fraubock.at

.at crawl

First seen 2026-05-31 · Last seen 2026-06-02 · ok HTTP/1.1 200 807 ms crawled 2026-05-31

AT · 144.208.3.78 · AS44453 interneX GmbH

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Verein Ute Bock – Die Flüchtlingshilfe in Wien
Description
Der Flüchtlings-Verein Ute Bock ist für viele geflüchtete Menschen die erste Adresse in Österreich! Hier finden sie Obdach, Bildung, Soforthilfe und Beratung.
Language
de-at
Generator
Joomla! - Open Source Content Management

Technology

Server
Apache
CMS
Joomla
PHP
8.2.30 security-only
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Email

DNS records live

NS
  • ns1.easyname.eu
  • ns2.easyname.eu
MX
  • 0 fraubock-at.mail.protection.outlook.com
TXT
  • thb4hr73g5t73h32955vkxxcbk06k6bm
  • 2017070513595934az6tzzndfgukutpish2var8eouwzcd9um7xuiw1cugbdrtfb
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 a ip4:213.174.241.150 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

R12
from 2026-05-03 to 2026-08-01
Expires in 58 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://www.fraubock.at/de/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' https://fonts.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://unpkg.com https://ajax.googleapis.com https://sdks.shopifycdn.com https://cdn.qenta.com https://eu-prod.oppwa.com https://*.techlab-cdn.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://chimpstatic.com https://downloads.mailchimp.com https://*.list-manage.com https://code.jquery.com https://cdn.jsdelivr.net https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://ajax.googleapis.com https://eu-prod.oppwa.com https://cdn-images.mailchimp.com https://downloads.mailchimp.com; worker-src 'self' blob:; frame-src https:; connect-src 'self' https:; object-src 'none'; img-src 'self' https: data:; base-uri 'self'; form-action 'self' https:;
cross-origin-opener-policy
same-origin

Links to (7)

Linked from (2)