executiveacademy.at
HTML metadata
Technology
- CMS
- Nuxt
Social
DNS records live
- NS
-
- ns1.wu-wien.ac.at
- ns2.wu-wien.ac.at
- MX
-
- 10 mail-s1.nessus.at
- Verified for
-
- HARICA
Email authentication weak
- SPF
-
v=spf1 include:spf.presstige.at -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GEANT TLS RSA 1
Expires in 12 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), autoplay=(self), camera=(), encrypted-media=(self), geolocation=(self), magnetometer=(), microphone=(), payment=(), picture-in-picture=(self), usb=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; connect-src 'self' *.clarity.ms *.crazyegg.com google.com bat.bing.net bat.bing.com public-eur.mkt.dynamics.com assets-eur.mkt.dynamics.com px.ads.linkedin.com www.facebook.com i.clarify.ms cxppusa1formui01cdnsa01-endpoint.azureedge.net prod-66.westeurope.logic.azure.com mobile.events.data.microsoft.com www.google.com *.google-analytics.com sst.executiveacademy.at api.storyblok.com *.usercentrics.eu *.googlesyndication.com; default-src 'self' https: data:; font-src 'self' data:; form-action 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: bat.bing.com app.storyblok.com snap.licdn.com script.crazyegg.com analytics-eu.clickdimensions.com scripts.clarity.ms www.clarity.ms pagead2.googlesyndication.com googleads.g.doubleclick.net connect.facebook.net cxppusa1formui01cdnsa01-endpoint.azureedge.net cxppeur1rdrect01sa02cdn.blob.core.windows.net web.cmp.usercentrics.eu app.usercentrics.eu *.executiveacademy.at; style-src 'self' 'unsafe-inline';- strict-transport-security
max-age=2592000; includeSubDomains