autoplus.at
HTML metadata
Technology
- Server
- Schneider
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.a1.net
- dns2.a1.net
- dns3.a1.net
- MX
-
- 10 denzel-pm.blue-shield.at
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx include:spf_mdata.denzel.at include:spf1.denzel.at a:s06.oursubnet.org -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwo07m4h+Sof+bR8Crje6cZUrCoyBAPzaeujZlR66/SW942gwFJ7qEiBtrpJ5PNSREO5q… - dkim:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArG9inSYHd/hI6DbMDtGdDLKbT5b02Razu8TviidFEbzR+E/BV19b6jUkq3QVRLbJvgwWWWVd5IkBFS/U9eV+z…
selectors probed - default:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 260 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' https://localhost:* http://localhost:* wss://localhost:* ws://localhost:* wss://127.0.0.1:* https://*.adform.net https://ppipe.net https://autoplus.at https://*.autoplus.at https://denzel.containers.piwik.pro https://denzel.piwik.pro https://eu-test.oppwa.com https://eu-prod.oppwa.com https://*.ppipe.net wss://*.userlike.com https://*.userlike.com https://userlike-cdn-umm.b-cdn.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://userback-us.s3.amazonaws.com https://d3dc1lgancj6l0.cloudfront.net https://*.autoplus.at https://*.userback.io https://*.psa.at/ https://*.google.com https://*.googleapis.com https://*.gstatic.com https://www.recaptcha.net https://*.youtube.com https://youtu.be https://*.umbraco.com https://*.googletagmanager.com https://*.google-analytics.com https://*.snazzymaps.com https://snazzymaps.com https://cdn-cookieyes.com https://*.cookieyes.com- strict-transport-security
max-age=16070400; includeSubDomains