aspern-seestadt.at
HTML metadata
Technology
- Server
- nginx
- PHP
- 8.3.23 security-only
Social
Contact
- Address
- Seestadtstraße 27/13, 1220, Wien, Wien, AT
DNS records live
- NS
-
- ns.udag.de
- ns.udag.net
- ns.udag.org
- MX
-
- 10 aspernseestadt-at01e.mail.eo.outlook.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:spf.mailjet.com ip4:83.138.80.195 include:spf1.eyepinnews.com include:spf2.eyepinnews.com include:spf3.eyepinnews.com include:outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 61 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
same-origin- permissions-policy
geolocation=(), midi=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.aspern-seestadt.at *.plyr.io; style-src 'self' 'unsafe-inline' *.googleapis.com cdn.ckeditor.com; style-src-elem 'self' 'unsafe-inline' *.googletagmanager.com *.googleapis.com cdn.ckeditor.com; img-src 'self' blob: data: mksiteview.mktimelapse.com i.ytimg.com *.buzzsprout.com *.mapbox.com *.linkedin.com *.openstreetmap.org *.googleadservices.com *.googletagmanager.com *.doubleclick.net maps.gstatic.com *.googleapis.com *.google.at *.google.com *.google.pt *.bing.com *.clarity.ms cdn-cookieyes.com cdn.ckeditor.com *.facebook.com; font-src 'self' data: *.gstatic.com; script-src 'self' blob: 'unsafe-inline' 'unsafe-eval' cdn-cookieyes.com *.cdn-cookieyes.com *.cookieyes.com *.googleapis.com *.googleadservices.com *.googletagmanager.com *.doubleclick.net *.google-analytics.com *.google.com *.google.at *.google.pt *.googlesyndication.com cdn.ckeditor.com *.facebook.net *.facebook.com *.bing.com *.clarity.ms; script-src-elem 'self' 'unsafe-inline' www.buz