 9220, Aalborg Ø, DK
DNS records live
- NS
-
- ns0122.secondary.cloudflare.com
- ns0243.secondary.cloudflare.com
- MX
-
- 10 aau-dk.mail.protection.outlook.com
- TXT
-
Show 18 TXT records
n0j4liboai56f2k63ol7vc18fdd365mktkey=lx0LJxo3k1FGJOdFWTz9i7ylG3AP5eJkLF3HRDuTCWkxgoogle-site-verification=w89-F2MD6W8pzUnZim0MdMwZAamu0q7s7XiU1p8K9QYHARICA-t5AfFTGr76OE5uIaHnHd365mktkey=14yii8czuyiouy2ojp6fg7b4adobe-idp-site-verification=377352ae79cbad27a7fa503684623b58becc8c65753a15e4f789ed14208cd347docusign=a1468f5b-2520-45ec-99f2-e50f27545ca8i58tUtFPHd1d7Hdk+0SozdOYXYyUHOREOjrZ77bZFzE0vJc3HlLVdz9FQSQ0KHb9mvf4HjuSUTUU+U2o14LwAA==DomainVerification=QH0BA7VHK3I0A12X6UD47DYDP5C0QB6L96T9M0W6Y0UXV8CQB4C4C33X5MCMU08Wd365mktkey=4ruxWRtcS31TzAS0xbPGJuPJBcSwMe5hOBT2y4vXre4xmentimeter-80765762-68ce-40e2-9b18-f31d99c02737fp3g9hs2n74g9hkf50i0u938eofacebook-domain-verification=qdtr8jy1ii880wdt9stpeg8ffkaq6mmistral-domain-verification=9b0b768e286a5c404f880353551ac9159e986e06apple-domain-verification=Oy3oswMDjRrhM1Qlatlassian-domain-verification=VZsA2T6hFJg72/c1REox7aKjvGy1mYrXDtSL1vCnyXO3G4HQgRaCjKY4/d11t2Pkd365mktkey=b3qAdEtBRECRPGWEnVjQtqFJYl22qMoSuAxxAY2A1rIxMS=ms24336085
Email authentication strong
- SPF
-
v=spf1 include:_spfhard.aau.dk include:_spf.varbi.com ip4:89.250.112.0 ip4:192.38.91.30 ip4:77.237.55.139 ip4:130.225.62.3 ip4:130.225.62.19 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCvpaV44MyPKcSJkzAZgnzKcDNt18ZZrPAJgFmx6Ukp1aWFfa22hNXUDBAjlTtQ+Tnb6OubXH95OvSu6jnV/H… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0UVwA10T5kIY9tQTeCfYGfIQwXbafm/Zk14fwToTCQHqm2/977q12n+S24QGKsX3UHmOYYGgj7LA0r… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
R12
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.aau.dk https://*.azurewebsites.net https://*.dropbox.com https://*.dropboxusercontent.com https://podcastpusher.com https://*.doubleclick.net https://*.fonts.net https://*.linkedin.com https://*.facebook.com https://*.snapchat.com https://*.google.com https://*.youtube.com https://*.twitter.com https://*.survey-xact.dk https://*.microsoftonline.com https://*.office.com https://*.gstatic.com https://*.cookieinformation.com https://test-1.aau.dk https://test-2.aau.dk; frame-ancestors 'none'; base-uri 'self'; font-src 'self' data: https://fonts.gstatic.com; script-src 'self' 'unsafe-inline' wifipassword.aau.dk https://stats.g.doubleclick.net https://cxppusa1formui01cdnsa01-endpoint.azureedge.net https://www.googletagmanager.com https://www.youtube-nocookie.com https://*.scratcher.io https://*.elfsightcdn.com https://*.snapchat.com https://*.readpeak.com https://*.sc-static.net https://*.licdn.com https://*.google.com https://*.googleapis.com https://*.elfsight- strict-transport-security
max-age=15768000; includeSubdomains; preload;
Links to (6)
- digst.dk×1
- facebook.com×1
- instagram.com×1
- linkedin.com×1
- snapchat.com×1
- youtube.com×1