hagel.at
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Cookie consent
-
- Usercentrics
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- ik.imagekit.io×7
- cdn.jsdelivr.net×4
- privacy-proxy.usercentrics.eu×3
- web.cmp.usercentrics.eu×3
- cdnjs.cloudflare.com×2
- api.usercentrics.eu×1
- app.usercentrics.eu×1
- fonts.googleapis.com×1
- gmpg.org×1
- maps.googleapis.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- austin.ns.cloudflare.com
- iris.ns.cloudflare.com
- MX
-
- 10 mx-02-eu-central-1.prod.hydra.sophos.com
- 5 mx-01-eu-central-1.prod.hydra.sophos.com
- TXT
-
sophos-domain-verification=e3bf6e242d6cb452865b0332bd4650a24f2cdec193aa1eee32bbc35f2cf27787k8aqeqj8g9t1g2dh5utltrjdr2.
Email authentication weak
- SPF
-
v=spf1 mx include:_spf_eucentral1.prod.hydra.sophos.com include:spf.mailjet.com include:_spf.eventmaker.at include:spf.protection.outlook.com ip4:45.156.241.85 ip4:45.156.241.77 ip4:193.228.122.163 ip4:193.228.122.164 ip4:193.228.122.60 ip4:193.228.122.61 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 33 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https: dev.hagel.at.167-235-61-31.dev.functn.com *.hagel.at https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googletagmanager.com https://*.noembed.com https://cdn.plyr.io https://*.g.doubleclick.net https://*.usercentrics.eu https://*.simplecast.com https://*.simplecastcdn.com https://*.gstatic.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com https://s.ytimg.com https://ik.imagekit.io/hagel/*- strict-transport-security
max-age=15552000; includeSubDomains; preload