flagincluded.at

.at crawl

First seen 2026-05-27 · Last seen 2026-05-27 · ok HTTP/1.1 200 410 ms crawled 2026-05-30

US · 104.21.48.96 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
FLAGincluded – für queere Sichtbarkeit an Schulen
Language
de
Generator
WordPress 7.0
Canonical
https://flagincluded.at/
Feeds

Technology

CDN
Cloudflare
CMS
WordPress 7.0
PHP
8.2.31 security-only
jQuery
3.7.1

Third-party hosts loaded (1)

  • flagincluded-wordpress.4lima.de×3

Social

Contact

Phone

DNS records live

NS
  • georgia.ns.cloudflare.com
  • watson.ns.cloudflare.com
MX
  • 0 flagincluded-at.mail.protection.outlook.com
Verified for
  • Microsoft
  • Microsoft 365
  • Stripe

Email authentication strong

SPF
v=spf1 a mx include:spf.protection.outlook.com include:sendersrv.com include:_spf.maileroo.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=100; rua=mailto:9280b67dab2040e186fd93dc1c08a205@dmarc-reports.cloudflare.net;
policy: quarantine
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCm/akJlaXEnvmeLzOFeA5Vl543aO+U4xqHM9AYMJkcLsJN+Dqh8M0rQ62N6CwV8qBvzBLv2GBuN0jf6o0fyG…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsptsnzc7AAqF/DO0xpK/QlabW/rU+naR2Bm4NlX8y+NRJjGPip7jhfmAFTcwc3L2ixrSrj+BSRADHBE27R…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCgNxmEkKbkdqm2PhgvoWMPQiuHGsAKbOb9mqgLIk0jHTnkdPNmF7YQDH8FsKk3MaPeKhBy/6X1KsXLrIzggizUa6…
selectors probed

Certificate (current)

WE1
from 2026-04-27 to 2026-07-26
Expires in 55 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://flagincluded.at/

present
  • strict-transport-security
  • content-security-policy
  • permissions-policy
findings
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
content-security-policy
upgrade-insecure-requests
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (2)

Linked from (1)