etc.at
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress 6.9.4
- PHP
- 8.3.31 security-only
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (8)
- ik.imagekit.io×46
- privacy-proxy.usercentrics.eu×3
- api.usercentrics.eu×2
- app.usercentrics.eu×2
- maps.googleapis.com×2
- web.cmp.usercentrics.eu×2
- hb.wpmucdn.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- coleman.ns.cloudflare.com
- sunny.ns.cloudflare.com
- MX
-
- 0 etc-at.mail.protection.outlook.com
- 100 etc-at.s-v1.mx.microsoft
- TXT
-
5inbc6la1m8hdim8uqp2lha59dklaviyo-site-verification=Uw6Jfwpko91itc96vjsadk79m7msb66r
- Verified for
-
- Brevo
- Meta
- OpenAI
Email authentication partial
- SPF
-
v=spf1 include:send.klaviyo.com include:klaviyo-mail.com include:sendgrid.net include:spf.protection.outlook.com a:postfox.bitonline.cc a:postillion.bitonline.cc ip4:193.104.82.0/24 ip4:188.20.70.145 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:202f5294@mxtoolbox.dmarc-report.com,mailto:dmarc-report@etc.at; ruf=mailto:202f5294@forensics.dmarc-report.com,mailto:dmarc-report@etc.at; fo=1policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKNtpeoglAF0C4W5kshzFGh2TRhdyjWzF6XDunj0iV8jpPfVGKFcNJHGnY1KFPwoHoI592RQa1mmeLP51fSV… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https: *.aws *.adform.net *.ars.at *.etc.at *.flane.at *.bing.com *.clarity.ms *.cloudflare.com *.cloudfront.net *.g.doubleclick.net *.google-analytics.com *.google.at *.google.com *.googleapis.com *.googletagmanager.com *.hotjar.com *.imagekit.io *.licdn.com *.linkedin.com *.popt.in *.stripe.com *.stripe.network *.usercentrics.eu *.wp.com *.zopim.com app.adwordsagentur.at cdn.jsdelivr.net connect.facebook.net ekr.zdassets.com etc-enterprisetrainingcenter.zendesk.com static.zdassets.com www.facebook.com widget-mediator.zopim.com- strict-transport-security
max-age=31536000; includeSubDomains; preload