ergo-versicherung.at
HTML metadata
Technology
Third-party hosts loaded (1)
- assets.adobedtm.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.ergo-austria.at
- ns2.coltnet.at
- ns2.ergo-austria.at
- MX
-
- 10 ergoversicherung-at01b.mail.protection.outlook.com
- TXT
-
MS=8ABE5102A68368E25A27863A511DBCC1F62DF691wzdrfKobEgbkxpQ9zqLPVnstlawg3M94dgjBnT1Ci+oExsZA3RvgFgCPTe/zWaDMxzlPTCVT0QOOzh4DjewpXg==
- Verified for
-
- Apple
- Atlassian
- Dynatrace
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a:mail.ergo-austria.at a:mail01.ergo-austria.at ip4:91.212.46.0/24 ip4:193.228.86.27 ip4:193.104.82.0/24 ip4:185.132.180.84 ip4:185.183.28.49 include:spf.protection.outlook.com include:spf.mlwrx.com include:_spf.eventmaker.at -allstrict (-all) - DMARC
-
v=DMARC1; p=none; aspf=rpolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyzBhd7d6o4c30kFS1WsU4RarL+afrjwAi1RlmSQkOO4/9/3blsibDs6ln0nrZxLdxN8ALvo6uHi71M…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 131 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline'; script-src 'unsafe-eval' 'self' 'unsafe-inline' *.ergo-versicherung.at *.ergo.cz cdn.cookielaw.org assets.adobedtm.com cdn.jsdelivr.net sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de www.ekomi.de api.ekomi.de widgets.ekomi.com *.gsitrix.com *.skadtec.com *.cnd-motionmedia.de *.taboola.com *.mbww.com adform.net *.adform.net googleads.g.doubleclick.net consentcdn.cookiebot.com *.cookiebot.com www.googleadservices.com connect.facebook.net *.facebook.net t13.intelliad.de *.intelliad.de bat.bing.com try.abtasty.com *.abtasty.com maps.googleapis.com www.googletagmanager.com consent.cookiebot.com www.google-analytics.com snap.licdn.com cdn.storepoint.co ajax.googleapis.com *.hotjar.com plugins.flockler.com *.cdn.flockler.com optimize.google.com; style-src *.cdn.flockler.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de www.ekomi.de api.ekomi.de widgets.ekomi.com use.fontawesome.com hello.myfonts.net fonts.googleapis.com *.gsitrix.com *.sk- strict-transport-security
max-age=63072000; includeSubDomains