europapier.at
HTML metadata
Technology
- CMS
- Gatsby
Third-party hosts loaded (1)
- webcachex-eu.datareporter.eu×1
Contact
DNS records live
- NS
-
- dns1.a1.net
- dns2.a1.net
- dns3.a1.net
- MX
-
- 10 europapier-at.mail.protection.outlook.com
- TXT
-
OXxDhi12RPHfmngF+2OXSCX0qabw5aCE1Q7vvvkzrlGWuFVJo+KsCoCJgJpyNWQ9wIqbjgbRrDCbey7EBaFb0g==bw=RhfVfjFAR8oz1SSeZnjBVAT50XBy5ZDiVVg4xNQN64sI
- Verified for
-
- Apple
- Atlassian
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx include:spf.protection.outlook.com include:spf.emailsignatures365.com include:spf.crsend.com include:_spf.cmail.ondemand.com a:smtp01.external.network a:smtp02.external.network a:eupexmgmt.europapier.com a:mail.sntdc.at ip4:185.238.35.95 ip4:185.159.58.17 -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc@europapier.com;aspf=r;fo=1;adkim=rpolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxf5NFD2ClGa+ORMQvzpdtxLX9ZQeNNeEPKwg+Ykqh2ClrkXF+mBcmzvMM7piuajak/zH1YqsMWbBkA… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxnrPeLS+ttd5xTa+ijBimXcKUhSMCoph+3uvmnx7bO5O9iwo6IWMMepv7sZ2Cbf74+d87myIsfH/wB…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 304 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
origin-when-cross-origin- permissions-policy
payment=('self'), clipboard-read=('self), clipboard-write=('self), camera=(), geolocation=(), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), autoplay=(), usb=(), fullscreen=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' script-src-elem * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src-elem * 'unsafe-inline';img-src * data: 'unsafe-inline'; connect-src *;- strict-transport-security
max-age=16070400; includeSubDomains