lifescienceaustria.at
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- jQuery
- 3.2.1 known XSS (<3.5)
Third-party hosts loaded (1)
- stats.aws.at×1
Social
Contact
DNS records live
- NS
-
- ns1.awsg.at
- nsa.baddaboom.at
- nsb.baddaboom.at
- MX
-
- 10 lifescienceaustria-at.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
v=msv1 t=006E4976-42CF-4E7B-8037-D114C58D3201p00z743q0vqjbnmdjqnlt6jdwsv2drjb_uhr1mme9ipnjt7y757ik4k3x6v2kp6z_cxtogurs4dy00epxvzjfnxtwqxm522l_po6wwd5q1abvlo7ypihtjggysggk15moffensity-domain-verification=980cd687d555ca78c267bed5dff92f6f6e9f3133e663c81ee00f78805310d8e3vhm1y692xrycrxzh8yqk9j12znlbphvl
Email authentication strong
- SPF
-
v=spf1 ip4:91.198.45.19 ip4:91.198.45.20 ip4:62.99.130.186 ip4:128.204.136.158 ip4:128.204.136.159 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc_agg@vali.email; adkim=r; aspf=rpolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFzdPX7DqFE08Z2M5g3rlV/wkI3Dellv5OP6CemI7567yv/9cMp/EOViAqj0l46unMJhqrywqqcU+TPwPXEf… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBLozRsnJ/mdEX78p+pgZ1+kHTh+2JD6izBU4aZ/wG2yFA1D66JrsZ8b6CmlVdBsASD9IigGjZE2HbBt8x3d…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 151 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://stats.aws.at;script-src 'self' 'unsafe-eval' https://stats.aws.at https://www.google.com https://www.gstatic.com https://s7.addthis.com https://v1.addthisedge.com https://z.moatads.com https://m.addthis.com 'sha256-IUgQCFFl4SFR/Lc+2t77IKRiswjlIR5OUnXUyobI1UM=';style-src 'self' 'unsafe-inline' https://stackpath.bootstrapcdn.com;object-src 'none';frame-ancestors 'none';form-action 'self';font-src 'self' https://stackpath.bootstrapcdn.com;img-src 'self' data:;frame-src 'self' https://s7.addthis.com https://www.google.com;connect-src https://api-public.addthis.com https://stats.aws.at https://m.addthis.com;- strict-transport-security
max-age=31536000