fragdenstaat.at
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Stack
- Django
Third-party hosts loaded (1)
- static.frag.denstaat.at×9
DNS records live
- NS
-
- ns1.easyname.eu
- ns2.easyname.eu
- MX
-
- 10 mail.fragdenstaat.at
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 a mx a:mx.holzhauer.it include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- mail:
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp9dyGas/59NsvrJHiRyUZmu+Z1ZU+pRgAvk3jNLZKY4m0uRHmjWoeSZkFNw+p+0pyicF…
selectors probed - mail:
Certificate (current)
R12
Expires in 84 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
same-origin, same-origin- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self', default-src 'none';script-src 'self' 'unsafe-inline' https://js.stripe.com https://static.frag.denstaat.at;style-src 'self' 'unsafe-inline' https://static.frag.denstaat.at;img-src 'self' data: blob: https://static.frag.denstaat.at https://media.frag.denstaat.at;media-src https://static.frag.denstaat.at https://media.frag.denstaat.at;worker-src 'self' blob: https://static.frag.denstaat.at;frame-src 'self' https://js.stripe.com blob: https://static.frag.denstaat.at https://media.frag.denstaat.at;object-src 'self' https://media.frag.denstaat.at;connect-src 'self' https://media.frag.denstaat.at https://static.frag.denstaat.at wss://fragdenstaat.at https://sentry.io;child-src blob: https://static.frag.denstaat.at;base-uri 'none';font-src data: https://static.frag.denstaat.at;manifest-src https://static.frag.denstaat.at;form-action 'self' https://fragdenstaat.at https://www.paypal.com https://pretix.eu https://hooks.stripe.com https://stripe.com https://r.girogate.de- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin