ivii.eu
HTML metadata
Technology
- Server
- knapp.com
- CMS
- WordPress 7.0
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- gmpg.org×1
- js-eu1.hs-scripts.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.rrpproxy.net
- ns2.rrpproxy.net
- ns3.rrpproxy.net
- MX
-
- 10 mx1.hc104-47.eu.iphmx.com
- 20 mx2.hc104-47.eu.iphmx.com
- TXT
-
knowbe4-site-verification=14383c89fa0e974351c2d9c3d6b75834SoaZname=ivii.eu
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 mx ip4:195.67.13.119 ip4:167.235.28.246 a:207.54.67.238.spf.hc104-47.eu.iphmx.com a:207.54.65.153.spf.hc104-47.eu.iphmx.com include:spf1.knapp.com include:spf.protection.outlook.com include:spf_sap.knapp.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' fonts.googleapis.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: snap.licdn.com *.doubleclick.net www.gstatic.com www.google.com *.hubspot.com *.hsleadflows.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com *.hscollectedforms.net *.hsforms.net *.hs-scripts.com maps.googleapis.com www.googletagmanager.com www.youtube.com connect.facebook.net; connect-src 'self' *.ads.linkedin.com www.facebook.com stats.g.doubleclick.net www.google.at www.googletagmanager.com region1.analytics.google.com *.hs-banner.com *.hubapi.com *.hscollectedforms.net *.hubspot.com *.hsforms.com mapsresources-pa.googleapis.com *.google-analytics.com maps.googleapis.com; img-src 'self' data: *.ads.linkedin.com www.googletagmanager.com fonts.gstatic.com www.facebook.com *.google.at mapsresources-pa.googleapis.com *.hubspot.com *.hsforms.com *.google.com maps.googleapis.com maps.gstatic.com; font-src 'self' data: fonts.gstatic.com; fra- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin, same-origin
Links to (5)
- youtube.com×1
- xing.com×1
- linkedin.com×1
- instagram.com×1
- facebook.com×1
Linked from (4)
- bildgaenger.at×1
- ils365.at×1
- itanic.at×1
- touchday.de×1